220-1002 · Question #683
A technician is attempting to remove a virus from the machine of a user who just retuned from leave. The virus is a known signature that was identified 30 days ago. The antivirus solution the…
The correct answer is A. The last antivirus update the machine received was seven days ago. The machine's AV definitions were only updated seven days ago, leaving it unprotected against a virus that has been known for 30 days - creating a 23-day window during which the infection occurred.
Question
A technician is attempting to remove a virus from the machine of a user who just retuned from leave. The virus is a known signature that was identified 30 days ago. The antivirus solution the company is using was updated seven days ago with the most current signatures. Which of the following MOST likely allowed the infection?
Options
- AThe last antivirus update the machine received was seven days ago.
- BThe user changed the machine's password 30 days ago.
- CThe user manually killed the antivirus process.
- DThe machine has not received an antivirus update in the past 30 days.
How the community answered
(26 responses)- A69% (18)
- B15% (4)
- C12% (3)
- D4% (1)
Why each option
The machine's AV definitions were only updated seven days ago, leaving it unprotected against a virus that has been known for 30 days - creating a 23-day window during which the infection occurred.
Because the machine's antivirus signatures were last updated seven days ago, and the virus has had a known signature for 30 days, the machine lacked detection capability for approximately 23 days after the virus was first identified. The infection almost certainly occurred during this unprotected window. This highlights the critical importance of timely and frequent AV definition updates to minimize exposure to known threats.
Changing a machine's password 30 days ago has no relationship to the antivirus signature database or the machine's ability to detect and block malware.
While manually terminating the antivirus process would disable real-time protection, the scenario provides no evidence that the user performed this action.
The scenario explicitly states the antivirus solution was updated seven days ago, meaning the machine did receive a recent update - the statement that it has not been updated in 30 days is factually contradicted by the scenario.
Concept tested: Antivirus definition update gap and malware infection window
Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/microsoft-defender-antivirus-updates
Topics
Community Discussion
No community discussion yet for this question.