CompTIA A+ 1102 Malware Flashcards

(18 cards)

1
Q

malicious software

A

Malware

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q
  • software that pretends to be something else
  • anti-virus may catch it, but the better trojan horses are built to avoid and to disable anti-virus software
A

Trojan Horse

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q
  • modifies core system files
  • embeds itself deep inside the OS, often in the kernel
  • can be invisible to the OS and to anti-virus software
A

Rootkits

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Finding and Removing Rootkits

A
  • look for the unusual
  • use a remover specific to the rootkit
  • Secure Boot using a UEFI BIOS
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q
  • malware that can replicate itself
  • requires the user to execute a program
A

Virus

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q
  • virus that is part of the boot sector
  • runs every time that you start your computer
  • preventable with UEFI Secure Boot
A

Boot Sector Virus

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q
  • malware that spies on you
  • may trick you into installing it
  • may work in conjunction with a keylogger
A

Spyware

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

saves your input and logs other data, such as your clipboard data

A

Keylogger

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

encrypts your data, but will decrypt it if you pay the attackers a ransom

A

Ransomware

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Cryptominers

A
  • require extensive CPU processing ability
  • malware that forces cryptomining to occur on your computer
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q
  • basic command line that can be used without having to fully start Windows
  • provides complete control, but requires an extensive knowledge base to properly and safely use
A

Windows Recovery Environment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q
  • hold shift while clicking the restart button
  • or, boot from installation media
  • or, restart into advanced startup
  • recovery > troubleshoot > advanced options > command prompt
A

Starting the Windows Recovery Environment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q
  • monitors the local computer
  • prevents malware communication
  • for example, Microsoft Defender Firewall
  • built into Windows
A

Software Firewall

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the only way to guarantee malware removal?

A

OS reinstallation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Malware Removal Process (steps)

A
  1. verify malware symptoms
  2. quarantine infected
  3. disable system restore
  4. remediate : update anti-virus
  5. remediate : scan and remove
  6. schedule scans and run updates
  7. enable system protection
  8. educate the end user
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q
  • disconnect from the network
  • isolate all removable media
  • control the spread
A
  1. Quarantine Infected (Malware Removal Process)
17
Q
  1. Remediate : Update Anti-Virus (Malware Removal Process)
A
  • the malware may prevent the update process
  • copy updated signatures onto your computer
18
Q
  1. Remediate : Scan and Remove (Malware Removal Process)
A

use tools or run in Safe Mode or in WinPE