312-50 exam dumps

312-50 practice question 175 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 175

Single answer▪ Malware Countermeasures

A security analyst discovers that several Windows workstations are making periodic outbound HTTPS connections to an unfamiliar domain, even when no users are logged in. Endpoint logs show a suspicious executable in a user's AppData\Roaming folder and a matching Run registry key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run. The analyst needs to contain the malware quickly while preserving evidence for later analysis. What is the MOST appropriate first action?

  1. A

    Immediately delete the executable, remove the Run key, and reboot the affected systems to stop the traffic

  2. B

    Disconnect the affected hosts from the network or place them in a quarantine VLAN, then capture volatile evidence before eradication

  3. C

    Run a full disk defragmentation and chkdsk operation to repair any malware-related filesystem corruption before collecting evidence

  4. D

    Disable Windows event logging to reduce system activity and prevent the malware from hiding in new log entries

Show answer and explanation

Correct answer: B

Explanation

In malware countermeasures, the preferred sequence is typically identification, containment, evidence collection, eradication, recovery, and lessons learned. In this scenario, the active outbound HTTPS beaconing and clear persistence mechanism indicate a likely ongoing compromise. The most appropriate first step is to isolate the affected systems from the network or move them into a controlled quarantine segment, which limits command-and-control communication and potential lateral movement while preserving the running state for analysis. After containment, volatile data should be collected before deleting files, changing registry keys, or rebooting. This aligns with widely accepted incident response guidance, including NIST SP 800-61 Computer Security Incident Handling Guide, which emphasizes containment strategies and preservation of evidence, and with common forensic best practices for malware investigations on live systems.

  • A. Incorrect.

    This is not the best first action. Although deleting the executable and removing the persistence key may interrupt the malware, it destroys useful evidence and can alert or alter the malware before investigators collect volatile data such as active network connections, running processes, memory-resident payloads, and command-and-control indicators. Rebooting also clears many volatile artifacts. A common mistake is jumping directly to eradication before containment and evidence preservation.

  • B. Correct.

    This is the best answer. Standard incident response and malware countermeasure practice is to contain the affected hosts first so the malware cannot continue beaconing, spreading, or exfiltrating data. Network isolation or quarantine VLAN placement limits damage while keeping the system powered on. After containment, the analyst should collect volatile evidence such as RAM contents, active processes, network sessions, logged-in users, scheduled tasks, and relevant registry persistence artifacts before moving to eradication. This approach balances rapid containment with forensic preservation.

  • C. Incorrect.

    This is incorrect. Disk defragmentation and chkdsk are not malware countermeasures and can change filesystem metadata, overwrite forensic artifacts, and complicate later analysis. They do nothing to address active command-and-control traffic or persistence. This option reflects a misconception that system repair utilities are an appropriate response to suspected malware infection.

  • D. Incorrect.

    This is incorrect and counterproductive. Event logs are valuable evidence during malware investigations, helping analysts identify execution, persistence, privilege use, process creation, and network-related activity. Disabling logging reduces visibility and may violate incident handling best practices. It also does not meaningfully stop the malware.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam