nerdexam
EC-Council

312-50V12 · Question #209

Sarah, a system administrator, was alerted of potential malicious activity on the network of her company. She discovered a malicious program spread through the instant messenger application used by he

The correct answer is B. Instant Messenger Applications; verifying the sender's identity before opening any files. The scenario describes a social engineering attack where a compromised instant messenger account was used to spread malicious files, which could have been prevented by users verifying sender identity.

Submitted by carter_n· Mar 4, 2026System Hacking Phases and Attack Techniques

Question

Sarah, a system administrator, was alerted of potential malicious activity on the network of her company. She discovered a malicious program spread through the instant messenger application used by her team. The attacker had obtained access to one of her teammate's messenger accounts and started sending files across the contact list. Which best describes the attack scenario and what measure could have prevented it?

Options

  • AInsecure Patch Management; updating application software regularly
  • BInstant Messenger Applications; verifying the sender's identity before opening any files
  • CRogue/Decoy Applications; ensuring software is labeled as TRUSTED
  • DPortable Hardware Media/Removable Devices; disabling Autorun functionality

How the community answered

(56 responses)
  • A
    7% (4)
  • B
    89% (50)
  • C
    2% (1)
  • D
    2% (1)

Why each option

The scenario describes a social engineering attack where a compromised instant messenger account was used to spread malicious files, which could have been prevented by users verifying sender identity.

AInsecure Patch Management; updating application software regularly

The scenario focuses on an attacker using a compromised account to send files, rather than exploiting an unpatched vulnerability in the application itself as the primary attack vector. While patching is important, it doesn't directly address the social engineering aspect of receiving files from a seemingly legitimate contact.

BInstant Messenger Applications; verifying the sender's identity before opening any filesCorrect

The attack vector is explicitly stated as a malicious program spread through an instant messenger application by an attacker who obtained access to a teammate's account and sent files. Verifying the sender's identity through an out-of-band method before opening any files is a crucial user-level security practice to prevent the execution of malicious payloads from compromised trusted sources.

CRogue/Decoy Applications; ensuring software is labeled as TRUSTED

Rogue/Decoy applications are malicious programs disguised as legitimate software to trick users into installation; this scenario involves an attacker compromising and using a legitimate instant messenger application, not distributing a fake one.

DPortable Hardware Media/Removable Devices; disabling Autorun functionality

The attack explicitly states the use of an instant messenger application for spreading malware, making portable hardware media and Autorun functionality entirely irrelevant to the described infection vector.

Concept tested: Social Engineering; Instant Messenger Security Practices

Source: https://learn.microsoft.com/en-us/training/modules/recognize-social-engineering-attacks/

Topics

#malware spread#instant messaging security#social engineering#user awareness

Community Discussion

No community discussion yet for this question.

Full 312-50V12 Practice