312-50v12 Exam QuestionsBrowse all questions from this exam

312-50v12 Exam - Question 33


Security administrator John Smith has noticed abnormal amounts of traffic coming from local computers at night. Upon reviewing, he finds that user data have been exfiltrated by an attacker. AV tools are unable to find any malicious software, and the IDS/IPS has not reported on any non-whitelisted programs.

What type of malware did the attacker use to bypass the company’s application whitelisting?

Show Answer
Correct Answer: A

The attacker used file-less malware. File-less malware operates entirely in the system's memory, making it difficult for traditional antivirus software to detect since it doesn't leave a trace on the hard drive. Additionally, since it can run in the context of a trusted system process or application, it can bypass application whitelisting and avoid being flagged by IDS/IPS systems.

Discussion

7 comments
Sign in to comment
eli117Option: A
Oct 4, 2023

A. File-less malware Explanation: In this scenario, the attacker used file-less malware to bypass the company's application whitelisting. File-less malware resides entirely in memory, making it difficult for antivirus software and IDS/IPS to detect. It can run in the context of a trusted process or system application, and can be delivered through various attack vectors, including phishing emails, malicious websites, or network exploits.

jeremy13Option: A
Oct 10, 2023

A. File-less malware 312-50v11 Q164 https://www.trellix.com/en-us/security-awareness/ransomware/what-is-fileless-malware.html

Vincent_Lu
Dec 12, 2023

A. File-less malware should be the answer. But why not B?

deviii
Jan 29, 2024

Because it's mentioned AV didn't flag any "non-whitelisted file"

mattlai
Feb 13, 2024

zero day does not necessarily need a file to execute

mattlai
Feb 13, 2024

zero day does not necessarily need a file to execute

insaniuntOption: A
Jun 10, 2024

A. File-less malware

kikourOption: B
Oct 11, 2024

0day because it's most likely not in a whitelist, IDS/IPS may detect file-less still

Mann098Option: A
Dec 29, 2024

File-less malware

hang10zOption: B
Dec 27, 2024

Zero day, otherwise his ips/ids and av would detect the threat. AV/EDR can detect malware running in memory.

hang10z
Dec 27, 2024

File-less, I change my answer