Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 5Objective 2

5.2 Detect, Analyze, and Mitigate Malware Incidents CCIE-SECURITY Practice Questions (Page 7)

Part of the 5.0 Advanced Threat Protection and Content Security domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)

54questions here
11free pages
8concepts
20%of the exam

Questions 31–35

  1. 31application · medium

    A security analyst receives an email with an attachment that is suspected to be malware. The analyst wants to safely analyze the attachment without risking the corporate network. Which method should the analyst use?

    Select an answer first
  2. 32application · medium

    During a malware incident, the incident response team has identified several indicators of compromise (IOCs) including file hashes, domains, and IP addresses. The team wants to determine if other hosts in the environment are affected. What is the most efficient way to search for these IOCs across the enterprise?

    Select an answer first
  3. 33application · medium

    After containing a malware incident, the incident response team is preparing a post-incident report. What should be included in the report to ensure lessons learned are captured for future prevention?

    Select an answer first
  4. 34application · medium

    A security analyst is investigating a suspicious file that was downloaded from the internet. The file is not detected by signature-based antivirus, but the analyst suspects it may be malicious. Which detection technique would be most effective in identifying this unknown malware?

    Select an answer first
  5. 35application · medium

    A security analyst at a financial firm notices that an employee received an email with a link to a file-sharing site. The link is not on any blocklist, but the domain was registered 48 hours ago. The analyst must determine if the file is malicious without risking the corporate network. Which approach best balances safety and speed?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.