CAS-001 · Question #388
A security engineer is troubleshooting a possible virus infection, which may have spread to multiple desktop computers within the organization. The company implements enterprise antivirus software…
The correct answer is C. The security administrator should consider installing a cloud augmented security service. The scenario describes a new malware variant not yet in antivirus signature databases, which is why traditional signature-based antivirus failed to detect it. A cloud-augmented security service leverages real-time, crowd-sourced threat intelligence, behavioral analysis, and…
Question
A security engineer is troubleshooting a possible virus infection, which may have spread to multiple desktop computers within the organization. The company implements enterprise antivirus software on all desktops, but the enterprise antivirus server's logs show no sign of a virus infection. The border firewall logs show suspicious activity from multiple internal hosts trying to connect to the same external IP address. The security administrator decides to post the firewall logs to a security mailing list and receives confirmation from other security administrators that the firewall logs indicate internal hosts are compromised with a new variant of the Trojan.Ransomcrypt.G malware not yet detected by most antivirus software. Which of the following would have detected the malware infection sooner?
Options
- AThe security administrator should consider deploying a signature-based intrusion detection
- BThe security administrator should consider deploying enterprise forensic analysis tools.
- CThe security administrator should consider installing a cloud augmented security service.
- DThe security administrator should consider establishing an incident response team.
How the community answered
(24 responses)- A13% (3)
- B21% (5)
- C63% (15)
- D4% (1)
Explanation
The scenario describes a new malware variant not yet in antivirus signature databases, which is why traditional signature-based antivirus failed to detect it. A cloud-augmented security service leverages real-time, crowd-sourced threat intelligence, behavioral analysis, and reputation data aggregated from millions of endpoints worldwide. Because it is not solely reliant on local signature databases, it can identify zero-day and newly emerging malware through behavioral patterns and global telemetry-exactly what was needed here. Option A (signature-based IDS) has the same limitation as the existing antivirus: it cannot detect signatures it does not know. Option B (forensic tools) aids investigation after detection, not prevention. Option D (incident response team) is a process response, not a detection technology.
Topics
Community Discussion
No community discussion yet for this question.