nerdexam
EC-Council

312-50V13 · Question #501

Sarah, a system administrator, was alerted of potential malicious activity on the network of her company. She discovered a malicious program spread through the instant messenger application used by…

The correct answer is A. Instant Messenger Applications; verifying the sender's identity before opening any files. Explanation Option A is correct because the attack vector is explicitly the instant messenger application - the attacker compromised a teammate's account and used it to distribute malicious files through that platform, making "Instant Messenger Applications" the accurate attack…

Submitted by packet_pusher· Mar 6, 2026Social Engineering

Question

Sarah, a system administrator, was alerted of potential malicious activity on the network of her company. She discovered a malicious program spread through the instant messenger application used by her team. The attacker had obtained access to one of her teammate's messenger accounts and started sending files across the contact list. Which best describes the attack scenario and what measure could have prevented it?

Options

  • AInstant Messenger Applications; verifying the sender's identity before opening any files
  • BInsecure Patch Management; updating application software regularly
  • CRogue/Decoy Applications; ensuring software is labeled as TRUSTED
  • DPortable Hardware Media/Removable Devices; disabling Autorun functionality

How the community answered

(51 responses)
  • A
    86% (44)
  • B
    4% (2)
  • C
    2% (1)
  • D
    8% (4)

Explanation

Explanation

Option A is correct because the attack vector is explicitly the instant messenger application - the attacker compromised a teammate's account and used it to distribute malicious files through that platform, making "Instant Messenger Applications" the accurate attack classification. The preventive measure directly aligns: had team members verified the sender's identity (e.g., confirming via phone or another channel before opening files), the malware spread could have been stopped, even with a legitimate-looking account sending the files.

Why the distractors are wrong:

  • B is incorrect because there is no mention of missing patches or software vulnerabilities being exploited; the attacker used social engineering through a compromised account.
  • C is incorrect because the messenger application was legitimate, not a rogue or decoy application - the threat came from within a trusted platform.
  • D is incorrect because no removable hardware (USB drives, etc.) was involved; the attack spread entirely through a network-based messaging platform.

Memory Tip

Think "method matches measure" - the attack method (messenger app) must match the measure (verify the sender before clicking). If the scenario describes files sent through a chat app by a hijacked account, always look for identity verification as the countermeasure, since account compromise ≠ patch problem or hardware issue.

Topics

#Malware Propagation#Instant Messenger Security#Social Engineering#User Vigilance

Community Discussion

No community discussion yet for this question.

Full 312-50V13 Practice