Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-215 Exam - Topic 4 Question 4 Discussion

A security team receives reports of multiple files causing suspicious activity on users' workstations. The file attempted to access highly confidential information in a centralized file server. Which two actions should be taken by a security analyst to evaluate the file in a sandbox? (Choose two.)
B) Inspect processes. and C) Inspect file hash.
A) Inspect registry entries
D) Inspect file type.
E) Inspect PE header.

Cisco 300-215 Exam - Topic 4 Question 4 Discussion

Actual exam question for Cisco's 300-215 exam
Question #: 4
Topic #: 4
[All 300-215 Questions]

A security team receives reports of multiple files causing suspicious activity on users' workstations. The file attempted to access highly confidential information in a centralized file server. Which two actions should be taken by a security analyst to evaluate the file in a sandbox? (Choose two.)

Show Suggested Answer Hide Answer
Suggested Answer: B, C

Contribute your Thoughts:

0/2000 characters
Leota
10 months ago
Registry entries can be useful, but not the priority.
upvoted 0 times
...
Charlie
10 months ago
Surprised that PE header isn't a top choice here!
upvoted 0 times
...
Avery
11 months ago
I thought inspecting file type was more important?
upvoted 0 times
...
Tresa
11 months ago
Inspecting processes is a must too!
upvoted 0 times
...
Barabara
11 months ago
Definitely check the file hash first.
upvoted 0 times
...
Kimberlie
11 months ago
Okay, let's see here. I'm pretty sure the "Delete Item" and "Apply System Configuration" tasks would need the plug-in, but I'm not sure about the others.
upvoted 0 times
...
Inocencia
11 months ago
I'm a little unsure about this one. The code snippets don't seem to directly show the "Account deleted" alert, so I'm not sure how to approach it. Maybe I'd try running the code and seeing where the alert is displayed, then tracing back to the relevant lines of code.
upvoted 0 times
...
Cecil
11 months ago
I'm not so sure though. The use of proprietary protocols could also create vulnerabilities, right? It's hard to say which is the greatest risk.
upvoted 0 times
...

Save Cancel