200-201 Question 251
Single answerA cybersecurity analyst is investigating a suspicious file flagged by an endpoint detection and response (EDR) system. Upon further analysis, the file is found to be a legitimate system update from a trusted vendor. What should the analyst classify this file as?
- A
Malicious
- B
Benign
- C
Unknown
- D
Phishing
Show answer and explanation
Correct answer: B
Explanation
In cybersecurity, 'benign' refers to files, behaviors, or activities that do not pose a threat to systems or data. In this scenario, the suspicious file was analyzed and confirmed to be a legitimate system update. Therefore, it should be classified as benign.
- A. Incorrect.
Malicious is incorrect because there is no evidence to indicate that the file is harmful or designed to compromise the system.
- B. Correct.
Benign is correct because the file has been verified as legitimate and poses no threat to the system.
- C. Incorrect.
Unknown is incorrect because further analysis has already determined the file's legitimacy, so it is no longer unknown.
- D. Incorrect.
Phishing is incorrect because phishing refers to fraudulent attempts to obtain sensitive information, which is unrelated to this scenario.