exam questions

Exam 312-50v13 All Questions

View all questions & answers for the 312-50v13 exam

Exam 312-50v13 topic 1 question 33 discussion

Actual exam question from ECCouncil's 312-50v13
Question #: 33
Topic #: 1
[All 312-50v13 Questions]

Security administrator John Smith has noticed abnormal amounts of traffic coming from local computers at night. Upon reviewing, he finds that user data have been exfiltrated by an attacker. AV tools are unable to find any malicious software, and the IDS/IPS has not reported on any non-whitelisted programs.
What type of malware did the attacker use to bypass the company’s application whitelisting?

  • A. File-less malware
  • B. Zero-day malware
  • C. Phishing malware
  • D. Logic bomb malware
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
jonekool
1 week, 4 days ago
Selected Answer: A
File-less Malware - AV tools are unable to find
upvoted 1 times
...
Jacket
2 weeks, 6 days ago
Selected Answer: A
Abnormal traffic is detected at night (data exfiltration). Antivirus tools detect nothing. IDS/IPS systems don’t flag any non-whitelisted programs. Everything appears normal, but something is clearly wrong. This suggests the attacker used malware that doesn’t leave traditional file footprints — a key characteristic of file-less malware.
upvoted 1 times
...
000f1d9
3 weeks, 2 days ago
Selected Answer: A
Fileless malware are associated with "live off the land" intrusions, which utilize whitelisted applications, for example powershell, to avoid detection. Also, they can employ malware in techniques that aren't stored to disk, only run in memory, like a remote execution of Powershell scripts like invoke-mimikatz to harvest credentials. These are not "zero day" malware, since they are either 1. legitimate tools being abused, 2. known malware running in memory.
upvoted 1 times
...
Fiete
1 month ago
Selected Answer: B
We have two criteria: - AV tools are unable to find any malicious software This could apply to both a file-less (in-memory) malware and zero-day malware. - the IDS/IPS has not reported on any non-whitelisted programs The wording seems to indicate that this is a host-based IDS/IPS that links packets to processes and their executable files and then reports if any non-whitelisted executable sends packets. For a file-less malware the executable would be <empty> which is most certainly not whitelisted. A zero-day malware could simply embed itself into an already whitelisted executable (e.g. chrome.exe) and would not trigger an alert. Therefore: B
upvoted 1 times
...
killwitch
1 month, 2 weeks ago
Selected Answer: A
File-less malware is a type of malicious software that operates without relying on traditional files. Instead of installing executable files, file-less malware typically exploits system vulnerabilities or runs in-memory, often through scripting languages or legitimate system tools. Because it doesn't rely on files, it can bypass traditional antivirus (AV) tools and application whitelisting mechanisms that focus on detecting file-based threats. In this case, the fact that AV tools couldn't detect any malicious software and the IDS/IPS didn't flag any non-whitelisted programs suggests that the malware did not rely on traditional files but instead operated directly in memory, making it difficult to detect and block.
upvoted 1 times
...
marcel9999
1 month, 4 weeks ago
Selected Answer: B
Zero day because not recognized bypass all detections
upvoted 1 times
...
SukhoiF35
2 months, 2 weeks ago
Selected Answer: B
Malware wasn't recognised by any AV or IPS/IDS. File-Less malware exfiltration can be detected with IPS
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago