🔥 3-day streak
Cisco CCNP Cybersecurity CBRCOR (350-201)62 / 147
Question 62 of 147

During dynamic analysis of a suspicious executable, an analyst notices that the sample runs briefly, performs no observable network or file activity, and then exits cleanly in the sandbox. However, endpoint telemetry from an infected production host shows extensive persistence and C2 traffic from the same binary. Which conclusion best explains this discrepancy, and what is the appropriate next step?

Reviewed for accuracy · Report an issueNext question