exam questions

Exam 200-201 All Questions

View all questions & answers for the 200-201 exam

Exam 200-201 topic 1 question 18 discussion

Actual exam question from Cisco's 200-201
Question #: 18
Topic #: 1
[All 200-201 Questions]

Which evasion technique is a function of ransomware?

  • A. extended sleep calls
  • B. encryption
  • C. resource exhaustion
  • D. encoding
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
alhamry
Highly Voted 2 years ago
The correct answer is B. encryption. Ransomware is a type of malware that encrypts a victim's files and demands payment in exchange for the decryption key. Encryption is the primary evasion technique used by ransomware to avoid detection and protect the malicious code from analysis or reverse-engineering. The other options listed as evasion techniques are not specific to ransomware.
upvoted 7 times
...
drdecker100
Most Recent 7 months, 1 week ago
Selected Answer: B
The other options are not specific to ransomware. For example, extended sleep calls are used in a variety of malicious software to slow down the execution of the malware, resource exhaustion is used to overload systems and cause them to crash, and encoding is used to obfuscate payloads. B - encryption is the correct answer because ransomware often encrypts the data of an infected system and demands payment in exchange for the decryption key. This encryption technique is a key aspect of the ransomware threat and is used to evade detection and make it difficult for organizations to recover their data.
upvoted 2 times
...
dunno_
7 months, 1 week ago
Selected Answer: B
The primary evasion technique used by ransomware is encryption. Ransomware encrypts the victim's files, making them inaccessible until a ransom is paid. This encryption is not only a means to hold the data hostage but also serves as an evasion technique because it prevents the data from being easily analyzed or recovered without the decryption key. While extended sleep calls can be used by some malware for evasion, encryption is the hallmark technique of ransomware. The Correct answer seems to be : B
upvoted 2 times
...
Andre70
1 year ago
Selected Answer: A
Enryption is not an an evasion technique. It is the primary function of randsomware. The evasion is the extended sleep, in my opinion
upvoted 1 times
Coffeezw
6 months, 2 weeks ago
The provided answer B is correct, the question asked for a function of Ransomware from the listed evasion techniques(answers).
upvoted 1 times
...
...
WISDOM2080
1 year, 8 months ago
B. encryption
upvoted 2 times
...
Nav1999
2 years ago
I go with B
upvoted 3 times
...
ASIDIBE
2 years, 3 months ago
The correct is B
upvoted 2 times
...
MaliDong
2 years, 6 months ago
Selected Answer: C
I go with C.
upvoted 1 times
MaliDong
2 years, 6 months ago
typo, B is correct.
upvoted 1 times
...
...
joseph267
2 years, 9 months ago
encryption is not used as an evation technique for ransomware but... it is for other attacks such as trojans or malicious payloads to hide from security mechanisms in ransomware encryption is used as the method to ask for a ransom
upvoted 1 times
...
halamah
3 years, 5 months ago
B IS CORRECT
upvoted 2 times
...
vprollc
3 years, 9 months ago
The study guide lists the following as evastion techniques against IDS and IPS devices: Fragmentation, low bandwidth attacks, address spoofing/proxying, pattern change evasion, and encryption. Based on that, I think the answer is correct.
upvoted 4 times
...
Leo_Visser
3 years, 11 months ago
I think the question should be "which attack vector is used by randsomeware". As most of the answers aren't really evesion techniques.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago