A security operations center (SOC) analyst receives a high-priority alert for an email with a suspicious, unknown executable file sent to a senior executive. To analyze the file's behavior and potential threat without jeopardizing the production network or the user's workstation, which of the following is the most appropriate initial action for the analyst to take?
Forward the executable to a third-party antivirus vendor for signature creation.
Run a full antivirus scan on the executive's workstation.
Execute the file within an isolated virtual environment to observe its behavior.
Immediately delete the email from the executive's inbox to prevent execution.
The correct action is to execute the file in a sandbox. A sandbox is an isolated, controlled environment where potentially malicious code can be run and analyzed without affecting the production system or network. This allows the analyst to observe the file's behavior, such as network connections, file modifications, or registry changes, to determine if it is malicious. Deleting the email removes the immediate threat but prevents analysis. Running a local AV scan may not detect an unknown or zero-day threat. Forwarding to a vendor is a valid step but not the best initial action for immediate internal analysis.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
How does a sandbox work in cybersecurity?
Open an interactive chat with Bash
What are common uses of sandboxes in security operations?
Open an interactive chat with Bash
What’s the difference between a virtual machine and a sandbox?
Open an interactive chat with Bash
ISC2 CISSP
Security Operations
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .