NSK100 · Question #40
You investigate a suspected malware incident and confirm that it was a false alarm.
The correct answer is D. Add the hash to the file filter. A file filter is a list of file hashes that you can use to exclude files from inspection by Netskope. By adding the hash of the file that triggered a false alarm to the file filter, you can prevent it from being scanned again by Netskope and avoid generating another incident…
Question
You investigate a suspected malware incident and confirm that it was a false alarm.
Options
- AIn this scenario, how would you prevent the same file from triggering another incident?
- BQuarantine the file. Look up the hash at the VirusTotal website.
- CExport the packet capture to a pcap file.
- DAdd the hash to the file filter.
How the community answered
(25 responses)- A8% (2)
- B4% (1)
- C4% (1)
- D84% (21)
Explanation
A file filter is a list of file hashes that you can use to exclude files from inspection by Netskope. By adding the hash of the file that triggered a false alarm to the file filter, you can prevent it from being scanned again by Netskope and avoid generating another incident. Quarantining the file, exporting the packet capture, or looking up the hash at VirusTotal are not effective ways to prevent the same file from triggering another incident, as they do not affect how Netskope handles the file.
Topics
Community Discussion
No community discussion yet for this question.