Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-215 Exam - Topic 6 Question 87 Discussion

Refer to the exhibit.According to the Wireshark output, what are two indicators of compromise for detecting an Emotet malware download? (Choose two.)
D) filename= ''Fy.exe''
A) Domain name:iraniansk.com
B) Server: nginx
C) Hash value: 5f31ab113af08=1597090577
E) Content-Type: application/octet-stream

Cisco 300-215 Exam - Topic 6 Question 87 Discussion

Actual exam question for Cisco's 300-215 exam
Question #: 87
Topic #: 6
[All 300-215 Questions]

Refer to the exhibit.

According to the Wireshark output, what are two indicators of compromise for detecting an Emotet malware download? (Choose two.)

Show Suggested Answer Hide Answer
Suggested Answer: D

Contribute your Thoughts:

0/2000 characters
Art
9 months ago
Hash values can be misleading, not always a solid indicator.
upvoted 0 times
...
Kenda
9 months ago
E is a big red flag too, application/octet-stream is suspicious.
upvoted 0 times
...
Jacqueline
10 months ago
Surprised to see A, I thought that domain was clean!
upvoted 0 times
...
Jesus
10 months ago
I think B is a red herring, nginx is pretty common.
upvoted 0 times
...
Vicky
10 months ago
Definitely A and D, those are classic signs of Emotet.
upvoted 0 times
...
Ahmed
10 months ago
I think the Content-Type being application/octet-stream is a common sign of malware downloads, but I’m not 100% certain about the other options.
upvoted 0 times
...
Carlton
11 months ago
I’m a bit confused about the hash value. I don’t recall if that’s a strong indicator for Emotet specifically, but it seems relevant.
upvoted 0 times
...
Shayne
11 months ago
I'm not entirely sure, but I feel like the filename 'Fy.exe' might also be suspicious based on similar practice questions we did.
upvoted 0 times
...
Charlene
11 months ago
I remember we discussed Emotet in class, and I think the domain name could definitely be a key indicator.
upvoted 0 times
...
Kristeen
11 months ago
This is a tricky one, but I think I've got it. The domain name and content type are clear indicators of an Emotet attack. I'll select those two options and move on.
upvoted 0 times
...
Blair
11 months ago
I'm a bit confused by all the technical details in this question. I'll try to identify the most obvious signs of compromise, like the suspicious domain name and file type.
upvoted 0 times
...
Matilda
11 months ago
Hmm, the domain name and server info seem like they could be relevant, but I'm not sure what to make of the hash value and filename. I'll have to think this through carefully.
upvoted 0 times
...
Luisa
11 months ago
This looks like a classic Emotet malware detection question. I'll focus on finding the indicators of compromise in the Wireshark output.
upvoted 0 times
...
Carolann
11 months ago
Okay, I see the domain name "iraniansk.com" and the "application/octet-stream" content type - those are definitely indicators of an Emotet download. I'll select those two.
upvoted 0 times
...
Sue
1 year ago
I'm just glad I don't have to deal with this stuff in real life. I'll stick to my spreadsheets and PowerPoint presentations, thank you very much.
upvoted 0 times
Malcolm
1 year ago
User 3: Those indicators of compromise can be tricky to detect.
upvoted 0 times
...
Andra
1 year ago
User 2: Definitely. I prefer working with spreadsheets too.
upvoted 0 times
...
Cortney
1 year ago
User 1: Yeah, dealing with malware is a whole different world.
upvoted 0 times
...
...
Jordan
1 year ago
Haha, 'Fy.exe'? Really? They couldn't come up with a more creative file name? And the domain 'iraniansk.com' - sounds like it was registered by a toddler.
upvoted 0 times
Nana
1 year ago
User 3: Nana: And 'iraniansk.com' sounds suspicious too.
upvoted 0 times
...
Laine
1 year ago
User 2: Laine: Yeah, they could have been a bit more creative with that.
upvoted 0 times
...
Sunshine
1 year ago
User 1: I know right, 'Fy.exe' is such a generic name.
upvoted 0 times
...
...
Dottie
1 year ago
The nginx server and the content type 'application/octet-stream' are also good signs that something fishy is going on. I bet the hash value is just there to confuse us.
upvoted 0 times
Kasandra
1 year ago
I agree, the hash value might just be a distraction from the real indicators of compromise.
upvoted 0 times
...
Leah
1 year ago
Yeah, the filename 'Fy.exe' is also a red flag for sure.
upvoted 0 times
...
Nancey
1 year ago
I think we should also keep an eye on the domain name 'iraniansk.com'.
upvoted 0 times
...
Cecil
1 year ago
I agree, the nginx server and content type are definitely suspicious.
upvoted 0 times
...
...
Art
1 year ago
I'm not sure about the hash value, but I think the filename and content type could also be indicators of compromise.
upvoted 0 times
...
Pearly
1 year ago
I agree with you, Johnathon. The domain name and hash value seem like key indicators in this case.
upvoted 0 times
...
Casey
1 year ago
The domain name 'iraniansk.com' and the file name 'Fy.exe' are definitely indicators of compromise for Emotet malware. This is really helpful information to detect and prevent such attacks.
upvoted 0 times
Skye
1 year ago
Emotet malware is a serious threat, so it's good to know what to watch for.
upvoted 0 times
...
Rosamond
1 year ago
I will make sure to keep an eye out for those indicators in our network traffic.
upvoted 0 times
...
Celia
1 year ago
It's important to stay vigilant and monitor for any signs of compromise.
upvoted 0 times
...
Fausto
1 year ago
I agree, those are definitely key indicators to look out for.
upvoted 0 times
...
...
Johnathon
1 year ago
I think the indicators of compromise for detecting Emotet malware download are domain name and hash value.
upvoted 0 times
...

Save Cancel