CAS-005 · Question #45
A security analyst reviews the following event timeline from an EDR solution: Which of the following has most likely occurred and needs to be fixed?
The correct answer is C. A logic flaw has introduced a TOCTOU vulnerability and must be addressed by the vendor. The event timeline shows that hr-reporting.docx was executed and launched a script before the malware scan completed and detected it as malicious. This indicates a TOCTOU (Time-of- Check to Time-of-Use) vulnerability - where the file was checked after it was already used. This…
Question
A security analyst reviews the following event timeline from an EDR solution:
Which of the following has most likely occurred and needs to be fixed?
Exhibits
Options
- AThe DLP has failed to block malicious exfiltration, and data tagging is not being utilized properly.
- BA NIDS bypass was utilized by a threat actor, and updates must be installed by the administrator.
- CA logic flaw has introduced a TOCTOU vulnerability and must be addressed by the vendor.
- DA potential insider threat is being investigated and will be addressed by the senior management
How the community answered
(29 responses)- A7% (2)
- B21% (6)
- C62% (18)
- D10% (3)
Explanation
The event timeline shows that hr-reporting.docx was executed and launched a script before the malware scan completed and detected it as malicious. This indicates a TOCTOU (Time-of- Check to Time-of-Use) vulnerability - where the file was checked after it was already used. This logic flaw needs to be fixed by the vendor to ensure scans complete before allowing execution.
Community Discussion
No community discussion yet for this question.

