exam questions

Exam 220-1002 All Questions

View all questions & answers for the 220-1002 exam

Exam 220-1002 topic 1 question 80 discussion

Actual exam question from CompTIA's 220-1002
Question #: 80
Topic #: 1
[All 220-1002 Questions]

A computer becomes infected with malware, which manages to steal all credentials stored on the PC. The malware then uses elevated credentials to infect all other PCs at the site. Management asks the IT staff to take action to prevent this from reoccurring.
Which of the following would BEST accomplish this goal?

  • A. Use an antivirus product capable of performing heuristic analysis
  • B. Use a host-based intrusion detection system on each computer
  • C. Disallow the password caching of accounts in the administrators group
  • D. Install a UTM in between PC endpoints to monitor for suspicious traffic
  • E. Log all failed login attempts to the PCs and report them to a central server
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
betty_boop
Highly Voted 4 years, 9 months ago
It's A OBJ-2.2: The only solution provided that could STOP this from reoccurring would be to use an anti-virus or anti-malware solution with heuristic analysis. The other options might be able to monitor and detect the issue, but not stop it from spreading. Heuristic analysis is a method employed by many computer anti-virus programs designed to detect previously unknown computer viruses, as well as new variants of viruses already in the wild. This is behavior-based detection and prevention, so it should be able to detect the issue in the scenario provided and stop it from spreading throughout the network. source: Jason Dion's practice exams.
upvoted 39 times
...
KM
Highly Voted 5 years, 3 months ago
UTM install at network level and not host level. The correct answer is A.
upvoted 16 times
...
Nat2down
Most Recent 2 years, 8 months ago
know what the definition of heuristic analysis is: Heuristic analysis is a method employed by many computer antivirus programs designed to detect previously unknown computer viruses, as well as new variants of viruses already in the "wild".Heuristic analysis is an expert based analysis that determines the susceptibility of a system towards particular threat/risk using various decision rules or weighing methods. MultiCriteria analysis is one of the means of weighing.
upvoted 2 times
...
miki1001
3 years, 6 months ago
Unified Threat Management, a UTM is a networking device or software program that helps reduce the complexity of securing a network. It accomplishes this by including an anti-malware, content filter, firewall, intrusion detection, and spam protection into a single package.
upvoted 1 times
...
dnbly
4 years ago
A is correct. It would detect and combat the threat on the host before it can act or spread to other hosts. B, D, E all reference the purpose of detecting or monitoring so they are not preventing the threat i.e. a UTM that is only monitoring will not help prevent a breach. C is also not preventing the threat, only reducing the attack surface.
upvoted 2 times
...
alanstorm
4 years, 1 month ago
MeasureUp give the A correct answer
upvoted 2 times
...
MrNYC
4 years, 4 months ago
In answer "A" it says "Use an antivirus product" but in the question it says infected with "Malware".I guess antivirus products are not antimalware. viruses are part of malware but malware is not part of viruses. So i guess "D" should be correct answer.
upvoted 2 times
...
MelvinJohn
4 years, 4 months ago
[Question says “to PREVENT this (malware infections? or using elevated credentials?) from reoccurring”] C? -- Disallow the password caching of accounts in the administrators group (last line of defense) - prevents hackers obtaining elevated credentials. D? – Unified Threat Management devices provide integrated Intrusion PREVENTION [first line of defense]
upvoted 1 times
...
solmon
4 years, 10 months ago
i believe the answer should be C . The malware used admins accounts conditionals
upvoted 3 times
...
JustinGonnaPassThis
4 years, 11 months ago
To prevent it from occurring again, install a utm. What is heuristic analysis?
upvoted 1 times
mfombi
4 years, 10 months ago
DescriptionHeuristic analysis is a method employed by many computer antivirus programs designed to detect previously unknown computer viruses, as well as new variants of viruses already in the "wild" - Wikipedia
upvoted 2 times
...
...
Ptera
5 years, 1 month ago
Not sure how much this matters but neither the word "heuristic" nor phrase "heuristic analysis" are found in the A+ prep book
upvoted 5 times
...
Rz10
5 years, 4 months ago
D sound correct to me: Per google search : Unified threat management (UTM) provides multiple security features and services in a single device or service on the network, protecting users from security threats in a simplified way. UTM includes functions such as anti-virus, anti-spam, content filtering, and web filtering.
upvoted 2 times
SkyShark
5 years, 1 month ago
If the malware has admin credentials and is utilizing them to log in, would that not render the UTM useless?
upvoted 2 times
...
...
Naveed
5 years, 4 months ago
best answer is D
upvoted 2 times
KingPo
5 years, 4 months ago
I'm not convinced! :) Can you pls post why you think D is correct. Just monitoring for suspicious traffic will not prevent this from reoccuring. A - Interpreted A as correct answer, as I expect the actuall malware app seems not to be able to detect these kind of virus. So they should upgrade to a app with is able to do heuristic analysis and be able to find these unknown virus (https://en.wikipedia.org › wiki › Heuristic_analysis)
upvoted 4 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago