A security analyst reviews an alert from an endpoint detection and response (EDR) agent installed on a user workstation. The telemetry reveals a background process silently logging user keystrokes, taking screenshots of desktop applications, and exfiltrating the collected data to an external server. Which of the following malware classifications and attributes describe this activity? (Select TWO.)
- Keylogger software designed to capture user inputs and credential submissionsAnswer
- Spyware functionality focused on monitoring user actions and gathering system dataAnswer
- CSelf-propagating worm mechanisms that spread autonomously across network subnets
- DNetwork firewall rules configured to prevent host application buffer overflows
Answer
The activity is described by keylogger software capturing user inputs and spyware functionality monitoring activity and exfiltrating data.
The observed indicators directly point to keylogging (intercepting keystrokes) and spyware (covertly recording screen activity and exfiltrating surveillance data to a third party).
Step-by-Step Solution
Key Concept
Malware Types and Indicators of Compromise (Keyloggers and Spyware)