nerdexam
EC-Council

312-50V13 · Question #576

During a comprehensive security assessment, your cybersecurity team at XYZ Corp stumbles upon signs that point toward a possible Advanced Persistent Threat (APT) infiltration in the network…

The correct answer is A. Investigate for anomalies in file movements or unauthorized data access attempts within your. To confirm an Advanced Persistent Threat (APT), prioritizing investigation into anomalies in file movements or unauthorized data access is crucial, as APTs focus on stealthy persistence and data exfiltration.

Submitted by jaden.t· Mar 6, 2026Malware Threats

Question

During a comprehensive security assessment, your cybersecurity team at XYZ Corp stumbles upon signs that point toward a possible Advanced Persistent Threat (APT) infiltration in the network infrastructure. These sophisticated threats often exhibit subtle indicators that distinguish them from other types of cyberattacks. To confirm your suspicion and adequately isolate the potential APT, which of the following actions should you prioritize?

Options

  • AInvestigate for anomalies in file movements or unauthorized data access attempts within your
  • BScrutinize for repeat network login attempts from unrecognized geographical regions
  • CVigilantly monitor for evidence of zero-day exploits that manage to evade your firewall or antivirus
  • DSearch for proof of a spear-phishing attempt, such as the presence of malicious emails or risky

How the community answered

(50 responses)
  • A
    66% (33)
  • B
    6% (3)
  • C
    20% (10)
  • D
    8% (4)

Why each option

To confirm an Advanced Persistent Threat (APT), prioritizing investigation into anomalies in file movements or unauthorized data access is crucial, as APTs focus on stealthy persistence and data exfiltration.

AInvestigate for anomalies in file movements or unauthorized data access attempts within yourCorrect

APTs are characterized by their stealth, persistence, and goal of long-term access and data exfiltration within a network. Anomalies in internal file movements and unauthorized internal data access attempts are strong indicators of an APT trying to locate, stage, and exfiltrate sensitive information undetected, making this the priority for confirmation.

BScrutinize for repeat network login attempts from unrecognized geographical regions

Repeat network login attempts from unrecognized geographical regions are a general indicator of brute-force attacks or compromised credentials, not specifically indicative of the stealth and persistence of an APT's internal activities.

CVigilantly monitor for evidence of zero-day exploits that manage to evade your firewall or antivirus

While APTs may use zero-day exploits, simply monitoring for them is a reactive measure and doesn't directly confirm the *presence* of an ongoing APT, which often uses a combination of tactics and focuses on post-exploitation activities.

DSearch for proof of a spear-phishing attempt, such as the presence of malicious emails or risky

Spear-phishing is a common initial access vector for many types of attacks, including APTs, but finding evidence of it is an indicator of initial compromise, not the defining characteristic or primary confirmation of an *ongoing* APT's internal activities and persistence.

Concept tested: APT detection and indicators

Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender/advanced-persistent-threat?view=o365-worldwide

Topics

#APT#Incident response#Data exfiltration#Threat detection

Community Discussion

No community discussion yet for this question.

Full 312-50V13 Practice