220-1102 · Question #75
A help desk technician is troubleshooting a workstation in a SOHO environment that is running above normal system baselines. The technician discovers an unknown executable with a random string name…
The correct answer is D. Monitor outbound network traffic. Because the malware has a randomly generated filename and evades antivirus detection, searching by filename or relying on AV signatures will not reliably identify infected machines. Malware typically establishes communication with command-and-control (C2) servers or generates…
Question
A help desk technician is troubleshooting a workstation in a SOHO environment that is running above normal system baselines. The technician discovers an unknown executable with a random string name running on the system. The technician terminates the process, and the system returns to normal operation. The technician thinks the issue was an infected file, but the antivirus is not detecting a threat. The technician is concerned other machines may be infected with this unknown virus. Which of the following is the MOST effective way to check other machines on the network for this unknown threat?
Options
- ARun a startup script that removes files by name.
- BProvide a sample to the antivirus vendor.
- CManually check each machine.
- DMonitor outbound network traffic.
How the community answered
(35 responses)- A3% (1)
- B6% (2)
- C11% (4)
- D80% (28)
Explanation
Because the malware has a randomly generated filename and evades antivirus detection, searching by filename or relying on AV signatures will not reliably identify infected machines. Malware typically establishes communication with command-and-control (C2) servers or generates unusual outbound traffic patterns. Monitoring outbound network traffic from all machines allows the technician to identify other hosts exhibiting the same suspicious network behavior-such as connections to unusual IPs or domains-without needing to know the malware's filename. Running a startup script by filename fails because the name is random per infection. Providing a sample to the AV vendor is a good long-term step but does not immediately identify other infected machines. Manual inspection is impractical at scale and unreliable without a known indicator.
Topics
Community Discussion
No community discussion yet for this question.