cs0-003 question 148 discussion

View all CompTIA CySA+ (CS0-003) here
back to comptia forum

Question 148

A security analyst is performing an investigation involving multiple targeted Windows malware binaries. The analyst wants to gather intelligence without disclosing information to the attackers. Which of the following actions would allow the analyst to achieve the objective?

  • A. Upload the binary to an air gapped sandbox for analysis Most Votes
  • B. Send the binaries to the antivirus vendor
  • C. Execute the binaries on an environment with internet connectivity
  • D. Query the file hashes using VirusTotal
Answer:

a

User Votes:
A 10 votes
50%
B 1 votes
50%
C
50%
D
50%
Discussions
0 / 1000
tmkencele
1 year, 1 month ago

Upload the binary to an air gapped sandbox for analysis

Rama
2 months, 2 weeks ago

sending to antivirus vendors