EC-Council Certified Ethical Hacker (CEH) v12Malware ThreatsEasy

A security administrator is configuring endpoint protection for a critical server. To prevent the execution of unauthorized or unknown malicious applications, the administrator decides to implement a policy that only allows applications explicitly approved by IT to run. All other applications, by default, are blocked. Which malware countermeasure is being implemented?

  1. ABehavioral Analysis
  2. BHeuristic Scanning
  3. CApplication Whitelisting
  4. DSignature-based Antivirus
Show answer & explanation

Correct answer: C. Application Whitelisting

Application whitelisting is a security measure that permits only an explicitly authorized list of applications to execute on a system, effectively blocking all others by default. This is highly effective against unknown malware and zero-day threats.

Why the other options are wrong

  • A. Behavioral analysis monitors program actions for suspicious patterns, but doesn't inherently block all unapproved applications by default.
  • B. Heuristic scanning uses rules and algorithms to identify potentially malicious behavior, but doesn't block all unapproved applications by default like whitelisting.
  • D. Signature-based antivirus detects known malware based on specific patterns, not unknown or unauthorized applications.

Application Whitelisting

A security strategy that allows only explicitly authorized applications to run on a computer system, while blocking all other applications by default.

  • Blocks unknown and unauthorized executables.
  • Highly effective against zero-day malware.
  • Requires careful management of the approved application list.

Memory trick: Whitelist: Only the 'White' ones get permission to run.

More Malware Threats questions