220-1102 · Question #779
Several computers have been infected with malware, causing the company network to slow down and sensitive company information to be lost. The IT department installs new antivirus software to remove…
The correct answer is C. Utilizing Intrusion detection systems. An Intrusion Detection System (IDS) monitors network traffic and system behavior for suspicious patterns - including those characteristic of malware activity such as unusual traffic spikes, unauthorized data transfers, and command-and-control communications. Since the malware…
Question
Several computers have been infected with malware, causing the company network to slow down and sensitive company information to be lost. The IT department installs new antivirus software to remove the malware and needs to decide the best method to prevent future malware infections. Which of the following methods would be the most effective?
Options
- AEncrypting data at rest
- BImplementing firewalls
- CUtilizing Intrusion detection systems
- DBacking up data regularly
How the community answered
(43 responses)- A7% (3)
- B2% (1)
- C81% (35)
- D9% (4)
Explanation
An Intrusion Detection System (IDS) monitors network traffic and system behavior for suspicious patterns - including those characteristic of malware activity such as unusual traffic spikes, unauthorized data transfers, and command-and-control communications. Since the malware caused network slowdowns (a behavioral signature), an IDS would detect these anomalies in real time and alert administrators before significant damage occurs. Encrypting data at rest (A) protects confidentiality but does not stop malware from running. Firewalls (B) filter traffic by rules but cannot deeply inspect application-layer malware behavior. Regular backups (D) aid in recovery but do nothing to prevent infection. IDS provides the active monitoring layer needed to catch future malware incidents early.
Topics
Community Discussion
No community discussion yet for this question.