
CCIE Security
Domain 5Objective 2
5.2 Detect, Analyze, and Mitigate Malware Incidents CCIE-SECURITY Practice Questions (Page 6)
Part of the 5.0 Advanced Threat Protection and Content Security domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
8concepts
20%of the exam
Questions 26–30
- 26
A security operations team is evaluating a new malware detection tool. The tool uses a combination of signature-based, behavioral, and heuristic analysis. During a proof-of-concept, the tool failed to detect a known malware sample that was packed with a custom packer. Which detection technique is most likely to have failed?
Select an answer first - 27
A security analyst has captured a suspicious executable from an infected host. The analyst needs to quickly determine if this file is related to a known malware family and identify its command-and-control (C2) server. The analyst has limited time and cannot risk executing the file on a production system. Which analysis method should the analyst use first?
Select an answer first - 28
A company has confirmed a ransomware outbreak on several workstations in the finance department. The malware is encrypting files and spreading to network shares. The incident response team has been activated. What should be the immediate next step in the incident response process?
Select an answer first - 29
A hospital network has experienced a malware infection that spread rapidly from an infected laptop to multiple servers via the internal network. The IT security team wants to implement a mitigation strategy to prevent such lateral movement in the future. Which strategy would be most effective?
Select an answer first - 30
A security team is evaluating how to improve their malware detection capabilities. They currently rely solely on signature-based antivirus. They want to incorporate threat intelligence feeds to detect emerging threats. Which approach would best integrate threat intelligence into their existing detection infrastructure?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.