nerdexam
CompTIA

220-1002 · Question #161

A corporate network was recently infected by a malicious application on a flash drive that downloaded sensitive company files and injected a virus, which spread onto the network. Which of the…

The correct answer is C. Disabling AutoRun. AutoRun (and AutoPlay) is a Windows feature that automatically executes a program defined in the autorun.inf file on a removable drive when it is inserted. Attackers exploit this by placing malicious executables on USB drives that launch immediately when plugged in, without any…

Hardware and network troubleshooting

Question

A corporate network was recently infected by a malicious application on a flash drive that downloaded sensitive company files and injected a virus, which spread onto the network. Which of the following best practices could have prevented the attack?

Options

  • AImplementing strong passwords
  • BChanging default credentials
  • CDisabling AutoRun
  • DRemoving Guest account
  • EEncrypting data

How the community answered

(33 responses)
  • A
    15% (5)
  • B
    3% (1)
  • C
    76% (25)
  • D
    6% (2)

Explanation

AutoRun (and AutoPlay) is a Windows feature that automatically executes a program defined in the autorun.inf file on a removable drive when it is inserted. Attackers exploit this by placing malicious executables on USB drives that launch immediately when plugged in, without any user interaction. Disabling AutoRun would have prevented the malicious application from executing automatically when the flash drive was inserted, stopping the infection at its source. Strong passwords, changing default credentials, removing Guest accounts, and encrypting data are all good security practices, but none of them would have prevented an autorun-based USB attack from executing in the first place.

Topics

#AutoRun#USB security#malware prevention#network infection

Community Discussion

No community discussion yet for this question.

Full 220-1002 Practice