nerdexam
CompTIA

SY0-501 · Question #151

A user clicked an email link that led to a website that infected the workstation with a virus. The virus encrypted all the network shares to which the user had access. The virus was not detected or…

The correct answer is D. The virus was a zero-day attack. A virus infected a workstation and successfully encrypted network shares after bypassing all existing security controls, including email, website, and antivirus filters.

Submitted by layla.eg· Mar 4, 2026Threats, vulnerabilities, and mitigations

Question

A user clicked an email link that led to a website that infected the workstation with a virus. The virus encrypted all the network shares to which the user had access. The virus was not detected or blocked by the company's email filter, website filter, or antivirus. Which of the following describes what occurred?

Options

  • AThe user's account was over-privileged.
  • BImproper error handling triggered a false negative in all three controls
  • CThe email originated from a private email server with no malware protection
  • DThe virus was a zero-day attack

How the community answered

(17 responses)
  • B
    12% (2)
  • C
    6% (1)
  • D
    82% (14)

Why each option

A virus infected a workstation and successfully encrypted network shares after bypassing all existing security controls, including email, website, and antivirus filters.

AThe user's account was over-privileged.

While the user's account being over-privileged allowed the virus to inflict more damage, it does not explain why the initial security controls failed to detect or block the malware.

BImproper error handling triggered a false negative in all three controls
CThe email originated from a private email server with no malware protection
DThe virus was a zero-day attackCorrect

The scenario describes a sophisticated attack where a virus was completely undetected by multiple layers of security (email filter, website filter, antivirus). This is the hallmark of a zero-day attack, which exploits a vulnerability unknown to security vendors or for which no patch or detection signature exists, allowing it to bypass conventional defenses.

Concept tested: Zero-day attack characteristics and detection bypass

Source: https://learn.microsoft.com/en-us/windows/security/threat-protection/zero-day-vulnerability

Topics

#zero-day attack#ransomware#over-privilege#security controls bypass

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice