🔥 3-day streak
Cisco CCNA Cybersecurity (200-201 CCNACBR)105 / 145
Question 105 of 145

An analyst detonates a suspicious executable in a sandbox. The output report shows the following observed behaviors: a child process spawned, a file written to %APPDATA%, and an outbound DNS query to 'update-svc.badhost[.]net' followed by an HTTPS connection to 175.120.44.9 on port 443. Based on this section of the report, which type of indicator is MOST directly identified by the DNS query and HTTPS connection?

Reviewed for accuracy · Report an issueNext question