Conducting Threat Hunting and Defending using Cisco Technologies for Cybersecurity
60 questions across 1 topics, with suggested answers, explanations where available, and imported community discussion. The first 6 questions are free to preview.
Topics
| # | Topic | Questions | Free |
|---|---|---|---|
| 1 | Threat Hunting Fundamentals | 60 | 6 |
Preview
6 of 60 accessibleHow does integrating multiple products improve data visibility and analysis within a corporate environment?
An analyst receives a report stating that the infection chain starts with a phishing email containing a malicious download link. When the victim downloads the malicious RAR file, the archive requires a specific password for extraction, revealing a fake PDF executable malware file and an image printing file. After the malware is decrypted and the fake PDF executable is run, the embedded LummaC2 or Rhadamanthys information stealer executes automatically, collects the victim’s credentials and data, and sends them to the C2 server. Which conclusion should the analyst make about the threat actor?
Refer to the exhibit. What distinguishes the procedures used by each APT group?