Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsHard

A forensic investigator is analyzing a compromised endpoint. The investigation reveals that malware was able to evade detection by modifying its signature multiple times, making it difficult for traditional antivirus software to identify. Which type of malware characteristic allowed it to bypass signature-based detection?

  1. ASpyware
  2. BAdware
  3. CRootkit
  4. DPolymorphic Malware
Show answer & explanation

Correct answer: D. Polymorphic Malware

Polymorphic malware is designed to constantly change its identifiable features (its 'signature') while retaining its original functionality. This allows it to evade detection by signature-based antivirus software, which relies on matching known malicious code patterns.

Why the other options are wrong

  • A. Spyware collects information about users without their knowledge and is not primarily defined by its ability to change signatures.
  • B. Adware displays unwanted advertisements and is generally not characterized by signature evasion techniques.
  • C. A rootkit is designed to hide its presence and maintain privileged access, but its primary characteristic isn't changing its signature to evade detection.

Polymorphic Malware

A type of malware that constantly changes its identifiable code or signature to evade detection by antivirus software and intrusion detection systems.

  • Uses encryption or obfuscation to alter its appearance.
  • Retains its malicious functionality despite code changes.
  • Presents a significant challenge for signature-based detection.

Memory trick: Malware Morphs to Hide.

More Security Concepts questions