EC-Council Certified Ethical Hacker (CEH) v12Malware ThreatsEasy
A security administrator is configuring endpoint protection for a critical server. To prevent the execution of unauthorized or unknown malicious applications, the administrator decides to implement a policy that only allows applications explicitly approved by IT to run. All other applications, by default, are blocked. Which malware countermeasure is being implemented?
- ABehavioral Analysis
- BHeuristic Scanning
- CApplication Whitelisting
- DSignature-based Antivirus
Show answer & explanationAnswer & explanation
Correct answer: C. Application Whitelisting
Application whitelisting is a security measure that permits only an explicitly authorized list of applications to execute on a system, effectively blocking all others by default. This is highly effective against unknown malware and zero-day threats.
Why the other options are wrong
- A. Behavioral analysis monitors program actions for suspicious patterns, but doesn't inherently block all unapproved applications by default.
- B. Heuristic scanning uses rules and algorithms to identify potentially malicious behavior, but doesn't block all unapproved applications by default like whitelisting.
- D. Signature-based antivirus detects known malware based on specific patterns, not unknown or unauthorized applications.
Application Whitelisting
A security strategy that allows only explicitly authorized applications to run on a computer system, while blocking all other applications by default.
- Blocks unknown and unauthorized executables.
- Highly effective against zero-day malware.
- Requires careful management of the approved application list.
Memory trick: Whitelist: Only the 'White' ones get permission to run.