A security analyst receives an alert that there was an attempt to download known malware. Which of the following actions would allow the best chance to analyze the malware?
Choose an answer
Tap an option to check your answer.
Correct answer: Obtain and execute the malware in a sandbox environment and perform packet captures..
Why this is the answer
Executing the malware in a sandbox environment allows for safe observation of its behavior without risking the production network. Packet captures during execution provide detailed information on network communication, including command-and-control (C2) servers, data exfiltration attempts, and other network-based actions. This combination offers the most comprehensive analysis of the malware's functionality. Reviewing IPS logs only shows blocked C2 IPs, not the malware's full behavior. Analyzing application logs might reveal persistence attempts but won't show the initial infection vector or network activity. Running vulnerability scans identifies potential weaknesses but doesn't analyze the specific malware in question.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed