PCNSA · Question #336
In order to protect users against exploit kits that exploit a vulnerability and then automatically download malicious payloads, which Security profile should be configured?
The correct answer is C. Vulnerability Protection. Vulnerability Protection profiles detect and block attempts to exploit known software vulnerabilities - which is exactly what exploit kits do. They inspect traffic for exploit patterns (buffer overflows, illegal code execution, etc.) before a payload is even delivered. Antivirus
Question
In order to protect users against exploit kits that exploit a vulnerability and then automatically download malicious payloads, which Security profile should be configured?
Options
- AAnti-Spyware
- BWildFire
- CVulnerability Protection
- DAntivirus
How the community answered
(52 responses)- A4% (2)
- B2% (1)
- C88% (46)
- D6% (3)
Explanation
Vulnerability Protection profiles detect and block attempts to exploit known software vulnerabilities - which is exactly what exploit kits do. They inspect traffic for exploit patterns (buffer overflows, illegal code execution, etc.) before a payload is even delivered. Antivirus profiles detect known malware in downloaded files after the fact. Anti-Spyware targets command-and-control (C2) traffic from already-infected hosts. WildFire analyzes unknown files in a sandbox but does not block the initial exploitation attempt. Because the attack chain starts with exploiting a vulnerability, Vulnerability Protection is the right profile to stop it at the earliest stage.
Topics
Community Discussion
No community discussion yet for this question.