EC-Council Certified Ethical Hacker (CEH) v12Malware ThreatsMedium
An organization is implementing a new security policy to prevent malware infections. Which of the following countermeasures is specifically designed to protect against malware that attempts to exploit unpatched software vulnerabilities by executing malicious code directly in memory?
- AApplication Whitelisting
- BNetwork Segmentation
- CData Loss Prevention (DLP)
- DExploit Prevention Systems (EPS)
Show answer & explanationAnswer & explanation
Correct answer: D. Exploit Prevention Systems (EPS)
Exploit Prevention Systems (EPS) are specifically designed to detect and block exploitation techniques, such as buffer overflows, heap sprays, and return-oriented programming (ROP), that malicious code uses to execute in memory, even against unpatched vulnerabilities.
Why the other options are wrong
- A. Application whitelisting prevents unauthorized applications from running, but doesn't directly stop exploits targeting authorized applications' memory.
- B. Network segmentation helps contain malware spread but doesn't prevent the initial exploitation of a vulnerability on an endpoint.
- C. DLP focuses on preventing sensitive data from leaving the organization, not blocking malware execution attempts.
Exploit Prevention System (EPS)
Security solutions designed to detect and block common exploit techniques (e.g., buffer overflows, ROP, heap spray) used by malware to leverage software vulnerabilities, often before a patch is available.
- Focuses on exploit techniques, not just signatures.
- Protects against zero-day exploits.
- Monitors memory and process behavior for anomalies.
Memory trick: EPS proactively 'Exploit-Proofs' your system's vulnerable spots.