SY0-301 · Question #569
An Information Systems Security Officer (ISSO) has been placed in charge of a classified peer-to- peer network that cannot connect to the Internet. The ISSO can update the antivirus definitions…
The correct answer is B. The signatures must have a hash value equal to what is displayed on the vendor site. When manually transferring antivirus definition files to an air-gapped classified network, verifying the hash of the DAT file against the vendor's published hash is the most critical step to ensure integrity and authenticity. This confirms the file has not been tampered with or…
Question
An Information Systems Security Officer (ISSO) has been placed in charge of a classified peer-to- peer network that cannot connect to the Internet. The ISSO can update the antivirus definitions manually, but which of the following steps is MOST important?
Options
- AA full scan must be run on the network after the DAT file is installed.
- BThe signatures must have a hash value equal to what is displayed on the vendor site.
- CThe definition file must be updated within seven days.
- DAll users must be logged off of the network prior to the installation of the definition file.
How the community answered
(26 responses)- A8% (2)
- B85% (22)
- C4% (1)
- D4% (1)
Why each option
When manually transferring antivirus definition files to an air-gapped classified network, verifying the hash of the DAT file against the vendor's published hash is the most critical step to ensure integrity and authenticity. This confirms the file has not been tampered with or corrupted in transit.
Running a full scan after installing the DAT file is good practice but is secondary to ensuring the integrity of the definition file itself before installation.
Comparing the hash value of the downloaded definition file against the hash published on the vendor's official site confirms cryptographic integrity, ensuring the file has not been modified by an attacker or corrupted during transfer. On a classified network that cannot reach the internet, a compromised or malicious definition file could spread malware under the guise of an antivirus update. Hash verification is the primary chain-of-trust control for offline software distribution in high-security environments.
Updating definitions within seven days is a general best-practice recommendation but is an arbitrary timeframe and not a security-critical verification step for the integrity of the update.
Logging users off before installing antivirus definition files is generally unnecessary as definitions update passively; it is not a security-critical integrity check.
Concept tested: Antivirus DAT file integrity verification via hashing
Source: https://csrc.nist.gov/publications/detail/sp/800-83/rev1/final
Topics
Community Discussion
No community discussion yet for this question.