SC-200 · Question #156
What information is shared by a deep file analysis?
The correct answer is A. Registry Modifications. Deep file analysis (also called sandbox detonation) in Microsoft Defender for Endpoint submits a suspicious file to a sandboxed environment for behavioral analysis. The results surface dynamic behaviors observed during execution, including registry modifications (A) - such as…
Question
What information is shared by a deep file analysis?
Options
- ARegistry Modifications
- BCode change history
- CCommand history
- DProcess history
How the community answered
(55 responses)- A89% (49)
- B4% (2)
- C5% (3)
- D2% (1)
Explanation
Deep file analysis (also called sandbox detonation) in Microsoft Defender for Endpoint submits a suspicious file to a sandboxed environment for behavioral analysis. The results surface dynamic behaviors observed during execution, including registry modifications (A) - such as keys created, modified, or deleted - as well as process creation, file system activity, and network connections. 'Code change history' is not a behavioral artifact. 'Command history' and 'Process history' are investigative artifacts collected from live devices (e.g., in investigation packages or Live Response), not outputs of static/dynamic file detonation analysis.
Topics
Community Discussion
No community discussion yet for this question.