700-270 · Question #57
Detection of an exploit kit that is installed on a device is an example of which loC event category?
The correct answer is D. IPS. IPS (Intrusion Prevention Systems) are specifically designed to detect exploit kits because exploit kits operate by targeting and exploiting software vulnerabilities - exactly the threat category IPS sensors monitor for. Exploit kits are not the malware payload itself, which is…
Question
Detection of an exploit kit that is installed on a device is an example of which loC event category?
Options
- Afirewall
- Bmalware
- Csecurity intelligence
- DIPS
How the community answered
(41 responses)- A7% (3)
- B2% (1)
- C2% (1)
- D88% (36)
Explanation
IPS (Intrusion Prevention Systems) are specifically designed to detect exploit kits because exploit kits operate by targeting and exploiting software vulnerabilities - exactly the threat category IPS sensors monitor for. Exploit kits are not the malware payload itself, which is why B (Malware) is incorrect; malware refers to the delivered payload (virus, ransomware, etc.), not the exploitation mechanism. A (Firewall) is wrong because firewalls generate IoC events around allowed/blocked network traffic, not device-level exploitation activity. C (Security Intelligence) covers threat-intelligence and reputation-based indicators (known bad IPs, domains), not active exploit detection on an endpoint.
Memory tip: Think "IPS = Intrusion Prevention = exploit kits intrude through vulnerabilities" - if an IoC involves exploiting a weakness to break in, it belongs in the IPS category, not the malware category.
Topics
Community Discussion
No community discussion yet for this question.