Cisco CyberOps Associate (CBROPS) 200-201Host-Based AnalysisMedium
A security analyst is investigating a suspected malware infection on a Windows workstation. Initial scans by the endpoint detection and response (EDR) solution have flagged several suspicious processes, but no definitive malicious payload has been identified. The analyst wants to understand the behavior of one particular process, `svchost.exe`, which is showing unusual network activity. Which host-based analysis technique would be most effective for gaining deeper insight into this process's actions without directly interacting with the potentially compromised system?
- ADynamic analysis in a sandbox environment.
- BStatic malware analysis of the `svchost.exe` binary.
- CLive memory forensics to dump and analyze the process memory.
- DNetwork packet capture on the workstation's interface.
Show answer & explanationAnswer & explanation
Correct answer: A. Dynamic analysis in a sandbox environment.
Dynamic analysis in a sandbox allows the analyst to observe the process's behavior, including network connections, file system changes, and registry modifications, in a controlled and isolated environment without risking further compromise of the production system.
Why the other options are wrong
- B. Static analysis reveals the potential capabilities but not the actual runtime behavior or network activity of the process.
- C. Live memory forensics is effective but involves direct interaction with the compromised system and is more complex than initial behavioral analysis.
- D. Network packet capture on the workstation would confirm network activity but wouldn't provide insight into the process's internal actions or file system/registry changes.
Dynamic Malware Analysis
The process of executing suspicious code in a controlled environment (sandbox) to observe its behavior and understand its functionality.
- Observes real-time execution.
- Identifies network communication, file system changes, registry modifications.
- Performed in an isolated environment to prevent infection.
Memory trick: To catch a sneaky bug, you either dissect it still or watch it run free (but safely!).