nerdexam
CrowdStrike

CCFR-201B · Question #30

When analyzing an executable with a global prevalence of common; but you do not know what the executable is, what is the best course of action?

The correct answer is B. From detection, click the VT Hash button to pivot to VirusTotal to investigate further. You've hit your limit · resets 12:50am (America/New_York)

Detection Triage and Investigation

Question

When analyzing an executable with a global prevalence of common; but you do not know what the executable is, what is the best course of action?

Options

  • ADo nothing, as this file is common and well known
  • BFrom detection, click the VT Hash button to pivot to VirusTotal to investigate further
  • CFrom detection, use API manager to create a custom blocklist
  • DFrom detection, submit to FalconX for deep dive analysis

How the community answered

(23 responses)
  • A
    17% (4)
  • B
    74% (17)
  • C
    4% (1)
  • D
    4% (1)

Explanation

You've hit your limit · resets 12:50am (America/New_York)

Topics

#Global Prevalence#VirusTotal#investigation workflow#unknown executable

Community Discussion

No community discussion yet for this question.

Full CCFR-201B Practice