Courseiva

CCNA Malicious Code and Exploit Mitigation Questions

16 questions · Malicious Code and Exploit Mitigation · All types, answers revealed

1
MCQmedium

Which of the following describes the primary goal of using a 'Honeytoken' in an environment to mitigate malicious code and insider threats?

A.To automatically patch vulnerabilities in real-time.
B.To serve as a decoy for detecting unauthorized access.
C.To encrypt sensitive data for long-term storage.
D.To provide a secure sandbox for testing malware.
AnswerB

The purpose of a honeytoken is to act as a detection mechanism. By creating a resource that serves no business purpose, any interaction with it serves as a clear indicator of malicious intent, allowing security teams to respond immediately to threats that have evaded other detection controls.

Why this answer

Honeytokens are fake credentials, files, or data entries planted in a system to act as a tripwire. Because no legitimate user or process should ever access these items, any attempt to use or read them provides a high-fidelity alert of malicious activity. This strategy is highly effective for detecting lateral movement, data exfiltration attempts, or credential harvesting by malware that is already inside the perimeter and searching for targets.

Exam trap

Candidates often mistake honeytokens for 'prevention' tools. They are strictly detection mechanisms; they do not block or stop an attacker from accessing the actual system.

2
Multi-Selectmedium

Which THREE of the following are primary defensive strategies to mitigate the risk of 'Living off the Land' (LotL) attacks?

Select 3 answers
A.Restrict access to administrative tools via Constrained Language Mode.
B.Increase the frequency of system reboots.
C.Enable granular command-line auditing and logging.
D.Implement Principle of Least Privilege for administrative accounts.
E.Disable all network logging to save disk space.
AnswersA, C, D

Constrained Language Mode (CLM) in PowerShell limits the access to sensitive .NET types and commands, making it harder for attackers to use the shell for malicious purposes. This restricts the power of the tool, ensuring that attackers cannot easily perform advanced memory-based operations or API calls.

Why this answer

LotL attacks use legitimate system tools (e.g., PowerShell, WMI, PsExec) for malicious purposes to avoid detection. Mitigation requires strict monitoring and restriction of these powerful utilities. By reducing the attack surface via restrictive policies, logging their usage, and implementing least-privilege principles, organizations can detect the abuse of these tools by an adversary, as their usage patterns will deviate significantly from the baseline behavior of legitimate system administrators and automated system management processes.

Exam trap

Candidates often suggest blocking all PowerShell access. This is rarely feasible in enterprise environments, which would break legitimate administrative automation and system management tasks.

3
MCQhard

A security analyst is concerned about Fileless Malware attacks. Which technique is most effective for detecting code that resides only in memory without writing files to the disk?

A.Deploying a traditional antivirus signature update.
B.Enabling PowerShell Script Block Logging.
C.Scanning the hard drive for unauthorized startup files.
D.Performing integrity checks on system binaries.
AnswerB

PowerShell Script Block Logging records the full content of code executed by the PowerShell engine. Since fileless malware frequently uses obfuscated PowerShell scripts for execution, this logging mechanism captures the de-obfuscated commands in memory, allowing for detection of malicious activity that never touches the disk.

Why this answer

Fileless malware often uses legitimate tools like PowerShell or WMI to execute code in memory. To detect this, analysts must shift from file-based scanning to process-based monitoring. Logging PowerShell Script Block Logging (Event ID 4104) and capturing command-line arguments are essential.

These logs provide visibility into the actual code being executed in memory, which is the only way to catch threats that bypass traditional signature-based disk scanners by living off the land.

Exam trap

Candidates often choose 'disk forensic imaging'. This is useless for fileless malware because the malicious code resides in RAM and never touches the physical hard drive storage.

4
MCQmedium

A security analyst is reviewing an incident where a user's browser was exploited by a drive-by download. The analyst wants to confirm whether the exploit achieved code execution and established persistence. Which artifact should the analyst examine first to determine if a new service was created for persistence on the Windows host?

A.The Application event log for Windows Error Reporting crash entries.
B.The browser's cache folder for recently downloaded JavaScript files.
C.The Windows Security event log for event ID 4688 process creation.
D.The System event log for event ID 7045 Service Control Manager entries.
AnswerD

Event ID 7045 in the System log is written by the Service Control Manager when a new service is installed, and it records the service name, image path, service type, and start type. This directly answers whether a new service was created for persistence. It is generated by default on modern Windows systems, requires no pre-enabled auditing, and provides the exact evidence needed to confirm service installation after a drive-by exploit.

Why this answer

The System event log entry with ID 7045 is generated by the Service Control Manager whenever a new service is installed on Windows. It captures the service name, binary path, start type, and account, which lets the analyst confirm both installation and the persistence mechanism. Unlike process creation auditing, 7045 is enabled by default and directly answers whether a service was created, making it the correct first artifact to examine.

Exam trap

The trap here is confusing process creation telemetry with service installation telemetry; event ID 4688 shows that a process ran, while event ID 7045 proves a service was actually installed.

5
MCQeasy

A small business owner is concerned about ransomware encrypting critical files on a shared network drive. The owner wants a solution that can restore files quickly after an attack without paying the ransom. Which of the following is the MOST effective control to achieve this?

A.Deploy antivirus software with real-time scanning on all endpoints.
B.Implement a regular backup strategy that includes offline and offsite copies.
C.Configure the network drive to be read-only for all users.
D.Enable file versioning on the shared network drive.
AnswerB

Regular backups that are kept offline and offsite ensure that even if ransomware encrypts the network drive, a clean copy of the data exists and can be restored. This is the most reliable way to recover from ransomware without paying. It directly addresses the need to restore files quickly and effectively.

Why this answer

A robust backup strategy with offline and offsite copies is the most effective way to recover from ransomware. It ensures that a clean copy of data is available regardless of the attack's success. While other controls can help prevent or limit damage, only backups provide a reliable restoration path without paying the ransom.

Exam trap

The trap here is assuming that antivirus or file versioning alone can guarantee recovery, when in fact ransomware often targets or encrypts those very mechanisms, making offline backups essential.

6
MCQmedium

An administrator identifies a suspicious process masquerading as a system service. To mitigate the risk while maintaining evidence, which action is the most appropriate first step in a professional incident response lifecycle?

A.Immediately terminate the process using the task manager.
B.Perform a full system backup to an external network share.
C.Isolate the infected host from the network via switch port shutdown.
D.Run a full scan with the local antivirus engine.
AnswerC

Network isolation successfully severs the communication channel between the malware and the attacker's command-and-control server. This containment step halts data exfiltration and remote command execution while leaving the host powered on, allowing for the secure collection of volatile memory and disk images for post-incident forensic investigation.

Why this answer

Isolating the host from the network preserves the integrity of the volatile memory and prevents command-and-control communication. In security operations, containment precedes deep analysis to ensure the adversary cannot execute further malicious actions or delete artifacts. This approach balances the need for forensic readiness with the urgent requirement to stop ongoing lateral movement or data exfiltration, adhering to standard GIAC incident response methodologies regarding host-based threat containment.

Exam trap

Candidates often suggest 'rebooting the host' or 'running a virus scan'. These actions wipe volatile memory, destroying critical forensic evidence before the incident responder can analyze the threat.

7
MCQeasy

Which security control is most effective at preventing the execution of unauthorized or malicious software by enforcing a 'deny-by-default' policy on a workstation?

A.Endpoint Detection and Response (EDR) agents.
B.Next-Generation Antivirus (NGAV) with behavioral analysis.
C.Application Whitelisting (e.g., AppLocker or WDAC).
D.Host-based Intrusion Prevention System (HIPS).
AnswerC

Application whitelisting explicitly restricts execution to only approved binaries, scripts, and installers. By implementing a default-deny policy, it ensures that any unauthorized or malicious software—regardless of whether it is known to security vendors—will be blocked from executing on the host, providing a robust security posture.

Why this answer

Application whitelisting (or Application Control) prevents any program from running unless it is explicitly permitted by a defined policy. This is vastly superior to blacklisting, which can only block known threats. In a professional environment, this controls the execution environment, significantly reducing the attack surface by ensuring that only vetted and approved binaries, scripts, and installers can run, effectively mitigating zero-day threats and unauthorized utility usage.

Exam trap

Candidates often choose 'Antivirus' or 'Endpoint Detection and Response (EDR)' because they are common tools, forgetting that these are often signature-based and do not inherently implement a strict 'deny-by-default' execution policy.

8
MCQhard

A penetration tester is assessing a web application and finds that user input is reflected into an HTML page without encoding. The tester wants to demonstrate that an attacker could steal a victim's session cookie by injecting a script that sends the cookie to an external server. Which mitigation, when implemented by the developers, most directly prevents this specific cookie theft even if the input reflection remains?

A.Set the session cookie with the HttpOnly attribute.
B.Add the Secure attribute to the session cookie.
C.Enable Content Security Policy with a strict script-src directive.
D.Implement output encoding for all user-supplied data.
AnswerA

The HttpOnly attribute prevents client-side scripts from accessing the cookie through document.cookie, so even a successful reflected script injection cannot read and exfiltrate the session cookie. This directly neutralizes the described theft technique while leaving the reflection bug in place. It is a targeted, server-side cookie attribute that requires no changes to input handling and is the most direct mitigation for script-based session cookie theft.

Why this answer

The HttpOnly attribute makes the session cookie inaccessible to client-side scripts, so a reflected script injection cannot read or exfiltrate it. This directly counters the described attack even though the reflection vulnerability remains. While output encoding would fix the root cause and a strict Content Security Policy would reduce script execution, the question asks for the most direct prevention of cookie theft given the reflection, and HttpOnly is that control.

Exam trap

The trap here is choosing the root-cause fix (output encoding) when the question explicitly asks for the control that protects the cookie even if the reflection remains.

9
MCQeasy

A medium-sized company's Windows workstations are being infected by malicious macro documents delivered as .docm email attachments. Employees routinely open these attachments because the macros appear to come from a trusted internal sender. The security team wants to stop the macro execution with the least disruption to legitimate business macros, which are used only by the finance department. Which mitigation should the team implement first?

A.Enable Microsoft Defender Application Guard for Office to open untrusted documents in an isolated container.
B.Configure an email gateway rule to strip all .docm attachments and quarantine them for administrator review.
C.Use Group Policy to set the Microsoft Office macro notification setting to 'Disable all macros except digitally signed macros' and distribute a trusted publisher certificate to finance.
D.Deploy an endpoint detection and response agent and create a detection rule that alerts when WINWORD.EXE spawns a child process.
AnswerC

This policy blocks unsigned macros for all users while permitting finance's signed macros, directly addressing the infection vector with minimal business impact. Trusted publisher certificates let finance macros run without prompts, and all other unsigned macros are silently blocked. This is the standard Group Policy control for exactly this scenario and does not require third-party tooling or network changes, making it the correct first step.

Why this answer

The correct control is a Group Policy macro setting that disables unsigned macros while allowing digitally signed macros, with a trusted publisher certificate deployed to finance. This blocks the malicious macro execution path for nearly all users, preserves the legitimate finance macros, and requires no changes to email flow or third-party tools. It is the least disruptive, targeted mitigation for macro-borne malware in a Windows Office environment.

Exam trap

The trap here is assuming that email attachment filtering alone solves macro malware, when the execution decision actually happens inside the Office application and must be controlled by macro policy.

10
Multi-Selecthard

A security team is hardening a fleet of Windows 10 workstations against exploit techniques used by malicious code. The team wants to enable operating system features that make it harder for an attacker to execute arbitrary code in memory and to bypass address space randomization. Which two features should the team enable? (Choose two.)

Select 2 answers
A.Address Space Layout Randomization (ASLR) with system-wide mandatory enforcement.
B.Control Flow Guard (CFG) configured only for applications that opt in.
C.Structured Exception Handling Overwrite Protection (SEHOP) in audit-only mode.
D.Data Execution Prevention (DEP) in opt-out mode.
E.Windows Defender Application Control (WDAC) in audit mode.
AnswersA, D

ASLR randomizes the base addresses of executable images, DLLs, the stack, and the heap, which makes it difficult for an attacker to reliably predict where code or gadgets reside. Enforcing ASLR system-wide through Windows Defender Exploit Guard's mandatory ASLR setting ensures that even applications not compiled with ASLR support are randomized, increasing the difficulty of exploitation. This is the second correct hardening feature for the scenario.

Why this answer

Data Execution Prevention and system-wide mandatory Address Space Layout Randomization are the two operating system features that directly raise the bar for memory-corruption exploits. DEP prevents execution of code from data pages, defeating simple shellcode placement, while mandatory ASLR randomizes memory layout so attackers cannot rely on fixed addresses. Together they force attackers to find information leaks or other bypasses, which is the intended hardening posture for the workstation fleet.

Exam trap

The trap here is selecting real mitigations that are configured in audit or opt-in mode, which log or partially apply the protection instead of fully enforcing it.

11
MCQmedium

A Windows workstation in the finance department suddenly starts launching PowerShell with an encoded command line shortly after a user opens a malicious Excel attachment. The endpoint has Microsoft Defender Antivirus enabled, but no PowerShell logging or script block logging is configured. Which action best mitigates this class of malicious code execution while preserving the ability to investigate the encoded payload?

A.Configure AppLocker default rules to allow only administrators to run PowerShell scripts in the environment.
B.Disable the Windows Script Host on all workstations by setting the Enabled registry value under WSH settings to 0.
C.Add the finance department's subnet to the Microsoft Defender Antivirus network inspection exclusion list.
D.Enable PowerShell script block logging and module logging through Group Policy, then collect the events in Windows Event Forwarding for analysis.
AnswerD

Script block logging records the de-obfuscated script content that PowerShell actually executes, even when the command line is Base64-encoded, and module logging captures pipeline execution details. Forwarding those events to a central collector preserves the decoded payload for investigation while giving defenders visibility into the malicious behavior, directly mitigating this encoded PowerShell execution scenario.

Why this answer

Encoded PowerShell commands hide the real script from casual command-line inspection, so the effective mitigation is to force PowerShell to log the de-obfuscated script blocks and module activity. Centralizing those events through Windows Event Forwarding lets analysts review the decoded payload and build detections, addressing both mitigation and evidence preservation without breaking legitimate administration.

Exam trap

The trap here is assuming that disabling a scripting host or restricting script files stops all PowerShell abuse, when encoded commands can execute without any script file on disk.

12
MCQhard

A security analyst is reviewing a suspicious Windows 10 workstation. The analyst finds that a user-level process named 'notepad.exe' has spawned a child process named 'cmd.exe', which then created a scheduled task named 'MicrosoftEdgeUpdateTaskMachineUA' that runs a PowerShell script from the user's AppData folder. The analyst suspects a fileless malware infection. Which of the following techniques is the malware MOST likely using to maintain persistence?

A.Scheduled task created via schtasks.exe
B.Service creation using sc.exe
C.Registry Run key modification
D.Windows Management Instrumentation (WMI) event subscription
AnswerA

The analyst observed that cmd.exe created a scheduled task named 'MicrosoftEdgeUpdateTaskMachineUA' that runs a PowerShell script from AppData. This is a classic persistence technique using the Windows Task Scheduler, often executed via schtasks.exe or the Task Scheduler COM API. The task masquerades as a legitimate Microsoft Edge update task to avoid suspicion, confirming scheduled task persistence.

Why this answer

The malware established persistence by creating a scheduled task that masquerades as a legitimate Microsoft Edge update task. This technique allows the malicious PowerShell script to run at logon or on a schedule. The task name mimics a trusted component to evade detection.

The other options are valid persistence methods but do not align with the observed artifact of a scheduled task created by cmd.exe.

Exam trap

The trap here is assuming that any suspicious child process of notepad.exe indicates a specific persistence method like WMI or registry keys, when the scenario explicitly points to a scheduled task.

13
MCQhard

A security engineer is hardening a fleet of Windows servers that run a legacy business application. The application vendor requires that the servers retain the ability to run unsigned macros for compatibility. Which mitigation strategy best reduces the risk of malicious macro-based code execution while maintaining the application's required functionality?

A.Enable Microsoft Defender Application Guard for Office and open all macro-enabled documents in the isolated container.
B.Add all internal file servers to the Trusted Locations list so macros in documents from those locations run without security prompts.
C.Set the Trust Center macro notification setting to Disable all macros without notification for all Office applications on the servers.
D.Implement Attack Surface Reduction rules that block Office applications from creating child processes and from injecting code into other processes.
AnswerD

ASR rules such as blocking Office child process creation and process injection target the behaviors that macro-based malware relies on, regardless of whether the macro itself is signed. This preserves the ability to run the required unsigned macros while preventing the most common payload delivery and execution techniques, directly matching the scenario's need to reduce malicious macro risk without breaking functionality.

Why this answer

Because the vendor insists on unsigned macros, the control must target what macros do after they run rather than whether they are trusted. Attack Surface Reduction rules that block Office child process creation and process injection stop the common execution chain used by macro malware while leaving legitimate macro logic intact, achieving the required balance between compatibility and risk reduction.

Exam trap

The trap here is treating macro execution itself as the only thing to block, when the stronger mitigation for mandatory unsigned macros is to constrain the post-exploitation behaviors they enable.

14
MCQhard

A penetration tester is examining a Windows 10 system and discovers that a recent exploit leveraged a use-after-free vulnerability in a widely used PDF reader application. The exploit successfully achieved code execution. Which of the following mitigation technologies, when enabled, would have made this exploitation significantly more difficult by randomizing the memory locations of key data structures?

A.Address Space Layout Randomization (ASLR)
B.Control Flow Guard (CFG)
C.Data Execution Prevention (DEP)
D.Structured Exception Handling Overwrite Protection (SEHOP)
AnswerA

ASLR randomizes the base addresses of executable modules, stack, and heap, making it difficult for an attacker to predict where to place or find their payload. For a use-after-free, the attacker often needs to know the address of a freed object or a function pointer to overwrite; ASLR forces them to leak addresses first, increasing complexity and reducing reliability.

Why this answer

ASLR is the mitigation that randomizes memory addresses, making it harder for an attacker to predict where to find or place code and data. In a use-after-free scenario, the attacker often needs to control the contents of a freed object and then trigger its reuse; ASLR forces the attacker to first leak a memory address to bypass randomization, adding a significant hurdle. DEP, CFG, and SEHOP address different exploitation techniques and do not provide the same randomization benefit.

Exam trap

The trap here is confusing exploit mitigations: DEP prevents execution from data pages, CFG validates indirect calls, and SEHOP protects exception handlers, but only ASLR randomizes memory layout to hinder address prediction.

15
MCQmedium

A Linux web server was compromised through a vulnerable PHP application. The attacker uploaded a web shell and is now using it to run commands. An incident responder needs to determine how the attacker is maintaining access after reboots. Which artifact should the responder check first to identify a persistent mechanism on this Linux host?

A.The crontab entries for all users and the /etc/cron.* directories.
B.The /etc/passwd file for accounts with UID 0.
C.The Apache access log for POST requests to the vulnerable PHP script.
D.The /var/log/auth.log file for failed SSH login attempts.
AnswerA

Scheduled tasks are one of the most common Linux persistence mechanisms, and checking every user's crontab plus the system cron directories reveals jobs that re-establish access or re-download payloads at regular intervals. Because cron survives reboots, it directly answers how the attacker maintains access. Root crontabs and files under /etc/cron.d, /etc/cron.hourly, and related directories are the highest-value locations to inspect first.

Why this answer

On Linux, cron jobs are a primary persistence mechanism because they run on a schedule and survive reboots. An attacker with web shell access often adds a crontab entry or a file in /etc/cron.d that re-downloads a payload or opens a reverse shell. Checking all user crontabs and the system cron directories is therefore the most direct first step to identify how access is maintained, ahead of logs that only show activity rather than configuration.

Exam trap

The trap here is focusing on logs that prove the intrusion occurred instead of configuration artifacts that explain how access persists after a restart.

16
MCQmedium

A security analyst at a financial firm discovers that a user's workstation is executing a malicious macro embedded in a Microsoft Word document. The macro is attempting to download a second-stage payload from a remote server. The analyst wants to prevent this specific type of attack from succeeding on other workstations while allowing legitimate macros to run. Which of the following is the MOST effective mitigation?

A.Disable all macros without notification in the Trust Center settings for all Office applications.
B.Deploy a web proxy that blocks all outbound traffic to unknown domains to prevent payload download.
C.Implement an application whitelist that only allows signed Microsoft Office executables to run.
D.Enable Microsoft Office's 'Block macros from running in Office files from the Internet' policy via Group Policy.
AnswerD

This policy, available in Office 2016 and later, blocks macros in files that originate from the Internet (e.g., downloaded from email or web). It directly addresses the scenario where a user opens a malicious document from an external source, while still allowing macros in trusted internal files. It is a targeted, effective control that does not require disabling macros entirely.

Why this answer

The 'Block macros from running in Office files from the Internet' policy is specifically designed to mitigate macro-based malware delivered via email or web downloads. It uses Mark-of-the-Web to identify files from untrusted sources and blocks macro execution while allowing macros in trusted local files. This balances security with usability, making it the most effective targeted mitigation for the described attack.

Exam trap

The trap here is assuming that disabling all macros is the only way to stop macro malware, overlooking the more granular 'Block macros from the Internet' policy that preserves legitimate macro functionality.

Ready to test yourself?

Try a timed practice session using only Malicious Code and Exploit Mitigation questions.