Cisco Certified Support Technician (CCST) CybersecurityEndpoint SecurityHard
A security engineer is evaluating the effectiveness of the company's current endpoint security posture against zero-day exploits. They note that traditional signature-based antivirus frequently fails to detect these new threats. Which advanced detection technique would provide a better defense against polymorphic malware and unknown threats?
- AHeuristic/Behavioral analysis
- BStatic file analysis
- CHash-based detection
- DSignature-based detection
Show answer & explanationAnswer & explanation
Correct answer: A. Heuristic/Behavioral analysis
Heuristic and behavioral analysis techniques monitor the actions and characteristics of programs for suspicious patterns, allowing them to detect new or polymorphic malware that doesn't have a known signature.
Why the other options are wrong
- B. Static file analysis examines file properties without executing it, which can be useful but less effective against polymorphic threats that change their code.
- C. Hash-based detection relies on exact file hashes, making it useless against polymorphic malware that changes its hash.
- D. Signature-based detection relies on known malware patterns and is ineffective against zero-day exploits or polymorphic malware.
Heuristic/Behavioral Analysis
An advanced malware detection technique that identifies malicious software by analyzing its behavior, characteristics, and potential actions, rather than relying solely on known signatures.
- Effective against zero-day and polymorphic threats.
- Monitors process activity, system calls, and file modifications.
- Can sometimes result in false positives.
Memory trick: Signatures are like mugshots, Heuristics are like profiling behavior.