🔥 3-day streak
Cisco CCNP Cybersecurity CBRCOR (350-201)67 / 147
Question 67 of 147
During analysis of a suspicious Windows executable, an analyst runs a static examination and finds almost no readable strings, high section entropy, and an unusually small import table containing only LoadLibrary and GetProcAddress. Dynamic execution in the sandbox shows the process allocating a large region of memory marked RWX and then jumping into it. Which conclusion and next step best fit these findings?
Reviewed for accuracy · Report an issueNext question