🔥 3-day streak
Cisco CCNP Cybersecurity CBRCOR (350-201)64 / 147
Question 64 of 147
A malware analyst has already completed static triage (hashing, string extraction) and dynamic execution in a sandbox for a suspicious binary. The behavioral report shows the sample connects to a C2 server, but the exact command structure and encryption routine used for exfiltration remain unclear because the traffic is encoded. The analyst needs to fully understand the algorithm the malware uses to encode its C2 payloads. Which analysis technique should be performed next to obtain this level of detail?
Reviewed for accuracy · Report an issueNext question