nerdexam
Netskope

NSK100 · Question #40

You investigate a suspected malware incident and confirm that it was a false alarm.

The correct answer is D. Add the hash to the file filter. A file filter is a list of file hashes that you can use to exclude files from inspection by Netskope. By adding the hash of the file that triggered a false alarm to the file filter, you can prevent it from being scanned again by Netskope and avoid generating another incident…

Threat Protection and Anomaly Detection

Question

You investigate a suspected malware incident and confirm that it was a false alarm.

Options

  • AIn this scenario, how would you prevent the same file from triggering another incident?
  • BQuarantine the file. Look up the hash at the VirusTotal website.
  • CExport the packet capture to a pcap file.
  • DAdd the hash to the file filter.

How the community answered

(25 responses)
  • A
    8% (2)
  • B
    4% (1)
  • C
    4% (1)
  • D
    84% (21)

Explanation

A file filter is a list of file hashes that you can use to exclude files from inspection by Netskope. By adding the hash of the file that triggered a false alarm to the file filter, you can prevent it from being scanned again by Netskope and avoid generating another incident. Quarantining the file, exporting the packet capture, or looking up the hash at VirusTotal are not effective ways to prevent the same file from triggering another incident, as they do not affect how Netskope handles the file.

Topics

#malware false positive#file hash#file filter#incident response

Community Discussion

No community discussion yet for this question.

Full NSK100 Practice