312-50V12 · Question #209
Sarah, a system administrator, was alerted of potential malicious activity on the network of her company. She discovered a malicious program spread through the instant messenger application used by he
The correct answer is B. Instant Messenger Applications; verifying the sender's identity before opening any files. The scenario describes a social engineering attack where a compromised instant messenger account was used to spread malicious files, which could have been prevented by users verifying sender identity.
Question
Options
- AInsecure Patch Management; updating application software regularly
- BInstant Messenger Applications; verifying the sender's identity before opening any files
- CRogue/Decoy Applications; ensuring software is labeled as TRUSTED
- DPortable Hardware Media/Removable Devices; disabling Autorun functionality
How the community answered
(56 responses)- A7% (4)
- B89% (50)
- C2% (1)
- D2% (1)
Why each option
The scenario describes a social engineering attack where a compromised instant messenger account was used to spread malicious files, which could have been prevented by users verifying sender identity.
The scenario focuses on an attacker using a compromised account to send files, rather than exploiting an unpatched vulnerability in the application itself as the primary attack vector. While patching is important, it doesn't directly address the social engineering aspect of receiving files from a seemingly legitimate contact.
The attack vector is explicitly stated as a malicious program spread through an instant messenger application by an attacker who obtained access to a teammate's account and sent files. Verifying the sender's identity through an out-of-band method before opening any files is a crucial user-level security practice to prevent the execution of malicious payloads from compromised trusted sources.
Rogue/Decoy applications are malicious programs disguised as legitimate software to trick users into installation; this scenario involves an attacker compromising and using a legitimate instant messenger application, not distributing a fake one.
The attack explicitly states the use of an instant messenger application for spreading malware, making portable hardware media and Autorun functionality entirely irrelevant to the described infection vector.
Concept tested: Social Engineering; Instant Messenger Security Practices
Source: https://learn.microsoft.com/en-us/training/modules/recognize-social-engineering-attacks/
Topics
Community Discussion
No community discussion yet for this question.