ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 206 - CS0-003 discussion

Report
Export

An incident response analyst is investigating the root cause of a recent malware outbreak. Initial binary analysis indicates that this malware disables host security services and performs cleanup routines on it infected hosts, including deletion of initial dropper and removal of event log entries and prefetch files from the host. Which of the following data sources would most likely reveal evidence of the root cause?

(Select two).

A.
Creation time of dropper
Answers
A.
Creation time of dropper
B.
Registry artifacts
Answers
B.
Registry artifacts
C.
EDR data
Answers
C.
EDR data
D.
Prefetch files
Answers
D.
Prefetch files
E.
File system metadata
Answers
E.
File system metadata
F.
Sysmon event log
Answers
F.
Sysmon event log
Suggested answer: B, C

Explanation:

Registry artifacts and EDR data are two data sources that can provide valuable information about the root cause of a malware outbreak. Registry artifacts can reveal changes made by the malware to the system configuration, such as disabling security services, modifying startup items, or creating persistence mechanisms1. EDR data can capture the behavior and network activity of the malware, such as the initial infection vector, the command and control communication, or the lateral movement2. These data sources can help the analyst identify the malware family, the attack technique, and the threat actor behind the outbreak.

asked 02/10/2024
Sharanjit Kareer
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first