SY0-501 · Question #562
A security administrator is reviewing the following network capture: Which of the following malware is MOST likely to generate the above information?
The correct answer is A. Keylogger. A network capture showing information being generated is most indicative of a keylogger, which captures keystrokes and transmits them over the network.
Question
A security administrator is reviewing the following network capture:
Which of the following malware is MOST likely to generate the above information?
Options
- AKeylogger
- BRansomware
- CLogic bomb
- DAdware
How the community answered
(58 responses)- A76% (44)
- B14% (8)
- C3% (2)
- D7% (4)
Why each option
A network capture showing information being generated is most indicative of a keylogger, which captures keystrokes and transmits them over the network.
Keyloggers are a type of surveillance software designed to record user keystrokes and other input without their knowledge. This captured 'information' (keystrokes, passwords, sensitive data) is then typically exfiltrated over the network to an attacker, making it visible in a network capture.
Adware primarily aims to display unwanted advertisements, redirect web traffic, and gather marketing data, but it does not typically focus on the covert exfiltration of captured keystrokes or other specific 'information' in the same manner as a keylogger.
Concept tested: Malware types and their network behavior
Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/malware-types?view=o365-worldwide
Topics
Community Discussion
No community discussion yet for this question.