Blocking Malware and Other Attacks Flashcards
What 4 common security controls can protect against malware?
1) spam filter on mail gateway
2) anti-malware on mail gateway
3) hosts/server anti-malware
4) boundary security devices - firewalls or UTMs
What must admins be aware to do when downloading and installing signature files manually?
they should compare the hash of signature file on the anti-virus site with the hash of the downloaded file
How does heuristic-based analysis detect polymorphic malware?
by checking for variations in copies of applications
what malware protection mechanism prevents malware from executing code in certain regions of memory? Where would you enable it?
Data Execution Prevention
Enabled in the BIOS or UEFI (the newer replacement of the BIOS)
In a well setup network, on what devices would find spam filters?
1) on UTMs
2) On email gateways
3) On user’s email clients
All 3 together!