nerdexam
CompTIA

CAS-003 · Question #45

A user workstation was infected with a new malware variant as a result of a drive-by download. The security administrator reviews key controls on the infected workstation and discovers the…

The correct answer is A. Install HIPS C. Install EDR. A drive-by download involves malicious code silently downloaded and executed when a user visits a compromised or malicious website, exploiting browser or plugin vulnerabilities. HIPS (A) - Host Intrusion Prevention System - monitors system calls, process behavior, and file…

Enterprise Security Operations

Question

A user workstation was infected with a new malware variant as a result of a drive-by download. The security administrator reviews key controls on the infected workstation and discovers the following:

Which of the following would BEST prevent the problem from reoccurring in the future? (Choose two.)

Exhibit

CAS-003 question #45 exhibit

Options

  • AInstall HIPS
  • BEnable DLP
  • CInstall EDR
  • DInstall HIDS
  • EEnable application blacklisting
  • FImprove patch management processes

How the community answered

(52 responses)
  • A
    75% (39)
  • B
    13% (7)
  • D
    2% (1)
  • E
    6% (3)
  • F
    4% (2)

Explanation

A drive-by download involves malicious code silently downloaded and executed when a user visits a compromised or malicious website, exploiting browser or plugin vulnerabilities. HIPS (A) - Host Intrusion Prevention System - monitors system calls, process behavior, and file activity in real time and can block suspicious execution before malware fully installs, directly preventing the attack vector. EDR (C) - Endpoint Detection and Response - provides advanced behavioral detection, threat hunting, and automated response capabilities that go beyond signature-based detection, catching novel malware like new variants. DLP (B) focuses on preventing data exfiltration, not infection. HIDS (D) detects intrusions but cannot prevent them. Application blacklisting (E) blocks known-bad applications but is ineffective against new/unknown malware variants used in drive-by downloads. Improving patch management (F) helps close exploited vulnerabilities but doesn't directly prevent execution of downloaded malware.

Topics

#endpoint protection#HIPS#EDR#malware prevention

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice