Soru

Zorluk: OrtaMalware Types and Indicators of Compromise

During a security audit, system administrators discover an unapproved executable file residing on a database server. Technical analysis reveals that the executable monitors system performance and remains inactive until the database reaches exactly 1000010{}000 records, at which point it automatically executes a script to purge system audit logs. Which of the following malware classifications best describes this threat?

  1. Logic bombCevap
  2. B
    Self-propagating worm
  3. C
    Trojan horse
  4. D
    Kernel-level rootkit

Cevap

Logic bomb
The correct answer is the choice identifying a logic bomb. A logic bomb is a piece of code intentionally inserted into a software system that remains dormant until specific logical conditions—such as reaching a specified number of database records, a specific timestamp, or an account status change—are met.

Adım Adım Çözüm

1
Analyze the operational behavior of the discovered malware.
The malware remains dormant until a specific condition (1000010{}000 database records) is satisfied.
Identifying the execution mechanism differentiates conditional execution from self-propagation or user trickery.
2
Evaluate the trigger condition against malware characteristics.
A payload programmed to fire when precise environmental or logical criteria are met defines a logic bomb.
Logic bombs execute automatically upon predefined event thresholds.

Anahtar Kavram

Logic Bomb Characteristics
Tahmini Süre:1m 15s
Bu soruyu puanla