GIAC
GREM · Question #167
In malware analysis, what is the purpose of comparing the hash of a suspicious file to known malware databases?
The correct answer is C. To potentially identify the malware and its known behaviors. See the full explanation below for the reasoning.
Question
In malware analysis, what is the purpose of comparing the hash of a suspicious file to known malware databases?
Options
- ATo identify the file's original author
- BTo determine the exact changes made to the system by the malware
- CTo potentially identify the malware and its known behaviors
- DTo understand the network behavior of the malware
How the community answered
(20 responses)- B15% (3)
- C80% (16)
- D5% (1)
Community Discussion
No community discussion yet for this question.