ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 61 - CS0-003 discussion

Report
Export

A security analyst is performing an investigation involving multiple targeted Windows malware binaries. The analyst wants to gather intelligence without disclosing information to the attackers. Which of the following actions would allow the analyst to achieve the objective?

A.
Upload the binary to an air gapped sandbox for analysis
Answers
A.
Upload the binary to an air gapped sandbox for analysis
B.
Send the binaries to the antivirus vendor
Answers
B.
Send the binaries to the antivirus vendor
C.
Execute the binaries on an environment with internet connectivity
Answers
C.
Execute the binaries on an environment with internet connectivity
D.
Query the file hashes using VirusTotal
Answers
D.
Query the file hashes using VirusTotal
Suggested answer: A

Explanation:

The best action that would allow the analyst to gather intelligence without disclosing information to the attackers is to upload the binary to an air gapped sandbox for analysis. An air gapped sandbox is an isolated environment that has no connection to any external network or system. Uploading the binary to an air gapped sandbox can prevent any communication or interaction between the binary and the attackers, as well as any potential harm or infection to other systems or networks. An air gapped sandbox can also allow the analyst to safely analyze and observe the behavior, functionality, or characteristics of the binary.

asked 02/10/2024
SERGIO FREITAS
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first