CrowdStrike Certified Falcon Responder CCFR-201 Question # 1 Topic 1 Discussion

CrowdStrike Certified Falcon Responder CCFR-201 Question # 1 Topic 1 Discussion

CCFR-201 Exam Topic 1 Question 1 Discussion:
Question #: 1
Topic #: 1

When analyzing an executable with a global prevalence of common; but you do not know what the executable is. what is the best course of action?


A.

Do nothing, as this file is common and well known


B.

From detection, click the VT Hash button to pivot to VirusTotal to investigate further


C.

From detection, use API manager to create a custom blocklist


D.

From detection, submit to FalconX for deep dive analysis


Get Premium CCFR-201 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.