GIAC
GREM · Question #96
Why would an analyst examine the timestamps within the metadata of a suspected malware file?
The correct answer is B. To understand when the malware was created or last modified. See the full explanation below for the reasoning.
Question
Why would an analyst examine the timestamps within the metadata of a suspected malware file?
Options
- ATo check for time-based triggers within the malware
- BTo understand when the malware was created or last modified
- CTo determine the malware's expiration date
- DTo assess the file's relevance to a specific malware campaign
How the community answered
(23 responses)- A13% (3)
- B78% (18)
- C4% (1)
- D4% (1)
Community Discussion
No community discussion yet for this question.