nerdexam
CompTIA

SY0-301 · Question #528

The Chief Technical Officer (CTO) is worried about an increased amount of malware detected on end user's workstations. Which of the following technologies should be recommended to detect such…

The correct answer is C. Host-based IDS. A Host-based Intrusion Detection System (HIDS) runs directly on individual workstations and monitors local system activity - file system changes, running processes, registry modifications, and anomalous behavior - which are the key indicators of malware infection. Because the…

Security operations

Question

The Chief Technical Officer (CTO) is worried about an increased amount of malware detected on end user's workstations. Which of the following technologies should be recommended to detect such anomalies?

Options

  • ANIDS
  • BWeb content filter
  • CHost-based IDS
  • DWeb application firewall

How the community answered

(22 responses)
  • C
    95% (21)
  • D
    5% (1)

Explanation

A Host-based Intrusion Detection System (HIDS) runs directly on individual workstations and monitors local system activity - file system changes, running processes, registry modifications, and anomalous behavior - which are the key indicators of malware infection. Because the concern is malware on endpoints (workstations), a host-resident solution is the correct fit. A NIDS (A) monitors network traffic and cannot inspect activity inside an endpoint. A web content filter (B) can block malicious websites but cannot detect malware already present on a machine. A web application firewall (D) protects web applications from external attacks and is irrelevant to workstation malware.

Topics

#host-based IDS#malware detection#endpoint security#anomaly detection

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice