Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 5Objective 2

5.2 Detect, Analyze, and Mitigate Malware Incidents CCIE-SECURITY Practice Questions (Page 5)

Part of the 5.0 Advanced Threat Protection and Content Security domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)

54questions here
11free pages
8concepts
20%of the exam

Questions 21–25

  1. 21expert · hard

    A large enterprise has a mature security operations center (SOC) that uses a commercial threat intelligence platform (TIP) to aggregate multiple feeds. The SOC is experiencing a high volume of alerts from a new feed that lists IP addresses with a low confidence score. Analysts are spending too much time investigating false positives. The SOC manager wants to reduce alert fatigue while maintaining detection of genuine threats. What should the SOC do?

    Select an answer first
  2. 22expert · hard

    A security team is using a sandboxing solution to analyze suspicious files. The sandbox is configured to emulate a Windows 10 environment with common applications. Recently, a malware sample was submitted but the sandbox reported it as benign. However, later analysis revealed the malware only executes when it detects a specific USB drive is present. Why did the sandbox fail to detect the malware?

    Select an answer first
  3. 23expert · hard

    During a ransomware incident, the incident response team has isolated the affected systems and eradicated the malware. However, the team is concerned about re-infection because the initial attack vector was a phishing email that bypassed the email gateway. The team wants to implement a long-term mitigation to reduce the risk of similar incidents. Which combination of actions would be most effective?

    Select an answer first
  4. 24expert · hard

    A security analyst is investigating a malware campaign that uses a common phishing lure. The analyst has identified several IOCs, including a set of file hashes and domains. The analyst wants to determine if the campaign is related to a known threat actor group. Which approach would be most effective?

    Select an answer first
  5. 25expert · hard

    After a major malware incident, the incident response team is writing the final report. The report will be shared with executive management and the board of directors. What is the most important aspect to include in the report for this audience?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.