nerdexam
GIAC

GCFA · Question #279

GCFA Question #279: Real Exam Question with Answer & Explanation

Sign in or unlock GCFA to reveal the answer and full explanation for question #279. The question stem and answer options stay visible for context.

Question

Your friend plans to install a Trojan on your computer. He knows that if he gives you a new version of chess.exe, you will definitely install the game on your computer. He picks up a Trojan and joins it to chess.exe. The size of chess.exe was 526,895 bytes originally, and after joining this chess file to the Trojan, the file size increased to 651,823 bytes. When he gives you this new game, you install the infected chess.exe file on your computer. He now performs various malicious tasks on your computer remotely. But you suspect that someone has installed a Trojan on your computer and begin to investigate it. When you enter the netstat command in the command prompt, you get the following results: C:\WINDOWS>netstat -an | find "UDP" UDP IP_Address:31337 : Now you check the following registry address: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices In the above address, you notice a 'default' key in the 'Name' field having " .exe" value in the corresponding 'Data' field. Which of the following Trojans do you think your friend may have installed on your computer on the basis of the above evidence?

Options

  • ATini
  • BQaz
  • CDonald Dick
  • DBack Orifice

Unlock GCFA to see the answer

You've previewed enough free GCFA questions. Unlock GCFA for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full GCFA Practice