Q6Fundamentals
An employee misused PowerShell commands and script interpreters, resulting in an indicator of compromise (IOC) trigger. The IOC event indicates that a known malicious file was executed and that the likelihood of a breach is increased. Which indicator produced this IOC event?
← → navigate · a answer
Community votes
Discussion · 9
5
Crossrider is an unwanted app and not related with PS/script interpreters. In AMP4E console IoC list, ExecutedMalware.IoC describes it as a malicious file executed. Answer is A
2
I think B is correct since Crossrider is malware. This malware is part of the Adware family.
1
Correct. B.
1
Crossrider.ioc
Crossrider is an Adware variant that targets Mac with the intent of showing ads. It also changes the default home page of Safari and Chrome browsers.
W32.AccesschkUtility.ioc
Accesscheck is a Windows utility that lets users check for access rights on resources including files, directories, registry keys, global objects and Windows services. This utility could be used by malware or threat actors with malicious intent such as collecting information needed for privilege escalation on the compromised host. This indicator monitors for accesschk tool used with suspicious options that suppress errors and dialog boxes.
ExecutedMalware.ioc
A known malicious file was executed. This increases the likelihood of a successful breach and this event should be promptly investigated.
Answer is A
1
From the Cisco website; As an example, if the following malicious file is executed, it will be detected as "Cloud IOC ExecutedMalware.ioc". So Answer is A
1
Without more information on the IOC event, it is not possible to tell which indicator generated it. However, the fact that a known malicious file has been executed suggests that the ExecutedMalware.ioc may have been triggered. - ChatGPT
1
took the test last week, this was a test question
A 1
Selected Answer: A
ChatGPT: Since the IOC event is tied to a known malicious file being executed, the best fit would be ExecutedMalware.ioc.
A 1
Selected Answer: A
IOC triggered by a known malicious file being executed = ExecutedMalware.ioc