CAS-003 · Question #45
A user workstation was infected with a new malware variant as a result of a drive-by download. The security administrator reviews key controls on the infected workstation and discovers the…
The correct answer is A. Install HIPS C. Install EDR. A drive-by download involves malicious code silently downloaded and executed when a user visits a compromised or malicious website, exploiting browser or plugin vulnerabilities. HIPS (A) - Host Intrusion Prevention System - monitors system calls, process behavior, and file…
Question
A user workstation was infected with a new malware variant as a result of a drive-by download. The security administrator reviews key controls on the infected workstation and discovers the following:
Which of the following would BEST prevent the problem from reoccurring in the future? (Choose two.)
Exhibit
Options
- AInstall HIPS
- BEnable DLP
- CInstall EDR
- DInstall HIDS
- EEnable application blacklisting
- FImprove patch management processes
How the community answered
(52 responses)- A75% (39)
- B13% (7)
- D2% (1)
- E6% (3)
- F4% (2)
Explanation
A drive-by download involves malicious code silently downloaded and executed when a user visits a compromised or malicious website, exploiting browser or plugin vulnerabilities. HIPS (A) - Host Intrusion Prevention System - monitors system calls, process behavior, and file activity in real time and can block suspicious execution before malware fully installs, directly preventing the attack vector. EDR (C) - Endpoint Detection and Response - provides advanced behavioral detection, threat hunting, and automated response capabilities that go beyond signature-based detection, catching novel malware like new variants. DLP (B) focuses on preventing data exfiltration, not infection. HIDS (D) detects intrusions but cannot prevent them. Application blacklisting (E) blocks known-bad applications but is ineffective against new/unknown malware variants used in drive-by downloads. Improving patch management (F) helps close exploited vulnerabilities but doesn't directly prevent execution of downloaded malware.
Topics
Community Discussion
No community discussion yet for this question.
