ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 296 - CAS-004 discussion

Report
Export

A security solution uses a sandbox environment to execute zero-day software and collect indicators of compromise. Which of the following should the organization do to BEST take advantage of this solution?

A.
Develop an Nmap plug-in to detect the indicator of compromise.
Answers
A.
Develop an Nmap plug-in to detect the indicator of compromise.
B.
Update the organization's group policy.
Answers
B.
Update the organization's group policy.
C.
Include the signature in the vulnerability scanning tool.
Answers
C.
Include the signature in the vulnerability scanning tool.
D.
Deliver an updated threat signature throughout the EDR system
Answers
D.
Deliver an updated threat signature throughout the EDR system
Suggested answer: D

Explanation:

Delivering an updated threat signature throughout the endpoint detection and response (EDR) system is the best way to take advantage of the security solution that uses a sandbox environment to execute zero-day software and collect indicators of compromise. An EDR system is a solution that monitors and analyzes the activities and behaviors of endpoints, such as computers, mobile devices, or servers, and detects and responds to potential threats. An EDR system can use threat signatures, which are patterns or characteristics of known malicious software or attacks, to identify and block malicious activities on endpoints. By delivering an updated threat signature based on the indicators of compromise collected from the sandbox environment, the organization can enhance its EDR system's ability to detect and prevent zero-day attacks that exploit unknown vulnerabilities. Verified

Reference:

https://www.cisco.com/c/en/us/products/security/what-is-endpoint-detection-response.html

https://www.crowdstrike.com/epp-101/what-is-a-sandbox/

asked 02/10/2024
Avinash Kumar
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first