200-201 Question 185
Single answerA cybersecurity analyst is investigating a suspected malware infection on a workstation. The analyst notices that the host-based firewall on the workstation has been disabled, but there are no administrative records of this action. What is the most likely reason the host-based firewall was disabled?
- A
A legitimate system update required the firewall to be temporarily disabled.
- B
The malware disabled the host-based firewall to allow unrestricted access to the system.
- C
The user manually disabled the firewall to troubleshoot a network issue.
- D
The firewall was disabled by the organization's IT policy for compliance reasons.
Show answer and explanation
Correct answer: B
Explanation
Malware commonly disables host-based firewalls as part of its strategy to compromise system security. Doing so allows the malware to communicate with command-and-control servers or spread laterally without being blocked by the firewall. In this scenario, the absence of administrative records and the suspicious nature of the system activity strongly indicate that malware is the cause of the disabled firewall.
- A. Incorrect.
Legitimate system updates do not typically require the firewall to be disabled. Such updates are designed to work without compromising system security.
- B. Correct.
Malware often disables host-based firewalls to bypass network restrictions and allow malicious traffic to enter or leave the system without detection. This is the most likely scenario in this case.
- C. Incorrect.
While users may sometimes disable firewalls for troubleshooting, this scenario involves no evidence suggesting user intervention or administrative approval.
- D. Incorrect.
Disabling firewalls for compliance reasons is highly unusual and counterproductive to security. IT policies typically strengthen security rather than weaken it.