QuestionQ94

Forensics Processes

Question Image

Refer to the exhibit. A company employee receives an email from a customer that contains a Microsoft Word attachment. As soon as the employee opens the attachment, the workstation starts behaving strangely and unusual pop-ups appear. Later that day, another workstation in the same department exhibits the same behavior. The security administrator analyzes the first workstation (Patient 0) in a sandbox environment and identifies several threats. What must the administrator determine next?

  • A if Patient 0 still demonstrates suspicious behavior
  • B source code of the malicious attachment
  • C if the file in Patient 0 is encrypted
  • D if Patient 0 tried to connect to another workstation
Explanation

A second workstation showing the same symptoms after Patient 0 was infected raises the possibility that the malware propagated through lateral movement. Determining whether Patient 0 attempted to connect to another workstation helps establish the infection path and scope of the compromise.

Community Discussion

No comments yet. Be the first to start the discussion!