🔥 3-day streak
Cisco CCNA Cybersecurity (200-201 CCNACBR)106 / 145
Question 106 of 145

An analyst detonates a suspicious executable in a sandbox. The output report shows the following activity: the file wrote a copy of itself to %APPDATA%, created a value under HKCU\Software\Microsoft\Windows\CurrentVersion\Run pointing to that copy, spawned a child process, and made an outbound DNS query to a newly registered domain. Which behavior in the report indicates the malware is attempting to establish persistence on the host?

Reviewed for accuracy · Report an issueNext question