SECFND 12: Endpoint Security Technologies Flashcards

1
Q

Address on whitelist and blacklist. Which wins?

A

Whitelist

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Whitelisted/blacklisted apps can be identified by…

A

hash value, certificate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Whitelisting flaw

A

Apps that run in memory

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

AV File trajectory

A

Hosts where files were seen

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

AV Device trajectory

A

Actions that files performed on a given host

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Packed malware

A

Compressed to make it polymorphic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly