CrowdStrike
CCFR-201B · Question #30
When analyzing an executable with a global prevalence of common; but you do not know what the executable is, what is the best course of action?
The correct answer is B. From detection, click the VT Hash button to pivot to VirusTotal to investigate further. You've hit your limit · resets 12:50am (America/New_York)
Detection Triage and Investigation
Question
When analyzing an executable with a global prevalence of common; but you do not know what the executable is, what is the best course of action?
Options
- ADo nothing, as this file is common and well known
- BFrom detection, click the VT Hash button to pivot to VirusTotal to investigate further
- CFrom detection, use API manager to create a custom blocklist
- DFrom detection, submit to FalconX for deep dive analysis
How the community answered
(23 responses)- A17% (4)
- B74% (17)
- C4% (1)
- D4% (1)
Explanation
You've hit your limit · resets 12:50am (America/New_York)
Topics
#Global Prevalence#VirusTotal#investigation workflow#unknown executable
Community Discussion
No community discussion yet for this question.