CCFR-201 Exam QuestionsBrowse all questions from this exam

CCFR-201 Exam - Question 46


When analyzing an executable with a global prevalence of common; but you do not know what the executable is, what is the best course of action?

Show Answer
Correct Answer: B

When you encounter an executable file with a global prevalence marked as 'common' but its specific functionality is unknown, the best course of action is to investigate further using VirusTotal (VT). Clicking the VT Hash button will allow you to pivot to VirusTotal, where you can access detailed information about the hash, including its reputation and any associated threat intelligence. This enables you to make a more informed decision about the nature and potential risk of the executable.

Discussion

7 comments
Sign in to comment
wildbandanaOption: C
Dec 14, 2023

100% sure

Aicha78Option: B
Dec 25, 2023

B is correct

sbag0024Option: B
Jan 31, 2024

Going with B on this one. It is an option when looking at Full detection details.

sbag0024Option: B
Jan 31, 2024

Going with B on this one. It is an option when looking at Full detection details.

kangaruOption: B
Feb 11, 2024

You don't know what the hash corresponds to, then look in VT. It provides you all details of the hash together with it's reputation.

silva222222Option: B
May 18, 2024

The best course of action when analyzing an executable with a global prevalence of "common" but unknown functionality is: B. From detection, click the VT Hash button to pivot to VirusTotal to investigate further

alanalanalanOption: B
May 22, 2024

Answer is B, check with the VT.