PCNSA · Question #252
A coworker found a USB labeled "confidential in the parking lot. They inserted the drive and it infected their corporate laptop with unknown malware The malware caused the laptop to begin…
The correct answer is C. Antivirus. Antivirus Security Profiles inspect network traffic for known malware signatures in real time - when the infected laptop began communicating and exfiltrating data, an Antivirus profile would scan that traffic and flag the malicious code patterns, making it the right tool for…
Question
A coworker found a USB labeled "confidential in the parking lot. They inserted the drive and it infected their corporate laptop with unknown malware The malware caused the laptop to begin infiltrating corporate data. Which Security Profile feature could have been used to detect the malware on the laptop?
Options
- ADNS Sinkhole
- BWildFire Analysis
- CAntivirus
- DDoS Protection
How the community answered
(22 responses)- A5% (1)
- C95% (21)
Explanation
Antivirus Security Profiles inspect network traffic for known malware signatures in real time - when the infected laptop began communicating and exfiltrating data, an Antivirus profile would scan that traffic and flag the malicious code patterns, making it the right tool for detecting the malware.
Why the distractors are wrong:
- A. DNS Sinkhole - This redirects DNS queries for known malicious domains to a controlled IP to identify already-infected hosts, but it doesn't detect or block the malware itself.
- B. WildFire Analysis - WildFire forwards unknown files to the cloud for behavioral analysis; it's a sandboxing/analysis service, not a real-time signature-based detector that catches active malware in traffic.
- D. DoS Protection - This defends against flooding and denial-of-service attacks (volumetric traffic), which has nothing to do with malware detection.
Memory tip: Think of "AV = Active Vigilance." Antivirus profiles actively scan live traffic for malware signatures - it's your real-time cop on the beat. WildFire is the forensics lab (sends unknowns out for analysis), DNS Sinkhole is the informant (tells you who's already compromised), and DoS Protection is the bouncer (blocks floods at the door).
Topics
Community Discussion
No community discussion yet for this question.