Cisco Certified Support Technician (CCST) CybersecurityEndpoint SecurityHard

A security engineer is evaluating the effectiveness of the company's current endpoint security posture against zero-day exploits. They note that traditional signature-based antivirus frequently fails to detect these new threats. Which advanced detection technique would provide a better defense against polymorphic malware and unknown threats?

  1. AHeuristic/Behavioral analysis
  2. BStatic file analysis
  3. CHash-based detection
  4. DSignature-based detection
Show answer & explanation

Correct answer: A. Heuristic/Behavioral analysis

Heuristic and behavioral analysis techniques monitor the actions and characteristics of programs for suspicious patterns, allowing them to detect new or polymorphic malware that doesn't have a known signature.

Why the other options are wrong

  • B. Static file analysis examines file properties without executing it, which can be useful but less effective against polymorphic threats that change their code.
  • C. Hash-based detection relies on exact file hashes, making it useless against polymorphic malware that changes its hash.
  • D. Signature-based detection relies on known malware patterns and is ineffective against zero-day exploits or polymorphic malware.

Heuristic/Behavioral Analysis

An advanced malware detection technique that identifies malicious software by analyzing its behavior, characteristics, and potential actions, rather than relying solely on known signatures.

  • Effective against zero-day and polymorphic threats.
  • Monitors process activity, system calls, and file modifications.
  • Can sometimes result in false positives.

Memory trick: Signatures are like mugshots, Heuristics are like profiling behavior.

More Endpoint Security questions