Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 350-201 Exam - Topic 4 Question 128 Discussion

An employee abused PowerShell commands and script interpreters, which lead to an indicator of compromise (IOC) trigger. The IOC event shows that a known malicious file has been executed, and there is an increased likelihood of a breach. Which indicator generated this IOC event?
D) W32 AccesschkUtility.ioc
A) ExecutedMalware.ioc
B) Crossrider.ioc
C) ConnectToSuspiciousDomain.ioc

Cisco 350-201 Exam - Topic 4 Question 128 Discussion

Actual exam question for Cisco's 350-201 exam
Question #: 128
Topic #: 4
[All 350-201 Questions]

An employee abused PowerShell commands and script interpreters, which lead to an indicator of compromise (IOC) trigger. The IOC event shows that a known malicious file has been executed, and there is an increased likelihood of a breach. Which indicator generated this IOC event?

Show Suggested Answer Hide Answer
Suggested Answer: D

Contribute your Thoughts:

0/2000 characters
Reita
3 days ago
C) ConnectToSuspiciousDomain.ioc could also apply if they connected to a bad site.
upvoted 0 times
...
Marilynn
8 days ago
True, but A is more direct for this scenario.
upvoted 0 times
...
Dottie
13 days ago
But what about B) Crossrider.ioc? It's known malware too.
upvoted 0 times
...
Kirby
19 days ago
I agree, A makes sense. Malicious file executed.
upvoted 0 times
...
Cyril
24 days ago
I think it's A) ExecutedMalware.ioc. Seems most relevant.
upvoted 0 times
...
Cyndy
29 days ago
I’m surprised this happened with PowerShell. Isn’t it supposed to be secure?
upvoted 0 times
...
Linn
1 month ago
Wait, are we sure it’s not D) W32 AccesschkUtility.ioc? That’s a bit odd.
upvoted 0 times
...
Anjelica
1 month ago
C) ConnectToSuspiciousDomain.ioc seems plausible too.
upvoted 0 times
...
Lonny
1 month ago
I think it could be B) Crossrider.ioc. Not so sure about A.
upvoted 0 times
...
Gary
2 months ago
Definitely A) ExecutedMalware.ioc. Makes sense!
upvoted 0 times
...
Yan
2 months ago
I’m leaning towards ExecutedMalware.ioc, but I’m not completely confident. The other options seem plausible too.
upvoted 0 times
...
Pok
2 months ago
I think the IOC is likely related to executed malware, but I wonder if the suspicious domain could also be a factor.
upvoted 0 times
...
Hildred
2 months ago
I feel like I've seen a question like this before. Crossrider sounds familiar, but I can't recall if it was specifically about PowerShell abuse.
upvoted 0 times
...
Stephane
2 months ago
I remember studying IOC events, but I'm not entirely sure which one fits here. I think it might be related to executed malware.
upvoted 0 times
...

Save Cancel