nerdexam
CompTIA

SY0-301 · Question #628

Which of the following malware types typically allows an attacker to monitor a user's computer, is characterized by a drive-by download, and requires no user interaction?

The correct answer is C. Spyware. Spyware is designed to covertly monitor user activity and is commonly delivered through drive-by downloads that execute without any deliberate action by the victim.

Threats, vulnerabilities, and mitigations

Question

Which of the following malware types typically allows an attacker to monitor a user's computer, is characterized by a drive-by download, and requires no user interaction?

Options

  • AVirus
  • BLogic bomb
  • CSpyware
  • DAdware

How the community answered

(30 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    93% (28)

Why each option

Spyware is designed to covertly monitor user activity and is commonly delivered through drive-by downloads that execute without any deliberate action by the victim.

AVirus

A virus requires a host file and typically needs a user to execute an infected file in order to propagate, which contradicts the no-user-interaction characteristic.

BLogic bomb

A logic bomb is dormant code that triggers when a specific condition is met and is not characterized by monitoring activity or drive-by delivery.

CSpywareCorrect

Spyware silently runs in the background to collect keystrokes, browsing habits, credentials, or screen captures and transmit them to an attacker. It is frequently installed via drive-by downloads - malicious scripts embedded in web pages that exploit browser or plugin vulnerabilities and execute automatically when the page is visited, requiring no explicit user consent or action.

DAdware

Adware displays advertisements and is usually installed alongside software the user intentionally downloads, requiring some level of user interaction.

Concept tested: Spyware delivery via drive-by download without user interaction

Source: https://www.cisa.gov/news-events/news/understanding-hidden-threats-rootkits-and-botnets

Topics

#spyware#malware types#drive-by download#covert monitoring

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice