312-50 exam dumps

312-50 practice question 163 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 163

Single answer▪ Trojan Concepts

During an internal security assessment, a Windows workstation begins making repeated outbound connections to an unfamiliar Internet host over TCP 4444 shortly after a user opens what appeared to be a PDF attachment. The security team finds no scheduled administrative software using that port, and the process responsible is a hidden executable launched from the user's profile directory. Based on common Trojan behavior, which action would be the MOST appropriate first containment step for the ethical hacker to recommend while preserving evidence for investigation?

  1. A

    Immediately isolate the workstation from the network to stop possible command-and-control traffic, then capture volatile evidence before full remediation

  2. B

    Delete the suspicious executable from the user's profile directory and reboot the workstation to see whether the problem returns

  3. C

    Leave the workstation online and run a vulnerability scan against it to determine whether TCP 4444 is officially assigned to malware

  4. D

    Uninstall the user's PDF reader because Trojans can only execute through vulnerable document viewers

Show answer and explanation

Correct answer: A

Explanation

This scenario describes classic Trojan behavior: a user is tricked into executing a malicious payload, which then creates outbound communications to an external host and may provide backdoor access. In CEH contexts, candidates should recognize that Trojans often depend on user execution and then attempt persistence, remote control, credential theft, or payload delivery. The most appropriate first response is containment of the affected system, typically by network isolation, followed by preservation of volatile evidence such as memory, process information, and active connections before eradication steps begin. This approach is consistent with incident response best practices in NIST SP 800-61 Computer Security Incident Handling Guide. The question also tests an important Trojan concept: deleting an obvious file or focusing on the apparent delivery application is insufficient because Trojans may establish persistence in multiple places and can remain active in memory or through secondary components.

  • A. Correct.

    Correct. A Trojan commonly establishes outbound command-and-control communication or opens a backdoor after user execution. In a suspected active compromise, the best initial containment action is to isolate the host from the network to prevent further attacker interaction, lateral movement, or data exfiltration. At the same time, evidence preservation matters: memory contents, active network connections, running processes, and logged-on sessions can be lost if the system is immediately rebooted or altered. This aligns with standard incident handling practice from sources such as NIST SP 800-61, which emphasizes containment and evidence preservation.

  • B. Incorrect.

    Incorrect. Deleting the file first can destroy important evidence and may not remove persistence mechanisms, secondary payloads, registry run keys, scheduled tasks, or injected processes associated with the Trojan. Rebooting can also erase volatile artifacts such as active connections and in-memory malware components. This is a common mistake when responders focus on cleanup before containment and forensic preservation.

  • C. Incorrect.

    Incorrect. Leaving a potentially Trojan-infected host online unnecessarily allows continued command-and-control communication. Also, a vulnerability scan is not the right first step for an active suspected malware infection. TCP 4444 is often seen in malware and backdoor contexts, but port association alone is not a reliable basis for investigative decisions. The priority should be containment and evidence collection, not scanning the compromised endpoint while it remains exposed.

  • D. Incorrect.

    Incorrect. Trojans are not limited to exploiting PDF readers, and many rely on social engineering rather than a software vulnerability. A user may execute a disguised payload that only appears to be a document, or a malicious attachment may drop another executable. Removing the PDF reader does not address the active compromise, persistence, or outbound communications. This option reflects the misconception that the delivery mechanism and the Trojan itself are the same issue.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam