312-50V12 · Question #261
During a comprehensive security assessment, your cybersecurity team at XYZ Corp stumbles upon signs that point toward a possible Advanced Persistent Threat (APT) infiltration in the network infrastruc
The correct answer is C. Vigilantly monitor for evidence of zero-day exploits that manage to evade your firewall or antivirus. To confirm and isolate a suspected Advanced Persistent Threat (APT) infiltration, the top priority should be to actively search for evidence of zero-day exploits that have bypassed existing security measures. APTs are characterized by their sophisticated, evasive techniques, ofte
Question
Options
- AInvestigate for anomalies in file movements or unauthorized data access attempts within your
- BScrutinize for repeat network login attempts from unrecognized geographical regions
- CVigilantly monitor for evidence of zero-day exploits that manage to evade your firewall or antivirus
- DSearch for proof of a spear-phishing attempt, such as the presence of malicious emails or risky
How the community answered
(24 responses)- A17% (4)
- B13% (3)
- C63% (15)
- D8% (2)
Why each option
To confirm and isolate a suspected Advanced Persistent Threat (APT) infiltration, the top priority should be to actively search for evidence of zero-day exploits that have bypassed existing security measures. APTs are characterized by their sophisticated, evasive techniques, often leveraging unknown vulnerabilities to gain and maintain access undetected.
While anomalies in file movements and data access are signs of a compromise, they often occur after initial infiltration, whereas detecting the sophisticated evasion techniques like zero-days is more indicative of an APT's initial access and persistence strategy.
Repeat network login attempts from unrecognized regions typically point to brute-force attacks or compromised credentials, which are common but not uniquely characteristic of the stealthy and often more subtle initial access or lateral movement methods employed by sophisticated APTs.
APTs are known for utilizing advanced techniques, including zero-day exploits, which leverage unknown vulnerabilities to bypass traditional security controls like firewalls and antivirus software. Detecting the use of such highly sophisticated and evasive exploits is a primary indicator of an APT and crucial for confirming its presence and beginning isolation efforts, as it demonstrates the attacker's advanced capabilities and intent to remain undetected.
Spear-phishing is a common initial vector for many attacks, including APTs, but if an infiltration is already suspected, prioritizing the search for active zero-day exploits provides more direct evidence of the advanced, evasive methods an APT would use to maintain its presence undetected, rather than focusing solely on the initial delivery mechanism.
Concept tested: Advanced Persistent Threat (APT) detection and characteristics
Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/zero-day-exploit?view=o365-worldwide
Topics
Community Discussion
No community discussion yet for this question.