ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 299 - CS0-003 discussion

Report
Export

A security analyst is performing an investigation involving multiple targeted Windows malware binaries. The analyst wants to gather intelligence without disclosing information to the attackers. Which of the following actions would allow the analyst to achieve the objective?

A.
Upload the binary to an air-gapped sandbox for analysis.
Answers
A.
Upload the binary to an air-gapped sandbox for analysis.
B.
Send the binaries to the antivirus vendor.
Answers
B.
Send the binaries to the antivirus vendor.
C.
Execute the binaries on an environment with internet connectivity.
Answers
C.
Execute the binaries on an environment with internet connectivity.
D.
Query the file hashes using VirusTotal.
Answers
D.
Query the file hashes using VirusTotal.
Suggested answer: A

Explanation:

An air-gapped sandbox is a virtual machine or a physical device that is isolated from any network connection. This allows the analyst to safely execute the malware binaries and observe their behavior without risking any communication with the attackers or any damage to other systems. Uploading the binary to an air-gapped sandbox is the best option to gather intelligence without disclosing information to the attackers12

Reference: 1: Dynamic Analysis of a Windows Malicious Self-Propagating Binary 2: GitHub - mikesiko/PracticalMalwareAnalysis-Labs: Binaries for the book Practical Malware Analysis

asked 02/10/2024
Pungava Gowda
29 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first