Hard 350-201 practice questions
Challenge — multi-step scenarios, trade-offs, and subtle distinctions. 7 hard questions available — no sign-up, always free.
During dynamic analysis of a suspicious executable, an analyst notices that the sample runs briefly, performs no observable network or file activity, and then exits cleanly in the sandbox. However, endpoint telemetry from an infected production host shows extensive persistence and C2 traffic from the same binary. Which conclusion best explains this discrepancy, and what is the appropriate next step?
During analysis of a suspicious Windows executable, an analyst runs a static examination and finds almost no readable strings, high section entropy, and an unusually small import table containing only LoadLibrary and GetProcAddress. Dynamic execution in the sandbox shows the process allocating a large region of memory marked RWX and then jumping into it. Which conclusion and next step best fit these findings?
A SOC analyst reviews a critical unpatched vulnerability (CVSS 9.1) on a legacy manufacturing control server. The vendor no longer supports the operating system, and applying the upstream OS patch would break the proprietary application that must remain in production. What is the most appropriate patching recommendation for this asset?
A SOC analyst is investigating potential data loss from a SaaS collaboration platform. The alert indicates that a large volume of files was downloaded from a corporate cloud storage account over the weekend, but the corporate identity provider logs show no interactive sign-in events from the affected user during that window. Which investigative action should the analyst prioritize to determine how the data was accessed?
An analyst detonates a suspicious executable in an automated sandbox. The report shows the sample writes a randomly named DLL to %AppData%, creates a registry Run key, then contacts three different domains that each resolve to the same IP block and use identical TLS certificate serial numbers. The analyst wants to produce a durable, high-fidelity detection artifact that will still match future variants of this malware family even if the file hash changes. Which action produces the most effective complex indicator?
A malware sample is detonated in an automated sandbox. The behavioral report shows the process spawning svchost.exe, writing a file to %AppData%, and making outbound DNS queries to hundreds of pseudo-random hostnames (e.g., xkjdlqwe.biz, plmqoazx.net) before one resolves and an HTTPS session begins. Which artifact from this run is the MOST useful host-based Indicator of Compromise (IOC) for detecting the same infection on other endpoints?
A vulnerability scanner reports a critical flaw (CVSS Base score 9.1) on 40 servers across the enterprise. During triage, the SOC analyst discovers that 35 of these servers are internal-only development boxes containing no sensitive data, while 5 are internet-facing systems processing customer financial transactions. Company policy requires prioritizing remediation using industry scoring systems. What should the analyst do to most accurately re-prioritize these findings for risk analysis?