CAS-002 · Question #627
A security administrator notices a recent increase in workstations becoming compromised by malware. Often, the malware is delivered via drive-by downloads, from malware hosting websites, and is not…
The correct answer is B. Deploy a cloud-based content filter and enable the appropriate category to prevent further. Drive-by download attacks from malicious websites are best mitigated by blocking access to those sites at the network level before any content reaches the workstation.
Question
A security administrator notices a recent increase in workstations becoming compromised by malware. Often, the malware is delivered via drive-by downloads, from malware hosting websites, and is not being detected by the corporate antivirus. Which of the following solutions would provide the BEST protection for the company?
Options
- AIncrease the frequency of antivirus downloads and install updates to all workstations.
- BDeploy a cloud-based content filter and enable the appropriate category to prevent further
- CDeploy a NIPS to inspect and block all web traffic which may contain malware and exploits.
- DDeploy a web based gateway antivirus server to intercept viruses before they enter the
How the community answered
(29 responses)- A3% (1)
- B76% (22)
- C7% (2)
- D14% (4)
Why each option
Drive-by download attacks from malicious websites are best mitigated by blocking access to those sites at the network level before any content reaches the workstation.
Increasing antivirus update frequency does not help when the malware is unknown or zero-day and is already evading the existing AV engine's signatures.
A cloud-based content filter blocks access to known malware-hosting websites by category before any payload is delivered to the endpoint, bypassing the antivirus detection gap entirely. This is a proactive defense that stops the attack at the source rather than attempting to detect malware after it arrives. Because the malicious content never reaches the workstation, signature-based AV failures become irrelevant.
A NIPS still relies on detection of known exploit signatures rather than preventing access to malicious sites, and may not intercept all web-based malware especially over encrypted channels.
A gateway antivirus server uses the same signature-based detection that is already failing, so it would not solve the problem of malware evading corporate antivirus.
Concept tested: Web content filtering to block malicious websites
Source: https://www.cisa.gov/topics/cyber-threats-and-advisories/malware
Topics
Community Discussion
No community discussion yet for this question.