ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 270 - SY0-601 discussion

Report
Export

A security operations center wants to implement a solution that can execute files to test for malicious activity. The solution should provide a report of the files' activity against known threats. Which of the following should the security operations center implement?

A.
theHarvester
Answers
A.
theHarvester
B.
Nessus
Answers
B.
Nessus
C.
Cuckoo
Answers
C.
Cuckoo
D.
Sn1per
Answers
D.
Sn1per
Suggested answer: C

Explanation:

Cuckoo is a sandbox that is specifically written to run programs inside and identify any malware. A sandbox is a virtualized environment that isolates the program from the rest of the system and monitors its behavior. Cuckoo can analyze files of various types, such as executables, documents, URLs, and more. Cuckoo can provide a report of the files’ activity against known threats, such as network traffic, file operations, registry changes, API calls, and so on. A security operations center can implement Cuckoo to execute files to test for malicious activity and generate a report of the analysis. Cuckoo can help the security operations center to detect and prevent malware infections, investigate incidents, and perform threat intelligence.

asked 02/10/2024
Priti Agrawal
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first