CCFA-200B · Question #27
Which of the following options is a feature found ONLY with the Sensor-based Machine Learning (ML)?
The correct answer is D. Identification and analysis of unknown executables. According to documentation (documentation/detections/technique/sensor-based-ml-cst0007): CrowdStrike sensor-based machine learning (ML) identifies and analyzes unknown executables as they run on hosts. This technique is triggered by files and file attributes associated with…
Question
Which of the following options is a feature found ONLY with the Sensor-based Machine Learning (ML)?
Options
- ANext-Gen Antivirus (NGAV) protection
- BAdware and Potentially Unwanted Program detection and prevention
- CReal-time offline protection
- DIdentification and analysis of unknown executables
How the community answered
(39 responses)- A13% (5)
- B5% (2)
- C3% (1)
- D79% (31)
Explanation
According to documentation (documentation/detections/technique/sensor-based-ml-cst0007): CrowdStrike sensor-based machine learning (ML) identifies and analyzes unknown executables as they run on hosts. This technique is triggered by files and file attributes associated with known malware. This is similar to the Cloud- basedML technique. Cloud-based ML is informed by global analysis of executables that classifies and identifies malware. The key difference is that it doesn't run on hosts when they're offline.
Topics
Community Discussion
No community discussion yet for this question.