312-50 exam dumps

312-50 practice question 176 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 176

Single answer▪ Malware Countermeasures

A security analyst discovers that several Windows workstations are making periodic outbound HTTPS connections to domains with newly registered names. Endpoint alerts also show a suspicious process injecting code into explorer.exe and creating a Run registry key for persistence. The organization wants to contain the threat quickly while preserving evidence for later analysis. Which action should the analyst take FIRST as the most appropriate malware countermeasure?

  1. A

    Immediately run an aggressive anti-malware scan that deletes all detected files and registry entries

  2. B

    Isolate the affected hosts from the network while keeping them powered on, then collect volatile evidence

  3. C

    Reboot the affected systems into safe mode and uninstall recently added software

  4. D

    Block all outbound HTTPS traffic at the perimeter firewall for the entire organization

Show answer and explanation

Correct answer: B

Explanation

The best initial malware countermeasure in this scenario is targeted containment: isolate the suspected endpoints from the network while preserving the system state for investigation. The indicators described, outbound beaconing to suspicious domains, process injection into explorer.exe, and Run key persistence, strongly suggest active malware with command-and-control and persistence capabilities. Standard incident response guidance emphasizes containment before eradication, and preservation of volatile evidence before shutdown or reboot. This approach is consistent with widely accepted practices such as the NIST Computer Security Incident Handling Guide (SP 800-61), which prioritizes containment and evidence handling, and NIST guidance on malware incident prevention and handling, which recommends collecting volatile data when feasible before making changes to the system. After isolation and evidence collection, the analyst can proceed with scoping, blocking indicators, eradication, and recovery in a controlled manner.

  • A. Incorrect.

    This is not the best first step. Although anti-malware scanning may help eradicate malware, immediately deleting artifacts can destroy forensic evidence, alter timestamps, remove persistence mechanisms that need to be documented, and interfere with understanding the full scope of compromise. In incident response, containment and evidence preservation come before broad eradication actions.

  • B. Correct.

    This is correct. Isolating the affected hosts contains command-and-control communication and limits lateral movement, while keeping them powered on preserves volatile data such as running processes, injected code, network connections, and memory-resident malware. Collecting volatile evidence first aligns with established incident response practice because memory and live connection data are lost if the system is shut down or rebooted.

  • C. Incorrect.

    This is incorrect as a first action. Rebooting can destroy valuable volatile evidence, terminate malicious processes before they are analyzed, and trigger malware cleanup or anti-forensic behavior. Safe mode may also prevent some malware from loading, which is useful later for remediation, but it is not the preferred initial countermeasure when evidence must be preserved.

  • D. Incorrect.

    This is too broad and not the most appropriate first response. While outbound filtering can be part of containment, blocking all HTTPS traffic would significantly disrupt business operations and still may not fully contain the malware if it uses other protocols or internal lateral movement. Targeted host isolation is a faster and more precise countermeasure.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam