(3) Malicious processes, malware and software that is not authorized Flashcards

1
Q

What important methods are normally involved in detecting malware, bad processes and not authorized software?

A

These major processes and tools are important in the detection of malware, bad processes and bad software:

-Central Management tools like Microsoft Endpoint Manager

-Antivirus and Antimalware tools

-Endpoint detection and response (EDR)

-Software and file block listing

-Application allow listing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

In terms of useful tools for detecting bad processes, software and malware, what is important to remember about Microsoft Endpoint Manager?

A

Microsoft Endpoint manager does manager software installation and report on it, but it doesn’t run in real time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

In terms of useful tools for detecting bad processes, software and malware, describe software and file block listing

A

In terms of useful tools for detecting bad processes, software and malware, software and file block listing uses a list of prohibited software and files and stops it from being installed.

This is a bit more inclusive than anti-virus and anti-malware as it includes non malicious programs and files

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

In terms of useful tools for detecting bad processes, software and malware, describe application allow listing

A

In terms of useful tools for detecting bad processes, software and malware, application allow listing only enables specifically allowed files and apps on a computer.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly