exam questions

Exam 312-50v11 All Questions

View all questions & answers for the 312-50v11 exam

Exam 312-50v11 topic 1 question 282 discussion

Actual exam question from ECCouncil's 312-50v11
Question #: 282
Topic #: 1
[All 312-50v11 Questions]

Chandler works as a pen-tester in an IT-firm in New York. As a part of detecting viruses in the systems, he uses a detection method where the anti-virus executes the malicious codes on a virtual machine to simulate CPU and memory activities. Which type of virus detection method did Chandler use in this context?

  • A. Heuristic Analysis
  • B. Code Emulation
  • C. Scanning
  • D. Integrity checking
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
dinonino
Highly Voted 7 months, 3 weeks ago
Virus Detection Methods Scanning: Once a virus is detected, it is possible to write scanning programs that look for signature string characteristics of the virus Integrity Checking: Integrity checking products work by reading the entire disk and recording integrity data that act as a signature for the files and system sectors Interception: The interceptor monitors the operating system requests that are written to the disk Code Emulation: In code emulation techniques, the antivirus executes the malicious code inside a virtual machine to simulate CPU and memory activities These techniques are considered very effective in dealing with encrypted and polymorphic viruses if the virtual machine mimics the real machine Heuristic Analysis: Heuristic analysis can be static or dynamic In static analysis, the antivirus analyses the file format and code structure to determine if the code is viral In dynamic analysis, the antivirus performs a code emulation of the suspicious code to determine if the code is viral CEH: Malware Threats
upvoted 6 times
...
Daniel8660
Most Recent 6 months, 3 weeks ago
Selected Answer: B
Virus Detection Methods - Code Emulation In code emulation techniques, the antivirus executes the malicious code inside a virtual machine to simulate CPU and memory activities.
These techniques are considered very effective in dealing with encrypted and polymorphic viruses if the virtual machine mimics the real machine. (P.1042/1026)
upvoted 3 times
...
AleksVAnd
1 year ago
Code Emulation is correct. The method described in the question is one of two. The other is to use a VM. Module 7 page 1026 However there's something to point out: heuristic analysis - dynamic analysis includes code emulation. So it is also a correct answer. Just not the best answer.
upvoted 4 times
...
ANDRESCB1988
1 year, 9 months ago
correct
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago