Cisco CyberOps Associate (CBROPS) 200-201Host-Based AnalysisMedium

A security analyst receives an alert from an EDR solution indicating a 'Suspicious Parent-Child Process Relationship' on a critical server. The alert details show `cmd.exe` spawning `powershell.exe`, which then executes an encoded command, all originating from an unexpected user context. To quickly pivot and investigate other potential indicators of compromise (IOCs) related to this specific event across other endpoints, which type of data, commonly collected by EDR, would be most valuable for a centralized search?

  1. ADNS query logs
  2. BNetwork flow data (NetFlow)
  3. CUser authentication logs
  4. DProcess creation events
Show answer & explanation

Correct answer: D. Process creation events

Process creation events (e.g., Sysmon Event ID 1 on Windows) provide crucial details like parent-child relationships, command-line arguments, and user context. These events are highly valuable for identifying similar suspicious activity across an environment, as the specific process chain and command arguments are strong IOCs.

Why the other options are wrong

  • A. DNS query logs are useful for identifying C2 infrastructure but don't directly show the parent-child process relationships or command execution on the host.
  • B. Network flow data provides high-level connection information but lacks the detail of specific process execution or command lines.
  • C. User authentication logs show login activity but not the specific process execution details of a compromised session.

Process Creation Events (EDR)

Detailed logs captured by EDR solutions that record when a new process is created, including its parent process, command-line arguments, and user context.

  • Crucial for identifying suspicious execution chains.
  • Enables detection of living-off-the-land techniques.
  • Often includes process hash, user, and execution path.

Memory trick: An EDR needs to 'see' every 'process', 'file', and 'network' move to understand the whole story.

More Host-Based Analysis questions