NETSEC-ANALYST · Question #78
The CFO found a malware infected USB drive in the parking lot, which when inserted infected their corporate laptop. The malware contacted a known command- and-control server, which caused the infected
The correct answer is A. Create an anti-spyware profile and enable DNS Sinkhole feature.. Anti-Spyware - Detects spyware downloads and command-and-control traffic from previously installed spyware Anti-Spyware Security Profiles Anti-Spyware security profiles block spyware on compromised hosts from trying to communicate with external command-and-control (C2) servers, t
Question
The CFO found a malware infected USB drive in the parking lot, which when inserted infected their corporate laptop. The malware contacted a known command- and-control server, which caused the infected laptop to begin exfiltrating corporate data. Which security profile feature could have been used to prevent the communication with the command-and-control server?
Options
- ACreate an anti-spyware profile and enable DNS Sinkhole feature.
- BCreate an antivirus profile and enable its DNS Sinkhole feature.
- CCreate a URL filtering profile and block the DNS Sinkhole URL category
- DCreate a Data Filtering Profiles and enable its DNS Sinkhole feature.
How the community answered
(64 responses)- A84% (54)
- B9% (6)
- C3% (2)
- D3% (2)
Explanation
Anti-Spyware - Detects spyware downloads and command-and-control traffic from previously installed spyware Anti-Spyware Security Profiles Anti-Spyware security profiles block spyware on compromised hosts from trying to communicate with external command-and-control (C2) servers, thus enabling you to detect malicious traffic leaving the network from infected clients. DNS Sinkhole should be considered only for traffic that includes DNS queries. URL Filtering Web Security: Most attacks and exposure to malicious content occur during normal web browsing activities. URL filtering with PAN-DB automatically prevents attacks that leverage the web as an attack vector, including phishing links in emails, phishing sites, HTTP-based command-and-control, malicious sites, and pages that carry exploit kits. Antivirus: Includes new and updated antivirus signatures, including WildFire signatures and automatically-generated command-and-control (C2) signatures. WildFire signatures detect malware seen first by firewalls from around the world.
Topics
Community Discussion
No community discussion yet for this question.