CompTIA A+ 1102 Malware Flashcards
(18 cards)
1
Q
malicious software
A
Malware
2
Q
- software that pretends to be something else
- anti-virus may catch it, but the better trojan horses are built to avoid and to disable anti-virus software
A
Trojan Horse
3
Q
- modifies core system files
- embeds itself deep inside the OS, often in the kernel
- can be invisible to the OS and to anti-virus software
A
Rootkits
4
Q
Finding and Removing Rootkits
A
- look for the unusual
- use a remover specific to the rootkit
- Secure Boot using a UEFI BIOS
5
Q
- malware that can replicate itself
- requires the user to execute a program
A
Virus
6
Q
- virus that is part of the boot sector
- runs every time that you start your computer
- preventable with UEFI Secure Boot
A
Boot Sector Virus
7
Q
- malware that spies on you
- may trick you into installing it
- may work in conjunction with a keylogger
A
Spyware
8
Q
saves your input and logs other data, such as your clipboard data
A
Keylogger
9
Q
encrypts your data, but will decrypt it if you pay the attackers a ransom
A
Ransomware
10
Q
Cryptominers
A
- require extensive CPU processing ability
- malware that forces cryptomining to occur on your computer
11
Q
- basic command line that can be used without having to fully start Windows
- provides complete control, but requires an extensive knowledge base to properly and safely use
A
Windows Recovery Environment
12
Q
- hold shift while clicking the restart button
- or, boot from installation media
- or, restart into advanced startup
- recovery > troubleshoot > advanced options > command prompt
A
Starting the Windows Recovery Environment
13
Q
- monitors the local computer
- prevents malware communication
- for example, Microsoft Defender Firewall
- built into Windows
A
Software Firewall
14
Q
What is the only way to guarantee malware removal?
A
OS reinstallation
15
Q
Malware Removal Process (steps)
A
- verify malware symptoms
- quarantine infected
- disable system restore
- remediate : update anti-virus
- remediate : scan and remove
- schedule scans and run updates
- enable system protection
- educate the end user
16
Q
- disconnect from the network
- isolate all removable media
- control the spread
A
- Quarantine Infected (Malware Removal Process)
17
Q
- Remediate : Update Anti-Virus (Malware Removal Process)
A
- the malware may prevent the update process
- copy updated signatures onto your computer
18
Q
- Remediate : Scan and Remove (Malware Removal Process)
A
use tools or run in Safe Mode or in WinPE