GCIH Exam QuestionsBrowse all questions from this exam

GCIH Exam - Question 172


How does the use of endpoint application allow lists impact malware attacks against the system?

Show Answer
Correct Answer: BD

The use of endpoint application allow lists impacts malware attacks against the system because it forces an attacker to modify their attack tool use. Application allow lists limit the applications that can run on a system to a pre-approved list, thereby preventing unauthorized or malicious applications from executing. This means attackers cannot use their usual tools and must find alternative methods to bypass these restrictions, typically leading to modifications in how they deploy their attacks.

Discussion

1 comment
Sign in to comment
XBalOption: D
Mar 16, 2023

Answer is "D" based upon Living Off the Land (LOL) concept

Vikt0r
Dec 6, 2023

What messes me up is the verbiage. modify attack tool.