SY0-301 · Question #528
The Chief Technical Officer (CTO) is worried about an increased amount of malware detected on end user's workstations. Which of the following technologies should be recommended to detect such…
The correct answer is C. Host-based IDS. A Host-based Intrusion Detection System (HIDS) runs directly on individual workstations and monitors local system activity - file system changes, running processes, registry modifications, and anomalous behavior - which are the key indicators of malware infection. Because the…
Question
The Chief Technical Officer (CTO) is worried about an increased amount of malware detected on end user's workstations. Which of the following technologies should be recommended to detect such anomalies?
Options
- ANIDS
- BWeb content filter
- CHost-based IDS
- DWeb application firewall
How the community answered
(22 responses)- C95% (21)
- D5% (1)
Explanation
A Host-based Intrusion Detection System (HIDS) runs directly on individual workstations and monitors local system activity - file system changes, running processes, registry modifications, and anomalous behavior - which are the key indicators of malware infection. Because the concern is malware on endpoints (workstations), a host-resident solution is the correct fit. A NIDS (A) monitors network traffic and cannot inspect activity inside an endpoint. A web content filter (B) can block malicious websites but cannot detect malware already present on a machine. A web application firewall (D) protects web applications from external attacks and is irrelevant to workstation malware.
Topics
Community Discussion
No community discussion yet for this question.