CAS-002 · Question #221
A security engineer is troubleshooting a possible virus infection, which may have spread to multiple desktop computers within the organization. The company implements enterprise antivirus software…
The correct answer is C. The security administrator should consider installing a cloud augmented security service. The core problem is that the malware is a new variant not yet in antivirus signature databases, making any signature-based solution ineffective. A cloud-augmented security service addresses this by leveraging collective threat intelligence, behavioral analysis, sandboxing, and…
Question
A security engineer is troubleshooting a possible virus infection, which may have spread to multiple desktop computers within the organization. The company implements enterprise antivirus software on all desktops, but the enterprise antivirus server's logs show no sign of a virus infection. The border firewall logs show suspicious activity from multiple internal hosts trying to connect to the same external IP address. The security administrator decides to post the firewall logs to a security mailing list and receives confirmation from other security administrators that the firewall logs indicate internal hosts are compromised with a new variant of the Trojan.Ransomcrypt.G malware not yet detected by most antivirus software. Which of the following would have detected the malware infection sooner?
Options
- AThe security administrator should consider deploying a signature-based intrusion detection
- BThe security administrator should consider deploying enterprise forensic analysis tools.
- CThe security administrator should consider installing a cloud augmented security service.
- DThe security administrator should consider establishing an incident response team.
How the community answered
(21 responses)- A5% (1)
- B5% (1)
- C81% (17)
- D10% (2)
Explanation
The core problem is that the malware is a new variant not yet in antivirus signature databases, making any signature-based solution ineffective. A cloud-augmented security service addresses this by leveraging collective threat intelligence, behavioral analysis, sandboxing, and machine learning from cloud-based threat networks-detecting novel threats based on behavior rather than known signatures. Option A (signature-based IDS) would have the same fundamental limitation as the current antivirus-it relies on known signatures and would also fail to detect the new variant. Option B (forensic analysis tools) is useful for post-incident investigation but does not improve proactive detection. Option D (incident response team) improves the response to detected incidents but does not enhance the detection capability itself. Cloud augmentation provides the behavioral and heuristic detection needed to catch zero-day and new variants.
Topics
Community Discussion
No community discussion yet for this question.