Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-215 Exam - Topic 9 Question 117 Discussion

An incident responder reviews a log entry that shows a Microsoft Word process initiating an outbound network connection followed by PowerShell execution with obfuscated commands. Considering the machine's role in a sensitive data department, what is the most critical action for the responder to take next to analyze this output for potential indicators of compromise?
C) Conduct a behavioral analysis of the PowerShell execution pattern and deobfuscate the commands to assess malicious intent.
A) Compare the metadata of the Microsoft Word document with known templates to verify its authenticity.
B) Examine the network destination of the outbound connection to assess the credibility and categorize the traffic.
D) Correlate the time of the outbound network connection with the user's activity log to establish a usage pattern.

Cisco 300-215 Exam - Topic 9 Question 117 Discussion

Actual exam question for Cisco's 300-215 exam
Question #: 117
Topic #: 9
[All 300-215 Questions]

An incident responder reviews a log entry that shows a Microsoft Word process initiating an outbound network connection followed by PowerShell execution with obfuscated commands. Considering the machine's role in a sensitive data department, what is the most critical action for the responder to take next to analyze this output for potential indicators of compromise?

Show Suggested Answer Hide Answer
Suggested Answer: C

When dealing with suspected malicious activity involving obfuscated PowerShell scripts---especially when launched from Microsoft Word documents---behavioral analysis is the most critical next step. This approach helps in determining if the process chain is part of a known attack pattern, such as a phishing attempt using malicious macros that launch PowerShell for data exfiltration or payload download.

As highlighted in the CyberOps Technologies (CBRFIR) 300-215 study guide, understanding behavior and deobfuscating PowerShell scripts is an essential part of the forensic and incident response process. Specifically:

During the detection and analysis phase, if PowerShell is used with obfuscated or encoded commands, responders should investigate the intent and behavior of the command.

Deobfuscation allows analysts to see what the script is doing (e.g., downloading files, creating persistence mechanisms, or opening a reverse shell).

The guide states:

''For example, if the threat is malware, the compromised system should be immediately isolated and the malware should be placed in a sandbox or a detonation chamber to understand what it is trying to do''.

This confirms that understanding execution behavior (such as what the PowerShell script intends to perform) is key to uncovering indicators of compromise (IoCs).

Thus, option C---conducting a behavioral analysis and deobfuscating PowerShell---is the most critical and effective response at this stage.


Contribute your Thoughts:

0/2000 characters
Denise
21 hours ago
I agree, but we shouldn't ignore option B. The network destination is crucial for credibility.
upvoted 0 times
...
Zack
6 days ago
I think option C is the best. Analyzing PowerShell can reveal hidden threats.
upvoted 0 times
...
Aretha
11 days ago
D could help, but I think we need to focus on the commands first.
upvoted 0 times
...
Delila
16 days ago
Wait, PowerShell can be that sneaky? I'm surprised!
upvoted 0 times
...
Franklyn
22 days ago
A seems like a waste of time in this scenario.
upvoted 0 times
...
Elise
27 days ago
B is important too, but C feels more critical here.
upvoted 0 times
...
Dominga
1 month ago
Definitely C, gotta deobfuscate those commands!
upvoted 0 times
...
Luisa
1 month ago
I feel like verifying the authenticity of the Word document is important too, but I’m leaning towards option C for a deeper analysis of the PowerShell execution.
upvoted 0 times
...
Ezekiel
1 month ago
I practiced a similar question where we had to correlate user activity with suspicious behavior. I think option D could provide useful context, but I’m not convinced it’s the most critical step.
upvoted 0 times
...
Gilma
2 months ago
I’m not entirely sure, but I think examining the network destination might help identify if it’s a known malicious site. Option B sounds relevant.
upvoted 0 times
...
Tu
2 months ago
I remember studying the importance of analyzing PowerShell commands, especially when they’re obfuscated. It seems like option C could be crucial here.
upvoted 0 times
...

Save Cancel