Cisco CCNP Security Core (SCOR) 350-701Network SecurityHard

A network security architect is designing a solution to protect against zero-day exploits and advanced persistent threats (APTs) that bypass traditional signature-based detection. The solution needs to analyze unknown files and URLs in a safe, isolated environment before they reach end-user systems. Which technology is best suited for this purpose?

  1. ASandbox (Threat Emulation)
  2. BData Loss Prevention (DLP)
  3. CSecurity Information and Event Management (SIEM)
  4. DIntrusion Detection System (IDS)
Show answer & explanation

Correct answer: A. Sandbox (Threat Emulation)

A sandbox, or threat emulation technology, is specifically designed to execute suspicious files and analyze URLs in a virtual, isolated environment. This allows it to observe malicious behavior, including zero-day exploits and APTs, without risking the actual network. IDS primarily detects known attack patterns. SIEM aggregates logs for analysis. DLP prevents sensitive data exfiltration.

Why the other options are wrong

  • B. DLP focuses on preventing sensitive data from leaving the organization and is not designed for analyzing unknown malware.
  • C. A SIEM aggregates and analyzes security logs but does not actively execute or analyze unknown files in isolation.
  • D. An IDS primarily detects known attack signatures or anomalies, which may be ineffective against zero-day exploits and APTs.

Threat Emulation (Sandboxing)

Threat emulation, often implemented via sandboxing, involves executing suspicious files or URLs in a virtual, isolated environment to observe and analyze their behavior for malicious activity without risking the production network.

  • Detects zero-day exploits and APTs.
  • Analyzes unknown files and URLs.
  • Operates in a safe, isolated environment.

Memory trick: To catch new monsters, you need a safe cage.

More Network Security questions