PCNSA · Question #16
An administrator receives a global notification for a new malware that infects hosts. The infection will result in the infected host attempting to contact a command-and-control (C2) server. Which…
The correct answer is B. anti-spyware profile applied to outbound security policies C. antivirus profile applied to outbound security policies. Anti-spyware (B) is specifically designed to detect malware attempting to "phone home" - its primary function is identifying command-and-control traffic patterns, making it the most direct match for this threat. Antivirus (C) complements this by detecting the malware payload…
Question
An administrator receives a global notification for a new malware that infects hosts. The infection will result in the infected host attempting to contact a command-and-control (C2) server. Which two security profile components will detect and prevent this threat after the firewall's signature database has been updated? (Choose two.)
Options
- Avulnerability protection profile applied to outbound security policies
- Banti-spyware profile applied to outbound security policies
- Cantivirus profile applied to outbound security policies
- DURL filtering profile applied to outbound security policies
How the community answered
(47 responses)- A13% (6)
- B83% (39)
- D4% (2)
Explanation
Anti-spyware (B) is specifically designed to detect malware attempting to "phone home" - its primary function is identifying command-and-control traffic patterns, making it the most direct match for this threat. Antivirus (C) complements this by detecting the malware payload itself within outbound traffic sessions once the signature database is updated with the new threat's signature.
Vulnerability protection (A) is wrong because it defends against exploit attempts targeting software vulnerabilities (think inbound attacks against your systems), not outbound C2 communications from already-infected hosts. URL filtering (D) is wrong because it operates on a separate URL category database - a malware signature database update doesn't enhance URL filtering's ability to block C2 domains.
Memory tip: Match the profile to the direction and behavior of the threat. "Spyware" = spying/reporting out → anti-spyware blocks the C2 callback. "Virus" = the malicious code itself → antivirus catches it in transit. Vulnerability protection is for inbound exploitation, not outbound infection traffic.
Topics
Community Discussion
No community discussion yet for this question.