220-1002 · Question #548
A technician receives a security alert stating a vendor has left a Keylogger on certain systems that shipped configured from the factory. The technician needs to research the system model numbers to…
The correct answer is B. Make sure the operating systems on all networked computers are fully patched and up to date. When a vendor pre-installs a keylogger on factory-shipped systems, applying OS security patches is the recommended remediation because OS and security vendors release targeted fixes for publicly disclosed threats, including known pre-installed malware.
Question
A technician receives a security alert stating a vendor has left a Keylogger on certain systems that shipped configured from the factory. The technician needs to research the system model numbers to determine if any production computers are affected. If the technician finds vulnerable systems, which of the following is the BEST method to remove the Keylogger?
Options
- AUpdate all antivirus definitions and run a full scan on all networked computers.
- BMake sure the operating systems on all networked computers are fully patched and up to date
- CUpdate all software drivers and firmware on all the affected computers.
- DEnable geofiltering on the network firewall to stop unwanted communications.
How the community answered
(32 responses)- A3% (1)
- B78% (25)
- C13% (4)
- D6% (2)
Why each option
When a vendor pre-installs a keylogger on factory-shipped systems, applying OS security patches is the recommended remediation because OS and security vendors release targeted fixes for publicly disclosed threats, including known pre-installed malware.
Antivirus signature databases may not yet include the specific factory-level keylogger, especially if it is a novel or proprietary implant not yet catalogued by AV vendors.
When a factory-installed keylogger is publicly disclosed, the OS vendor and security community release patches that specifically detect and remove it. Keeping all affected systems fully patched ensures those targeted fixes are applied across every vulnerable machine. This is the most scalable and systematic remediation for a known, catalogued threat tied to specific model numbers.
Updating drivers and firmware addresses hardware-embedded or firmware-level threats but does not target a software keylogger installed during OS configuration at the factory.
Geofiltering restricts outbound network traffic to certain geographic regions but does not remove the keylogger from the local system.
Concept tested: Remediating vendor-installed malware via OS patching
Source: https://support.microsoft.com/en-us/windows/remove-malware-from-your-windows-pc-9a769079-22d5-f59d-f29d-af956a4bdd08
Topics
Community Discussion
No community discussion yet for this question.