CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsMedium

A disgruntled system administrator, aware they are about to be terminated, embeds code into the company's payroll application that will delete all employee records if their user account is ever removed from Active Directory. Which malicious activity indicator best describes this scenario?

  1. ARansomware deployment
  2. BWatering hole attack
  3. CLogic bomb
  4. DBuffer overflow exploit
Show answer & explanation

Correct answer: C. Logic bomb

A logic bomb is malicious code intentionally inserted into software that lies dormant until a specific condition or trigger event occurs, such as an account deletion, at which point it executes a damaging action. This scenario is a classic example of an insider planting a logic bomb tied to their own termination.

Why the other options are wrong

  • A. Ransomware encrypts data for extortion, whereas this code deletes records upon a trigger, not for ransom.
  • B. A watering hole attack compromises a site frequented by targets, not an internal payroll application.
  • D. Buffer overflow exploits memory handling flaws, unrelated to condition-triggered sabotage code.

Logic Bomb

Malicious code deliberately planted within a program that remains inactive until a specific trigger condition is met, then executes a harmful action.

  • Often planted by insiders with legitimate access
  • Triggered by dates, events, or account changes
  • Detected through code reviews and change monitoring

Memory trick: A logic bomb waits like a landmine for the right footstep (trigger).

More Threats, Vulnerabilities, and Mitigations questions