401 SEC+ Exam: Guaranteed Pass with Expert
Solutions & Diverse Question Bank for Top
Academic Performance
Ann, a software developer, has installed some code to reactivate her account one week
after her account has been disabled. Which of the following is this an example of? (Select
TWO).
A. Rootkit
B. Logic Bomb
C. Botnet
D. Backdoor
E. Spyware - -correct ans- -Answer: B,D
Explanation:
This is an example of both a logic bomb and a backdoor. The logic bomb is configured to 'go
off' or activate one week after her account has been disabled. The reactivated account will
provide a backdoor into the system.
A logic bomb is a piece of code intentionally inserted into a software system that will set off
a malicious function when specified conditions are met. For example, a programmer may
hide a piece of code that starts deleting files should they ever be terminated from the
company.
Software that is inherently malicious, such as viruses and worms, often contain logic
bombs that execute a certain payload at a pre-defined time or when some other condition
is met. This technique can be used by a virus or worm to gain momentum and spread
before being noticed. Some viruses attack their host systems on specific dates, such as
Friday the 13th or April Fool's Day. Trojans that activate on certain dates are often called
"time bombs".
To be considered a logic bomb, the payload should be unwanted and unknown to the user
of the software. As an example, trial programs with code that disables certain functionality
after a set time are not normally regarded as logic bombs.
,A backdoor in a computer system (or cryptosystem or algorithm) is a method of bypassing
normal authentication, securing unauthorized remote access to a computer, obtaining
access to plaintext, and so on, while attempting to remain undetected. The backdoor may
take the form of an installed program (e.g., Back Orifice) or may subvert the system through
a rootkit.
A backdoor in a login system might take the form of a hard coded user and password
combination which gives access to the system.
Which of the following malware types is MOST likely to execute its payload after Jane, an
employee, has left the company?
A. Rootkit
B. Logic bomb
C. Worm
D. Botnet - -correct ans- -Answer: B
Explanation:
This is an example of a logic bomb. The logic bomb is configured to 'go off' or when Jane has
left the company.
A logic bomb is a piece of code intentionally inserted into a software system that will set off
a malicious function when specified conditions are met. For example, a programmer may
hide a piece of code that starts deleting files should they ever be terminated from the
company.
Software that is inherently malicious, such as viruses and worms, often contain logic
bombs that execute a certain payload at a pre-defined time or when some other condition
is met. This technique can be used by a virus or worm to gain momentum and spread
before being noticed. Some viruses attack their host systems on specific dates, such as
Friday the 13th or April Fool's Day. Trojans that activate on certain dates are often called
"time bombs".
To be considered a logic bomb, the payload should be unwanted and unknown to the user
of the software. As an example, trial programs with code that disables certain functionality
after a set time are not normally regarded as logic bombs.
, Pete, a security analyst, has been tasked with explaining the different types of malware to
his colleagues. The two malware types that the group seems to be most interested in are
botnets and viruses. Which of the following explains the difference between these two
types of malware?
A. Viruses are a subset of botnets which are used as part of SYN attacks.
B. Botnets are a subset of malware which are used as part of DDoS attacks.
C. Viruses are a class of malware which create hidden openings within an OS.
D. Botnets are used within DR to ensure network uptime and viruses are not. - -correct ans-
-Answer: B
Explanation:
A botnet is a collection of Internet-connected programs communicating with other similar
programs in order to perform tasks. This can be as mundane as keeping control of an
Internet Relay Chat (IRC) channel, or it could be used to send spam email or participate in
distributed denial-of-service attacks. The word botnet is a combination of the words robot
and network. The term is usually used with a negative or malicious connotation.
Computers can be co-opted into a botnet when they execute malicious software. This can
be accomplished by luring users into making a drive-by download, exploiting web browser
vulnerabilities, or by tricking the user into running a Trojan horse program, which may come
from an email attachment. This malware will typically install modules that allow the
computer to be commanded and controlled by the botnet's operator. Many computer users
are unaware that their computer is infected with bots. Depending on how it is written, a
Trojan may then delete itself, or may remain present to update and maintain the modules.
A user, Ann, is reporting to the company IT support group that her workstation screen is
blank other than a window with a message requesting payment or else her hard drive will
be formatted. Which of the following types of malware is on Ann's workstation?
A. Trojan
B. Spyware
C. Adware
Solutions & Diverse Question Bank for Top
Academic Performance
Ann, a software developer, has installed some code to reactivate her account one week
after her account has been disabled. Which of the following is this an example of? (Select
TWO).
A. Rootkit
B. Logic Bomb
C. Botnet
D. Backdoor
E. Spyware - -correct ans- -Answer: B,D
Explanation:
This is an example of both a logic bomb and a backdoor. The logic bomb is configured to 'go
off' or activate one week after her account has been disabled. The reactivated account will
provide a backdoor into the system.
A logic bomb is a piece of code intentionally inserted into a software system that will set off
a malicious function when specified conditions are met. For example, a programmer may
hide a piece of code that starts deleting files should they ever be terminated from the
company.
Software that is inherently malicious, such as viruses and worms, often contain logic
bombs that execute a certain payload at a pre-defined time or when some other condition
is met. This technique can be used by a virus or worm to gain momentum and spread
before being noticed. Some viruses attack their host systems on specific dates, such as
Friday the 13th or April Fool's Day. Trojans that activate on certain dates are often called
"time bombs".
To be considered a logic bomb, the payload should be unwanted and unknown to the user
of the software. As an example, trial programs with code that disables certain functionality
after a set time are not normally regarded as logic bombs.
,A backdoor in a computer system (or cryptosystem or algorithm) is a method of bypassing
normal authentication, securing unauthorized remote access to a computer, obtaining
access to plaintext, and so on, while attempting to remain undetected. The backdoor may
take the form of an installed program (e.g., Back Orifice) or may subvert the system through
a rootkit.
A backdoor in a login system might take the form of a hard coded user and password
combination which gives access to the system.
Which of the following malware types is MOST likely to execute its payload after Jane, an
employee, has left the company?
A. Rootkit
B. Logic bomb
C. Worm
D. Botnet - -correct ans- -Answer: B
Explanation:
This is an example of a logic bomb. The logic bomb is configured to 'go off' or when Jane has
left the company.
A logic bomb is a piece of code intentionally inserted into a software system that will set off
a malicious function when specified conditions are met. For example, a programmer may
hide a piece of code that starts deleting files should they ever be terminated from the
company.
Software that is inherently malicious, such as viruses and worms, often contain logic
bombs that execute a certain payload at a pre-defined time or when some other condition
is met. This technique can be used by a virus or worm to gain momentum and spread
before being noticed. Some viruses attack their host systems on specific dates, such as
Friday the 13th or April Fool's Day. Trojans that activate on certain dates are often called
"time bombs".
To be considered a logic bomb, the payload should be unwanted and unknown to the user
of the software. As an example, trial programs with code that disables certain functionality
after a set time are not normally regarded as logic bombs.
, Pete, a security analyst, has been tasked with explaining the different types of malware to
his colleagues. The two malware types that the group seems to be most interested in are
botnets and viruses. Which of the following explains the difference between these two
types of malware?
A. Viruses are a subset of botnets which are used as part of SYN attacks.
B. Botnets are a subset of malware which are used as part of DDoS attacks.
C. Viruses are a class of malware which create hidden openings within an OS.
D. Botnets are used within DR to ensure network uptime and viruses are not. - -correct ans-
-Answer: B
Explanation:
A botnet is a collection of Internet-connected programs communicating with other similar
programs in order to perform tasks. This can be as mundane as keeping control of an
Internet Relay Chat (IRC) channel, or it could be used to send spam email or participate in
distributed denial-of-service attacks. The word botnet is a combination of the words robot
and network. The term is usually used with a negative or malicious connotation.
Computers can be co-opted into a botnet when they execute malicious software. This can
be accomplished by luring users into making a drive-by download, exploiting web browser
vulnerabilities, or by tricking the user into running a Trojan horse program, which may come
from an email attachment. This malware will typically install modules that allow the
computer to be commanded and controlled by the botnet's operator. Many computer users
are unaware that their computer is infected with bots. Depending on how it is written, a
Trojan may then delete itself, or may remain present to update and maintain the modules.
A user, Ann, is reporting to the company IT support group that her workstation screen is
blank other than a window with a message requesting payment or else her hard drive will
be formatted. Which of the following types of malware is on Ann's workstation?
A. Trojan
B. Spyware
C. Adware