SY0-501 · Question #151
A user clicked an email link that led to a website that infected the workstation with a virus. The virus encrypted all the network shares to which the user had access. The virus was not detected or…
The correct answer is D. The virus was a zero-day attack. A virus infected a workstation and successfully encrypted network shares after bypassing all existing security controls, including email, website, and antivirus filters.
Question
A user clicked an email link that led to a website that infected the workstation with a virus. The virus encrypted all the network shares to which the user had access. The virus was not detected or blocked by the company's email filter, website filter, or antivirus. Which of the following describes what occurred?
Options
- AThe user's account was over-privileged.
- BImproper error handling triggered a false negative in all three controls
- CThe email originated from a private email server with no malware protection
- DThe virus was a zero-day attack
How the community answered
(17 responses)- B12% (2)
- C6% (1)
- D82% (14)
Why each option
A virus infected a workstation and successfully encrypted network shares after bypassing all existing security controls, including email, website, and antivirus filters.
While the user's account being over-privileged allowed the virus to inflict more damage, it does not explain why the initial security controls failed to detect or block the malware.
The scenario describes a sophisticated attack where a virus was completely undetected by multiple layers of security (email filter, website filter, antivirus). This is the hallmark of a zero-day attack, which exploits a vulnerability unknown to security vendors or for which no patch or detection signature exists, allowing it to bypass conventional defenses.
Concept tested: Zero-day attack characteristics and detection bypass
Source: https://learn.microsoft.com/en-us/windows/security/threat-protection/zero-day-vulnerability
Topics
Community Discussion
No community discussion yet for this question.