Cisco Certified Support Technician (CCST) CybersecurityEndpoint SecurityHard
An organization is concerned about phishing attacks and zero-day malware attempting to exploit vulnerabilities in web browsers or document readers on employee workstations. They want a solution that can isolate these high-risk applications from the rest of the operating system, limiting potential damage if an exploit is successful. Which security concept is being sought?
- ANetwork Access Control (NAC)
- BData Loss Prevention (DLP)
- CApplication Sandbox
- DAntivirus/Anti-malware
Show answer & explanationAnswer & explanation
Correct answer: C. Application Sandbox
An application sandbox provides a tightly controlled, isolated environment for applications like web browsers or PDF readers. If an exploit occurs within the sandbox, its impact is contained to that isolated environment, preventing it from affecting the rest of the operating system.
Why the other options are wrong
- A. NAC controls network access, not the isolation of applications on an endpoint.
- B. DLP prevents data exfiltration, not the containment of application exploits.
- D. Antivirus detects and removes malware, but may not stop zero-day exploits that bypass signatures.
Application Sandbox
A security mechanism that isolates a running program in a restricted environment, preventing it from interacting with other parts of the system or network outside of its defined boundaries.
- Contains potential exploits and malware.
- Limits damage to the sandboxed environment.
- Commonly used for web browsers, email clients, and document viewers.
Memory trick: Sandbox: A 'playpen' for risky apps, keeping messes contained.