nerdexam
Cisco

700-270 · Question #57

Detection of an exploit kit that is installed on a device is an example of which loC event category?

The correct answer is D. IPS. IPS (Intrusion Prevention Systems) are specifically designed to detect exploit kits because exploit kits operate by targeting and exploiting software vulnerabilities - exactly the threat category IPS sensors monitor for. Exploit kits are not the malware payload itself, which is…

Understanding Next-Generation Firewall Technology and Concepts

Question

Detection of an exploit kit that is installed on a device is an example of which loC event category?

Options

  • Afirewall
  • Bmalware
  • Csecurity intelligence
  • DIPS

How the community answered

(41 responses)
  • A
    7% (3)
  • B
    2% (1)
  • C
    2% (1)
  • D
    88% (36)

Explanation

IPS (Intrusion Prevention Systems) are specifically designed to detect exploit kits because exploit kits operate by targeting and exploiting software vulnerabilities - exactly the threat category IPS sensors monitor for. Exploit kits are not the malware payload itself, which is why B (Malware) is incorrect; malware refers to the delivered payload (virus, ransomware, etc.), not the exploitation mechanism. A (Firewall) is wrong because firewalls generate IoC events around allowed/blocked network traffic, not device-level exploitation activity. C (Security Intelligence) covers threat-intelligence and reputation-based indicators (known bad IPs, domains), not active exploit detection on an endpoint.

Memory tip: Think "IPS = Intrusion Prevention = exploit kits intrude through vulnerabilities" - if an IoC involves exploiting a weakness to break in, it belongs in the IPS category, not the malware category.

Topics

#IPS#exploit kit detection#malware signatures#LoC events

Community Discussion

No community discussion yet for this question.

Full 700-270 Practice