CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 56: 312-39V2: Certified SOC Analyst (CSA) v2

The SOC team at a national cybersecurity agency has detected anomalous network traffic originating from a sensitive government server. Initial analysis suggests a potential intrusion, leading the SOC team to escalate the incident to the forensic team for deeper investigation. Upon forensic examination, the team discov…

Nội dung câu hỏi

The SOC team at a national cybersecurity agency has detected anomalous network traffic originating from a sensitive government server. Initial analysis suggests a potential intrusion, leading the SOC team to escalate the incident to the forensic team for deeper investigation. Upon forensic examination, the team discovers a trojan on the compromised server. The trojan is suspected of engaging in data exfiltration, raising concerns about potential backdoor access and long-term persistence mechanisms employed by the malware. Given the severity of the situation, the lead malware analyst is tasked with conducting an in-depth analysis of the trojan to determine its capabilities (e.g., command execution, privilege escalation, keylogging), its persistence mechanisms (e.g., registry modifications, scheduled tasks, startup entries), and any backdoor functionalities (e.g., remote access, hidden communication channels). However, due to the sensitive nature of the system and the risk of unintended execution, the analyst must analyze the trojan's binary code at the instruction level without actually executing it. Which technique should the forensic analyst use?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Malware Disassembly — đáp án hiện tại
  2. B. Network Behavior Monitoring
  3. C. Dynamic Code Injection
  4. D. Interactive Debugging

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề