Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 350-201 Exam - Topic 3 Question 85 Discussion

A SOC analyst is investigating a recent email delivered to a high-value user for a customer whose network their organization monitors. The email includes a suspicious attachment titled ''Invoice RE: 0004489''. Thehash of the file is gathered from the Cisco Email Security Appliance. After searching Open Source Intelligence, no available history of this hash is found anywhere on the web. What is the next step in analyzing this attachment to allow the analyst to gather indicators of compromise?
A) Run and analyze the DLP Incident Summary Report from the Email Security Appliance and D) Obtain a copy of the file for detonation in a sandbox
B) Ask the company to execute the payload for real time analysis
C) Investigate further in open source repositories using YARA to find matches

Cisco 350-201 Exam - Topic 3 Question 85 Discussion

Actual exam question for Cisco's 350-201 exam
Question #: 85
Topic #: 3
[All 350-201 Questions]

A SOC analyst is investigating a recent email delivered to a high-value user for a customer whose network their organization monitors. The email includes a suspicious attachment titled ''Invoice RE: 0004489''. The

hash of the file is gathered from the Cisco Email Security Appliance. After searching Open Source Intelligence, no available history of this hash is found anywhere on the web. What is the next step in analyzing this attachment to allow the analyst to gather indicators of compromise?

Show Suggested Answer Hide Answer
Suggested Answer: A, D

Contribute your Thoughts:

0/2000 characters
Tenesha
9 months ago
No history on that hash? Sounds suspicious...
upvoted 0 times
...
Cammy
9 months ago
Wait, are we really considering executing the payload? That's risky!
upvoted 0 times
...
Stephanie
10 months ago
Running a DLP report won't give you the full picture.
upvoted 0 times
...
Stanton
10 months ago
I think checking YARA matches is a good move too.
upvoted 0 times
...
Grover
10 months ago
Definitely need to detonate that file in a sandbox.
upvoted 0 times
...
Marla
10 months ago
I feel like asking the company to execute the payload is definitely a bad idea. That seems way too risky!
upvoted 0 times
...
Yoko
11 months ago
YARA sounds familiar, but I can't recall if it's the best next step here. I thought it was more for identifying known malware patterns.
upvoted 0 times
...
France
11 months ago
I'm not entirely sure, but I feel like running a DLP report might not give us enough insight into the actual content of the attachment.
upvoted 0 times
...
Van
11 months ago
I remember we talked about the importance of sandboxing suspicious files. I think obtaining a copy for detonation could be the right move.
upvoted 0 times
...
Loren
11 months ago
I think option D is the way to go here. Getting that file into a controlled environment is key to understanding what it's doing. The other options seem a bit indirect for this type of investigation.
upvoted 0 times
...
Rashida
11 months ago
I'm a little confused by this question. What's the difference between options A and D? Wouldn't the DLP report and sandbox analysis both give us indicators of compromise?
upvoted 0 times
...
Chantay
11 months ago
Hmm, I'm not sure about that. Executing the payload directly could be risky. Maybe we should try option C and see if we can find any matches in open source repositories first.
upvoted 0 times
...
Jennie
11 months ago
This seems like a pretty straightforward question. I'd go with option D and detonate the file in a sandbox to see what it does.
upvoted 0 times
...
Lashaunda
11 months ago
I'm pretty sure the answer is B, 15.4 W. The 802.3af standard specifies a maximum of 15.4 W per port for Power over Ethernet.
upvoted 0 times
...
Darnell
11 months ago
Ah, I remember learning about this in my insurance class. A reduction in reserves is an "unfavorable development," while an increase is an "advance development." I'm confident I can get this one right.
upvoted 0 times
...
Mireya
11 months ago
Could it be anticipation inventory? That seems a bit off, but I remember that one having something to do with expected demand.
upvoted 0 times
...
Tyisha
11 months ago
I think AWSR can remove log files after indexing, but I'm unclear if that's always the case. It was in a practice question we did.
upvoted 0 times
...
Millie
1 year ago
Oh, great, another email attachment with a suspicious name. It's like these hackers are trying to play 'Guess the Malware' with us. Let's just toss it in the sandbox and see what kind of digital fireworks we can cook up.
upvoted 0 times
Kaycee
1 year ago
True, but detonating it in a sandbox will give us a better understanding of its behavior.
upvoted 0 times
...
Peggy
1 year ago
Running the DLP Incident Summary Report could also provide valuable insights into the potential threat.
upvoted 0 times
...
Zena
1 year ago
I agree, we need to gather as much information as possible to determine if it's malicious.
upvoted 0 times
...
Chandra
1 year ago
Let's not take any chances, we should definitely detonate that file in a sandbox.
upvoted 0 times
...
Danilo
1 year ago
C: Running and analyzing the DLP Incident Summary Report could also provide valuable insights into the potential threat.
upvoted 0 times
...
Brent
1 year ago
B: Agreed, that's the best way to analyze the attachment and gather indicators of compromise.
upvoted 0 times
...
Celestine
1 year ago
A: Let's not waste any time, we should definitely obtain a copy of the file for detonation in a sandbox.
upvoted 0 times
...
...
Fanny
1 year ago
DLP Incident Summary Report? That's like trying to solve a murder mystery by reading the police blotter. Nah, I'm going with the sandbox option. At least that way, we can see the attachment in action and really get to the bottom of this.
upvoted 0 times
Maryanne
1 year ago
Agreed, let's not waste time with summaries. Let's go straight to the source and detonate that file.
upvoted 0 times
...
Tennie
1 year ago
I think that's the best way to gather more information and understand the potential threat.
upvoted 0 times
...
Helaine
1 year ago
Yeah, I agree. Let's get that file into a sandbox and see what it's up to.
upvoted 0 times
...
...
Hubert
1 year ago
YARA, huh? Sounds like a good old-fashioned detective work. But I'm not sure I'd want to go snooping around open source repositories. Who knows what kind of digital booby traps might be waiting for us there?
upvoted 0 times
Ming
1 year ago
B: I agree, it's important to proceed with caution when investigating suspicious attachments. Running the DLP Incident Summary Report might also provide valuable insights.
upvoted 0 times
...
Goldie
1 year ago
A: YARA is a powerful tool for threat hunting. It can help us identify any potential matches in open source repositories.
upvoted 0 times
...
...
Leslee
1 year ago
I'm feeling a bit like a lab rat here. Executing the payload? No way, I'm not going to be the guinea pig for that one. Let's stick to the sandbox, where we can observe the attachment's behavior safely.
upvoted 0 times
...
Gerald
1 year ago
Option D is clearly the way to go. Detonating the file in a sandbox is the best way to analyze it and gather indicators of compromise. Anything else would be like trying to defuse a bomb with your bare hands.
upvoted 0 times
...
Denise
1 year ago
I'm not sure, maybe we should also investigate further in open source repositories using YARA to find matches.
upvoted 0 times
...
Laura
1 year ago
I agree with Rosendo, detonating the file in a sandbox will help gather indicators of compromise.
upvoted 0 times
...
Rosendo
1 year ago
I think the next step should be to obtain a copy of the file for detonation in a sandbox.
upvoted 0 times
...

Save Cancel