🔥 3-day streak
Cisco CCNP Cybersecurity CBRCOR (350-201)124 / 147
Question 124 of 147

A malware sample is detonated in an automated sandbox. The behavioral report shows the process spawning svchost.exe, writing a file to %AppData%, and making outbound DNS queries to hundreds of pseudo-random hostnames (e.g., xkjdlqwe.biz, plmqoazx.net) before one resolves and an HTTPS session begins. Which artifact from this run is the MOST useful host-based Indicator of Compromise (IOC) for detecting the same infection on other endpoints?

Reviewed for accuracy · Report an issueNext question