A security analyst reviews an alert from an endpoint detection and response (EDR) agent installed on a user workstation. The telemetry reveals a background process silently logging user keystrokes, taking screenshots of desktop applications, and exfiltrating the collected data to an external server. Which of the following malware classifications and attributes describe this activity? (Select TWO.)
- Keylogger software designed to capture user inputs and credential submissionsCevap
- Spyware functionality focused on monitoring user actions and gathering system dataCevap
- CSelf-propagating worm mechanisms that spread autonomously across network subnets
- DNetwork firewall rules configured to prevent host application buffer overflows
Cevap
The activity is described by keylogger software capturing user inputs and spyware functionality monitoring activity and exfiltrating data.
The observed indicators directly point to keylogging (intercepting keystrokes) and spyware (covertly recording screen activity and exfiltrating surveillance data to a third party).
Adım Adım Çözüm
Anahtar Kavram
Malware Types and Indicators of Compromise (Keyloggers and Spyware)