nerdexam
GAQM

CPEH-001 · Question #909

Security administrator John Smith has noticed abnormal amounts of traffic coming from local computers at night. Upon reviewing, he finds that user data have been exfilltrated by an attacker. AV…

The correct answer is C. File-less malware. See the full explanation below for the reasoning.

Question

Security administrator John Smith has noticed abnormal amounts of traffic coming from local computers at night. Upon reviewing, he finds that user data have been exfilltrated by an attacker. AV tools are unable to find any malicious software, and the IDS/IPS has not reported on any non- whitelisted programs, what type of malware did the attacker use to bypass the company's application whitelisting?

Options

  • APhishing malware
  • BZero-day malware
  • CFile-less malware
  • DLogic bomb malware

How the community answered

(48 responses)
  • A
    4% (2)
  • B
    6% (3)
  • C
    75% (36)
  • D
    15% (7)

Community Discussion

No community discussion yet for this question.

Full CPEH-001 Practice