🔥 3-day streak
Cisco CCNA Cybersecurity (200-201 CCNACBR)102 / 145
Question 102 of 145
During analysis of a suspicious executable, an analyst uploads the file to a detonation chamber. The sandbox report's static analysis section shows a benign import table and no known signature match, but the dynamic analysis section records the process spawning cmd.exe, writing to the Startup folder, and initiating an outbound TCP connection to a rare foreign IP. Which conclusion is best supported by this sandbox output?
Reviewed for accuracy · Report an issueNext question