Cisco Certified Support Technician (CCST) CybersecurityEndpoint SecurityMedium
A company is concerned about a new sophisticated malware strain that uses polymorphic code to evade traditional signature-based antivirus detection. The security team needs an endpoint security technology that can identify and block this type of evolving threat by analyzing its behavior rather than relying solely on known signatures. Which technology offers this capability?
- ASignature-based Antivirus
- BVulnerability Scanner
- CData Loss Prevention (DLP)
- DHeuristic/Behavioral Analysis
Show answer & explanationAnswer & explanation
Correct answer: D. Heuristic/Behavioral Analysis
Heuristic/Behavioral Analysis is designed to detect unknown or evolving threats by observing their actions and characteristics, such as unusual system calls, file modifications, or network activity, rather than relying on static signatures. This makes it effective against polymorphic malware.
Why the other options are wrong
- A. Signature-based antivirus is ineffective against polymorphic malware as it relies on known patterns.
- B. A vulnerability scanner identifies weaknesses in systems, not active malware behavior.
- C. DLP protects sensitive data, it does not detect malware based on its behavior.
Heuristic/Behavioral Analysis
An endpoint security technique that detects malware by analyzing its behavior and characteristics (e.g., system calls, API usage, file changes) rather than relying on predefined signatures. It is effective against zero-day and polymorphic threats.
- Identifies suspicious actions that indicate malicious intent.
- Can detect previously unknown (zero-day) malware.
- Often used in conjunction with signature-based detection for comprehensive protection.
Memory trick: Instead of a mugshot, behavioral analysis watches what the malware 'does' to catch it.