Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-220 Exam - Topic 3 Question 9 Discussion

A threat hunter wants to detect fileless malware activity using Cisco Secure Endpoint. Which behavior would MOST strongly indicate fileless execution?
C) Legitimate system processes executing encoded commands
A) Executables running from Program Files
B) Processes spawning from user-writable directories
D) Files with unknown hash reputation

Cisco 300-220 Exam - Topic 3 Question 9 Discussion

Actual exam question for Cisco's 300-220 exam
Question #: 9
Topic #: 3
[All 300-220 Questions]

A threat hunter wants to detect fileless malware activity using Cisco Secure Endpoint. Which behavior would MOST strongly indicate fileless execution?

Show Suggested Answer Hide Answer
Suggested Answer: C

The correct answer is legitimate system processes executing encoded commands. Fileless malware avoids writing binaries to disk and instead abuses trusted processes such as PowerShell, WMI, or rundll32.

Encoded or obfuscated commands executed by legitimate binaries are a strong indicator of fileless execution and defense evasion. Cisco Secure Endpoint provides deep visibility into command-line arguments and process behavior, enabling detection of this technique.

Option A is normal behavior. Option B may indicate suspicious execution but still involves files. Option D relies on file presence, which fileless attacks intentionally avoid.

This technique aligns with MITRE ATT&CK -- Command and Scripting Interpreter and Defense Evasion and is directly relevant to CBRTHD exam objectives related to endpoint-based threat hunting.

Therefore, Option C is the correct answer.


Contribute your Thoughts:

0/2000 characters
Wilda
3 days ago
I think C is the best choice. Encoded commands are suspicious.
upvoted 0 times
...
Sylvie
8 days ago
D is interesting, but not as clear-cut as C.
upvoted 0 times
...
Brinda
13 days ago
A is too common; it’s not a strong indicator at all.
upvoted 0 times
...
Marguerita
19 days ago
Wait, encoded commands? That sounds a bit extreme.
upvoted 0 times
...
Ryann
24 days ago
I think B could also be suspicious. User-writable directories are risky.
upvoted 0 times
...
Rozella
29 days ago
C is definitely the right choice. Encoded commands are a red flag!
upvoted 0 times
...
Twila
1 month ago
D seems like a red flag, but not as strong as C.
upvoted 0 times
...
Joana
1 month ago
A is too common, not really a threat indicator.
upvoted 0 times
...
Maile
1 month ago
Wait, encoded commands? That sounds sketchy!
upvoted 0 times
...
Mertie
2 months ago
I think B could also be a strong indicator.
upvoted 0 times
...
Lorrine
2 months ago
C is definitely the right choice!
upvoted 0 times
...
Brice
2 months ago
Unknown hash reputation sounds important, but I don't think that's specific enough for fileless execution. I lean towards C as well.
upvoted 0 times
...
Octavio
2 months ago
I practiced a similar question, and I think the key is looking for encoded commands in system processes. So, C seems likely.
upvoted 0 times
...
Stephanie
2 months ago
I'm not entirely sure, but I feel like processes from user-writable directories could be suspicious too.
upvoted 0 times
...
Tyra
4 months ago
I think I remember that fileless malware often uses legitimate processes, so maybe C is the right choice?
upvoted 0 times
...

Save Cancel