exam questions

Exam EPM-DEF All Questions

View all questions & answers for the EPM-DEF exam

Exam EPM-DEF topic 1 question 13 discussion

Actual exam question from CyberArk's EPM-DEF
Question #: 13
Topic #: 1
[All EPM-DEF Questions]

Which threat intelligence source requires the suspect file to be sent externally?

  • A. NSRL
  • B. Palo Alto Wildfire
  • C. VirusTotal
  • D. CyberArk Application Risk Analysis Service (ARA)
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
9cf186a
1 month, 3 weeks ago
not sure but I'll say D: According to documenntation, wildfire needs the file to execute and analyze it. plus is the only integration with an "upload timeout value" https://docs.cyberark.com/EPM-onprem/10.10/en/Content/EPM/Server%20User%20Guide/FireEye%20AX%20Series.htm
upvoted 1 times
...
Takumi
8 months, 2 weeks ago
Selected Answer: B
The answer must be B or D. On other hand VirusTotal and NSRL only analyze the checksum so they don't send files externally. Probably Palo Alto is the best answer.
upvoted 1 times
...
Hyper
1 year, 3 months ago
The correct answer is Virus total, because epm sents files to virus total to be analyzed. You must have internet access to enable automatic upload to VirusTotal. https://docs.cyberark.com/EPM-onprem/11.5.1/en/Content/EPM/Server%20User%20Guide/Virus%20Total.htm
upvoted 2 times
...
Hyper
1 year, 3 months ago
Is B. Palo alto, fireeyes & check point needs interchange a file. https://docs.cyberark.com/EPM-onprem/11.5.1/en/Content/EPM/Server%20User%20Guide/Configuring%20Integration%20Settings.htm
upvoted 2 times
...
pathomas1971
1 year, 3 months ago
Selected Answer: B
B. Palo Alto Wildfire Palo Alto Wildfire is a threat intelligence source that requires the suspect file to be sent externally for analysis. Wildfire is a cloud-based service provided by Palo Alto Networks that analyzes unknown files to determine if they are malicious. When a file is suspected of being malicious, it can be sent to the Wildfire service for evaluation. The service examines the file in a controlled environment to determine its behavior and potential threat level. The other options mentioned, such as NSRL (National Software Reference Library), VirusTotal, and CyberArk Application Risk Analysis Service (ARA), do not necessarily require the suspect file to be sent externally for analysis in the same way as Palo Alto Wildfire.
upvoted 2 times
...
CurryMuncher
1 year, 7 months ago
Not convinced D is the answer. I think its C https://docs.cyberark.com/Product-Doc/OnlineHelp/EPM/21.9/en/Content/EPM/Server%20User%20Guide/Virus%20Total.htm Says "You must have internet access to enable automatic upload to VirusTotal" I would go for C,
upvoted 3 times
...
buczy
1 year, 8 months ago
D is correct
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...