Câu 7: 300-220: Conducting Threat Hunting and Defending using Cisco Technologies for Cybersecurity
An analyst receives a report that states that the infection chain begins with a phishing email that contains a malicious download link. When the victim downloads the malicious RAR file, the archive needs a specific password to extract, which reveals a fake PDF executable malware and an image printing file. After the m…
Nội dung câu hỏi
An analyst receives a report that states that the infection chain begins with a phishing email that contains a malicious download link. When the victim downloads the malicious RAR file, the archive needs a specific password to extract, which reveals a fake PDF executable malware and an image printing file. After the malware is decrypted and the fake PDF executable is run, an automatic execution of the embedded LummaC2 or Rhadamanthys information stealer occurs, which then collects the victim’s credentials and data, and sends them back to the C2 server. Which conclusion should the analyst draw about the threat actor?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. The threat actor is focused on stealing sensitive information and may also aim to disrupt operations as a secondary objective after achieving the first one.
- B. The threat actor is likely engaged in opportunistic attacks without a clear target profile, focusing on broad-based phishing tactics to maximize reach.
- C. The threat actor is using a multi-stage attack to bypass security measures and exfiltrate sensitive information as the main objective of the operation. — đáp án hiện tại
- D. The threat actor is employing sophisticated techniques to gain initial access and uses malware to move laterally and maintain persistence across network.
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.