SECFND 12: Endpoint Security Technologies Flashcards
1
Q
Address on whitelist and blacklist. Which wins?
A
Whitelist
2
Q
Whitelisted/blacklisted apps can be identified by…
A
hash value, certificate
3
Q
Whitelisting flaw
A
Apps that run in memory
4
Q
AV File trajectory
A
Hosts where files were seen
5
Q
AV Device trajectory
A
Actions that files performed on a given host
6
Q
Packed malware
A
Compressed to make it polymorphic