ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 279 - CS0-003 discussion

Report
Export

A security analyst has identified a new malware file that has impacted the organization. The malware is polymorphic and has built-in conditional triggers that require a connection to the internet. The CPU has an idle process of at least 70%. Which of the following best describes how the security analyst can effectively review the malware without compromising the organization's network?

A.
Utilize an RDP session on an unused workstation to evaluate the malware.
Answers
A.
Utilize an RDP session on an unused workstation to evaluate the malware.
B.
Disconnect and utilize an existing infected asset off the network.
Answers
B.
Disconnect and utilize an existing infected asset off the network.
C.
Create a virtual host for testing on the security analyst workstation.
Answers
C.
Create a virtual host for testing on the security analyst workstation.
D.
Subscribe to an online service to create a sandbox environment.
Answers
D.
Subscribe to an online service to create a sandbox environment.
Suggested answer: D

Explanation:

A sandbox environment is a safe and isolated way to analyze malware without affecting the organization's network. An online service can provide a sandbox environment without requiring the security analyst to set up a virtual host or use an RDP session. Disconnecting and using an existing infected asset is risky and may not provide accurate results.

Reference: Malware Analysis: Steps & Examples, Dynamic Analysis

asked 02/10/2024
Martin Schwarz
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first