Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 350-201 Exam - Topic 12 Question 108 Discussion

An analyst is alerted for a malicious file hash. After analysis, the analyst determined that an internal workstation is communicating over port 80 with an external server and that the file hash is associated with Duqu malware. Which tactics, techniques, and procedures align with this analysis?
A) Command and Control, Application Layer Protocol, Duqu
B) Discovery, Remote Services: SMB/Windows Admin Shares, Duqu
C) Lateral Movement, Remote Services: SMB/Windows Admin Shares, Duqu
D) Discovery, System Network Configuration Discovery, Duqu

Cisco 350-201 Exam - Topic 12 Question 108 Discussion

Actual exam question for Cisco's 350-201 exam
Question #: 108
Topic #: 12
[All 350-201 Questions]

An analyst is alerted for a malicious file hash. After analysis, the analyst determined that an internal workstation is communicating over port 80 with an external server and that the file hash is associated with Duqu malware. Which tactics, techniques, and procedures align with this analysis?

Show Suggested Answer Hide Answer
Suggested Answer: A

Contribute your Thoughts:

0/2000 characters
Ulysses
9 months ago
Wait, are we sure it's Duqu? Seems a bit off.
upvoted 0 times
...
Yun
9 months ago
I agree, port 80 is a classic for C2!
upvoted 0 times
...
Lelia
9 months ago
C is also a possibility, but I lean towards A.
upvoted 0 times
...
Ressie
9 months ago
B seems more relevant with SMB involved.
upvoted 0 times
...
Elmer
9 months ago
Definitely sounds like Command and Control with Duqu.
upvoted 0 times
...
Matilda
10 months ago
I keep mixing up the techniques. I thought SMB was more about lateral movement, but this scenario feels like it’s more about command and control. Is A definitely the best choice?
upvoted 0 times
...
Delfina
10 months ago
I practiced a similar question about malware tactics, and I think Duqu is primarily about Command and Control, so option A seems right to me.
upvoted 0 times
...
Chantell
10 months ago
I'm not entirely sure, but I feel like the communication over port 80 could relate to some kind of discovery technique. Maybe option D?
upvoted 0 times
...
Cassandra
10 months ago
I remember studying Duqu and its connection to Command and Control. I think option A makes sense here.
upvoted 0 times
...
Kate
11 months ago
I'm feeling confident about this one. The communication over port 80 and the Duqu malware association point to Command and Control and Application Layer Protocol tactics, which match option A. I'll go with that.
upvoted 0 times
...
Margery
11 months ago
Okay, I've got a strategy here. First, I'll eliminate the options that don't seem to match the details given. Then I'll focus on the remaining options and try to determine which one best aligns with the Duqu malware and the communication over port 80.
upvoted 0 times
...
Tijuana
11 months ago
Hmm, I'm a bit unsure about this one. The question mentions tactics, techniques, and procedures, so I need to think about the broader attack lifecycle, not just the specific details provided. Let me re-read the options carefully.
upvoted 0 times
...
Viva
11 months ago
This one seems pretty straightforward. The key details are the malicious file hash, the internal workstation communicating over port 80 with an external server, and the association with Duqu malware. I think option A is the best fit.
upvoted 0 times
...
Herschel
1 year ago
I hope the exam question isn't as 'Duqu'ced up as this one. Anyway, A) seems like the best choice to me.
upvoted 0 times
Margery
1 year ago
User 2: Yeah, Command and Control, Application Layer Protocol, Duqu make sense.
upvoted 0 times
...
Miriam
1 year ago
User 1: I agree, A) seems like the right choice.
upvoted 0 times
...
...
Eden
1 year ago
But Vernice, the analysis mentioned port 80 communication, which is not related to SMB/Windows Admin Shares.
upvoted 0 times
...
Vernice
1 year ago
I believe the answer is B) Discovery, Remote Services: SMB/Windows Admin Shares, Duqu.
upvoted 0 times
...
Cora
1 year ago
I agree with Eden, because the internal workstation communicating with an external server over port 80 aligns with Command and Control tactics.
upvoted 0 times
...
Timothy
1 year ago
A) is the way to go, no doubt. Duqu is notorious for using Application Layer Protocol for its Command and Control activities.
upvoted 0 times
...
Lawrence
1 year ago
Hmm, I'm not sure. D) Discovery, System Network Configuration Discovery, Duqu could also be a possibility, as the analyst was alerted about a malicious file hash.
upvoted 0 times
Beula
1 year ago
True, but C) Lateral Movement, Remote Services: SMB/Windows Admin Shares, Duqu aligns better with the communication over port 80 with an external server.
upvoted 0 times
...
Alfreda
1 year ago
I agree, but B) Discovery, Remote Services: SMB/Windows Admin Shares, Duqu could also be a valid option.
upvoted 0 times
...
Loreta
1 year ago
I think A) Command and Control, Application Layer Protocol, Duqu makes more sense in this scenario.
upvoted 0 times
...
...
Eden
1 year ago
I think the answer is A) Command and Control, Application Layer Protocol, Duqu.
upvoted 0 times
...
Frederic
1 year ago
I think C) Lateral Movement, Remote Services: SMB/Windows Admin Shares, Duqu is the correct answer. The workstation communicating with an external server suggests lateral movement.
upvoted 0 times
King
1 year ago
User 2
upvoted 0 times
...
Clay
1 year ago
User 1
upvoted 0 times
...
...
Wade
1 year ago
A) Definitely! The communication over port 80 and the file hash association with Duqu malware point to Command and Control, Application Layer Protocol, and Duqu tactics, techniques, and procedures.
upvoted 0 times
Angelyn
1 year ago
C) Maybe there's also Lateral Movement involved with Remote Services: SMB/Windows Admin Shares.
upvoted 0 times
...
Tamar
1 year ago
B) I agree, it could also involve Discovery and Remote Services: SMB/Windows Admin Shares.
upvoted 0 times
...
Amie
1 year ago
A) Definitely! The communication over port 80 and the file hash association with Duqu malware point to Command and Control, Application Layer Protocol, and Duqu tactics, techniques, and procedures.
upvoted 0 times
...
...

Save Cancel