nerdexam
GIAC

GSLC · Question #453

You work as a professional Ethical Hacker. You are assigned a project to test the security of suspect that your friend has installed the keyghost keylogger onto your computer. Which of the following…

The correct answer is A. Use commercially available anti-keyloggers such as PrivacyKeyboard. C. Monitor the programs running on the server to see whether any new process is running on the server or D. Use on-screen keyboards and speech-to-text conversion software which can also be useful against. Defending against the KeyGhost hardware keylogger requires tools and techniques that either detect the logger or bypass the physical keyboard input path it monitors.

Security Operations & Incident Response Leadership

Question

You work as a professional Ethical Hacker. You are assigned a project to test the security of suspect that your friend has installed the keyghost keylogger onto your computer. Which of the following countermeasures would you employ in such a situation? Each correct answer represents a complete solution. Choose all that apply.

Options

  • AUse commercially available anti-keyloggers such as PrivacyKeyboard.
  • BRemove the SNMP agent or disable the SNMP service.
  • CMonitor the programs running on the server to see whether any new process is running on the server or
  • DUse on-screen keyboards and speech-to-text conversion software which can also be useful against

How the community answered

(28 responses)
  • A
    82% (23)
  • B
    18% (5)

Why each option

Defending against the KeyGhost hardware keylogger requires tools and techniques that either detect the logger or bypass the physical keyboard input path it monitors.

AUse commercially available anti-keyloggers such as PrivacyKeyboard.Correct

Anti-keylogger software such as PrivacyKeyboard is specifically designed to detect and neutralize keylogging activity by monitoring for known keylogger signatures and behaviors, making it a direct countermeasure.

BRemove the SNMP agent or disable the SNMP service.

Removing the SNMP agent or disabling the SNMP service is a countermeasure against network management protocol exploitation and has no relevance to keylogger detection or prevention.

CMonitor the programs running on the server to see whether any new process is running on the server orCorrect

Monitoring running processes can reveal suspicious or unauthorized programs that may have been installed as a software component accompanying the hardware keylogger, allowing the user to identify and terminate the threat.

DUse on-screen keyboards and speech-to-text conversion software which can also be useful againstCorrect

On-screen keyboards and speech-to-text conversion software bypass hardware keyloggers like KeyGhost entirely because they do not use the physical keyboard input path that the device intercepts and records.

Concept tested: Hardware keylogger detection and countermeasures

Topics

#keylogger#anti-keylogger#endpoint security#countermeasures

Community Discussion

No community discussion yet for this question.

Full GSLC Practice