Which technique isolates and analyzes unknown files by executing them in a controlled environment to protect endpoints and data?
Choose an answer
Tap an option to check your answer.
Correct answer: file sandboxing using a protected environment to analyze and simulate the behavior of unknown files.
Why this is the answer
File sandboxing is the correct answer because it directly describes the process of executing unknown files in a secure, isolated environment to observe their behavior without risking the actual system. This technique is crucial for identifying malware, including zero-day threats. Crypto file ransomware protection using a file hash calculation is incorrect because hash calculations identify known malicious files, not unknown ones, and don't involve execution. File retrospection using continuous scan and analyses is a broader concept of continuously monitoring files for changes or new threat intelligence, but it doesn't specifically involve executing unknown files in isolation. Phishing file quarantine using an internal environment to store attached files is incorrect as it focuses on storing potentially malicious email attachments, not on executing and analyzing unknown files in a controlled, isolated environment.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed