QuestionQ53

Threat Hunting Processes

The security team detects an alert for a potentially malicious file named Financial_Data_123456789.pdf that a user downloaded. After reviewing SIEM logs and Cisco Secure Endpoint, the team confirms that the file was obtained from an untrusted website. Hash analysis of the file returns an unknown status.

Which action must be taken next?

Explanation

A file with an unknown hash status from an untrusted source requires behavioral analysis to establish whether it is malicious. Sandboxing executes or observes the file in an isolated environment and provides the evidence needed to determine its threat level without exposing the user’s workstation.

Community Discussion

No comments yet. Be the first to start the discussion!