nerdexam
GIAC

GSLC · Question #515

John works as a Network Administrator for We-are-secure Inc. The We-are-secure server is based on Windows Server 2003. One day, while analyzing the network security, he receives an error message that

The correct answer is A. He should upgrade his antivirus program. B. He should observe the process viewer (Task Manager) to see whether any new process is running on. The presence of Kernel32.exe (an .exe masquerading as the legitimate kernel32.dll system file) is a well-known malware indicator requiring antivirus action and process inspection. Patching and restoring settings do not directly remediate an active infection.

Security Operations & Incident Response Leadership

Question

John works as a Network Administrator for We-are-secure Inc. The We-are-secure server is based on Windows Server 2003. One day, while analyzing the network security, he receives an error message that Kernel32.exe is encountering a problem. Which of the following steps should John take as a countermeasure to this situation? Each correct answer represents a complete solution. Choose all that apply.

Options

  • AHe should upgrade his antivirus program.
  • BHe should observe the process viewer (Task Manager) to see whether any new process is running on
  • CHe should download the latest patches for Windows Server 2003 from the Microsoft site, so that he can
  • DHe should restore his Windows settings.

How the community answered

(30 responses)
  • A
    83% (25)
  • C
    13% (4)
  • D
    3% (1)

Why each option

The presence of Kernel32.exe (an .exe masquerading as the legitimate kernel32.dll system file) is a well-known malware indicator requiring antivirus action and process inspection. Patching and restoring settings do not directly remediate an active infection.

AHe should upgrade his antivirus program.Correct

Upgrading and running the antivirus program is a direct countermeasure because Kernel32.exe is a recognized malware signature that attempts to impersonate the legitimate Windows kernel32.dll, and updated antivirus definitions can detect and remove it.

BHe should observe the process viewer (Task Manager) to see whether any new process is running onCorrect

Inspecting Task Manager for unknown or suspicious processes allows the administrator to identify and terminate rogue processes spawned by the malware before they cause further system compromise.

CHe should download the latest patches for Windows Server 2003 from the Microsoft site, so that he can

Downloading OS patches addresses known vulnerabilities but does not remove malware that is already actively running on the system, making it an insufficient direct countermeasure for this specific incident.

DHe should restore his Windows settings.

Restoring Windows settings does not reliably eliminate malware like Kernel32.exe, which may have embedded itself in system directories or startup entries that a settings restore would not touch.

Concept tested: Malware identification and response - fake system process

Source: https://learn.microsoft.com/en-us/microsoft-365/security/intelligence/malware-naming

Topics

#malware response#Kernel32.exe#incident countermeasures#Windows security

Community Discussion

No community discussion yet for this question.

Full GSLC Practice