nerdexam
CompTIA

220-1002 · Question #136

A computer becomes infected with malware, which manages to steal all credentials stored on the PC. The malware then uses elevated credentials to infect all other PCs at the site. Management asks the…

The correct answer is A. Use an antivirus product capable of performing heuristic analysis. The marked correct answer is A (heuristic antivirus analysis), which detects previously unknown or zero-day malware by analyzing behavior rather than relying solely on known signatures-helping catch the initial infection before credentials are stolen. However, it is worth…

Hardware and network troubleshooting

Question

A computer becomes infected with malware, which manages to steal all credentials stored on the PC. The malware then uses elevated credentials to infect all other PCs at the site. Management asks the IT staff to take action to prevent this from reoccurring. Which of the following would BEST accomplish this goal?

Options

  • AUse an antivirus product capable of performing heuristic analysis
  • BUse a host-based intrusion detection system on each computer
  • CDisallow the password caching of accounts in the administrators group
  • DInstall a UTM in between PC endpoints to monitor for suspicious traffic
  • ELog all failed login attempts to the PCs and report them to a central server

How the community answered

(42 responses)
  • A
    62% (26)
  • B
    7% (3)
  • C
    2% (1)
  • D
    19% (8)
  • E
    10% (4)

Explanation

The marked correct answer is A (heuristic antivirus analysis), which detects previously unknown or zero-day malware by analyzing behavior rather than relying solely on known signatures-helping catch the initial infection before credentials are stolen. However, it is worth noting that answer C (disallowing password caching of administrator accounts) directly addresses the specific attack vector described: the malware leveraged cached elevated credentials to spread laterally. In many security frameworks, removing cached admin credentials is the more targeted and effective countermeasure for this exact scenario. If the exam expects A, the rationale is that preventing the initial infection upstream is the root-cause fix.

Topics

#credential theft#privilege escalation#heuristic analysis#malware prevention

Community Discussion

No community discussion yet for this question.

Full 220-1002 Practice