Soru

Zorluk: KolayMalware Types and Indicators of Compromise

A security analyst reviews an alert from an endpoint detection and response (EDR) agent installed on a user workstation. The telemetry reveals a background process silently logging user keystrokes, taking screenshots of desktop applications, and exfiltrating the collected data to an external server. Which of the following malware classifications and attributes describe this activity? (Select TWO.)

  1. Keylogger software designed to capture user inputs and credential submissionsCevap
  2. Spyware functionality focused on monitoring user actions and gathering system dataCevap
  3. C
    Self-propagating worm mechanisms that spread autonomously across network subnets
  4. D
    Network firewall rules configured to prevent host application buffer overflows

Cevap

The activity is described by keylogger software capturing user inputs and spyware functionality monitoring activity and exfiltrating data.
The observed indicators directly point to keylogging (intercepting keystrokes) and spyware (covertly recording screen activity and exfiltrating surveillance data to a third party).

Adım Adım Çözüm

1
Analyze the observed technical indicators of compromise (IoCs)
The background process captures keystrokes, takes screenshots, and transmits telemetry to a remote server.
Identifying specific payload actions helps categorize malware types.
2
Match IoCs to malware categories
Capturing keystrokes directly identifies keylogger capabilities, while covert surveillance and data exfiltration identify spyware functions.
Keyloggers and spyware frequently operate together on compromised endpoints to harvest sensitive data.

Anahtar Kavram

Malware Types and Indicators of Compromise (Keyloggers and Spyware)
Bu soruyu puanla