• Home
  • Textbooks
  • The SSCP Prep Guide: Mastering the Seven Key Areas of System Security
  • Domain 7: Malicious Code

The SSCP Prep Guide: Mastering the Seven Key Areas of System Security

Debra S. Isaac, Michael J. Isaac

Chapter 8

Domain 7: Malicious Code - all with Video Answers

Educators


Chapter Questions

Problem 1

Which one of the following characteristics is NOT associated with a computer virus?
a. Malicious code that infects files and can infect the boot sector
b. A program that replicates itself without the approval of the user
c. Malicious code that attaches to a host program and propagates when the infected program is executed
d. Malicious code that is hidden in a program that has a useful function or apparently useful function

Check back soon!
01:31

Problem 2

A malicious computer program that is activated when a particular state of the computer occurs, such as a particular date and time, is called a:
a. Polymorphic virus
b. Logic bomb
c. Retro virus
d. Keyed virus

Asma Venkitta
Asma Venkitta
Numerade Educator
00:25

Problem 3

Code that can be downloaded from a network and executed on a local computer is known as:
a. A virtual machine
b. A dynamic machine
c. Mobile code
d. Pointer code

Ernest Castorena
Ernest Castorena
Numerade Educator
01:17

Problem 4

Which one of the following is NOT a characteristic of a worm virus?
a. Can remain on an infected computer indefinitely
b. Requires operating systems that support the execution of downloaded programs
c. Creates multiple replicas of itself on the infected computer until memory is used up and the infected computer crashes
d. Requires a means to transmit itself to other networked computers

Joanna Quigley
Joanna Quigley
Numerade Educator
01:31

Problem 5

A virus that conceals the modifications that it makes to a computer's files is called a:
a. Hidden virus
b. Proxy virus
c. Stealth virus
d. Multipartite virus

Asma Venkitta
Asma Venkitta
Numerade Educator

Problem 6

An individual that creates or uses programs to break into telephone systems to be able to access other computers is called a:
a. Hacker
b. Phreaker
c. Cracker
d. Social engineer

Check back soon!
01:46

Problem 7

Which of the following statements regarding malicious code is NOT true?
a. Worms and viruses replicate themselves.
b. Trojan horses and viruses replicate themselves.
c. Trojan horses and viruses are associated with other programs.
d. A worm does not need another program to serve as a host.

Joanna Quigley
Joanna Quigley
Numerade Educator

Problem 8

Malicious code that is set to execute when a user, A, logs on 110 times is a:
a. Stealth virus
b. Polymorphic virus
c. Worm
d. Logic bomb

Check back soon!

Problem 9

An attack script is which one of the following?
a. A step-by-step procedure that a cracker follows to initiate attacks on networks
b. Malicious code that can be downloaded from different sites on the Internet and used to mount an attack on computing resources
c. A rehearsed social engineering ploy to gain access to passwords
d. The product of applying a keyed hash function to a sensitive message

Check back soon!

Problem 10

Which one of the following procedures is NOT recommended for detecting malicious code and preventing malicious code attacks?
a. Deploying virus scanning software
b. Education of employees
c. Downloading of software from the Internet
d. Disable ports that are not required for the organization's business

Check back soon!

Problem 11

An excellent approach to defending against malicious code is an access control layered defense. Which one of the following is NOT a component of this type of defense?
a. Making backups of "clean" files
b. Restricting who can physically gain entry to areas containing computing resources
c. Controlling who has the ability to read, write, and copy files
d. Restricting the use of specific computing resources to those who require those resources to perform their assigned job functions

Check back soon!
00:57

Problem 12

A virus that is associated with loading of the operating system into memory on startup is called a:
a. Boot sector virus
b. Companion virus
c. Macro virus
d. Source code virus

Joanna Quigley
Joanna Quigley
Numerade Educator
06:55

Problem 13

Which one of the following items best describes the accuracy of the following statement: "Only executable programs can contain viruses, therefore files that are not executable are not a concern relative to malicious code"?
a. True
b. True with one exception
c. False
d. False with one exception

Nicholas Sacco
Nicholas Sacco
Numerade Educator

Problem 14

Two general categories of stealth virus capabilities are:
a. Write stealth and copy stealth
b. Read stealth and write stealth
c. Size stealth and write stealth
d. Size stealth and read stealth

Check back soon!

Problem 15

Which one of the following is NOT a reason that peer-to-peer networks are more vulnerable to file-resident virus attacks than network servers?
a. Because every workstation on a peer-to-peer network can function both as a client and a server, the network is more resistant to file-resident virus attacks.
b. Viruses can be transmitted from one workstation to another on a peer-to-peer network.
c. Because every workstation on a peer-to-peer network can function both as a client and a server, the network is less resistant to fileresident virus attacks.
d. Peer-to-peer network security is usually weaker than what exists on a network server.

Check back soon!
03:08

Problem 16

Which choice BEST describes a simple virus, as opposed to a complex virus?
a. Users who have little computer knowledge can use Internet programs to create simple viruses.
b. Simple viruses attempt to conceal themselves from systems.
c. A simple virus is divided into three parts: the replicator, the concealer, and the bomb.
d. Knowledge of assembly language is required to manipulate interrupts so that simple viruses can remain hidden.

Dr. Anas Syed
Dr. Anas Syed
Numerade Educator
02:10

Problem 17

Which choice is NOT a common part of a complex virus?
a. Replicator
b. Macro
c. Bomb
d. Concealer

Valeria Taborda
Valeria Taborda
Numerade Educator
00:36

Problem 18

Which choice is NOT a step in the polymorphic virus infection process?
a. The decryption routine first gains control of the computer and decrypts both the virus body and the mutation engine.
b. The decryption routine transfers control of the computer to the virus, which locates a new program to infect.
c. The virus makes a copy of itself and the mutation engine in RAM.
d. The virus creates a network backdoor to enable unauthorized entry at a later date.

Sam Limsuwannarot
Sam Limsuwannarot
Numerade Educator
03:07

Problem 19

Which choice is an incorrect statement about pre-infection prevention?
a. Pre-infection prevention products are used as the first level of defense against malicious code.
b. Email filtering products that do not enable executable programs or certain file types to be transferred.
c. Options in browsers that limit the use of and/or disable Java and ActiveX plug-ins.
d. Pre-infection prevention products are much less scientific than postinfection products because they use educated guesses.

Matthew Gooch
Matthew Gooch
Numerade Educator
00:54

Problem 20

Which choice is NOT true about virus vaccination programs?
a. The majority of short-term infection detection products use vaccination because it is easier to implement.
b. Vaccination programs modify application programs to allow for a self-test mechanism within each program.
c. The drawbacks to this implementation include the fact that the boot segment is very hard to vaccinate, and the malicious code might gain control before the vaccination program can warn the user.
d. The majority of short-term infection detection products do not use vaccinations because they are very difficult to implement.

Grant Castaneda
Grant Castaneda
Numerade Educator
03:07

Problem 21

Which statement is correct about short-term infection detection products?
a. The majority of short-term infection detection products use spectral analysis.
b. The majority of short-term infection detection products use the snapshot technique because it is easier to implement.
c. The majority of short-term infection detection products use vaccination because it is easier to implement.
d. The majority of short-term infection detection products use heuristic analysis.

Matthew Gooch
Matthew Gooch
Numerade Educator
01:46

Problem 22

Which choice BEST describes the snapshot technique of virus detection?
a. The snapshot technique is a long-term infection detection process.
b. The snapshot technique identifies systems that have been infected for a long time.
c. The snapshot technique uses educated guesses to find infections.
d. Upon installation, a log of all critical information is made.

Grant Castaneda
Grant Castaneda
Numerade Educator
01:47

Problem 23

Which choice BEST describes long-term virus infection products?
a. Long-term infection detection products detect an infection very soon after the infection has occurred.
b. Long-term infection detection products identify specific malicious code on a system that has already been infected for some time.
c. Long-term infection detection products can be implemented through vaccination programs and the snapshot technique.
d. Long-term infection detection products generally address a small infected area of the system.

Dennis Howard
Dennis Howard
Numerade Educator
01:31

Problem 24

Which choice is an element of heuristic infection detection?
a. Using heuristic analysis all data is examined and recorded for malicious code patterns.
b. Heuristic analysis is used in short-term infection detection products.
c. Heuristic analysis is much less scientific, using educated guesses.
d. Heuristic analysis guarantees exact and hard evidence of infection.

Alexander Cheng
Alexander Cheng
Numerade Educator
02:39

Problem 25

Which statement about spectral analysis is not correct?
a. Spectral analysis is a long-term infection detection product.
b. Spectral analysis is a short-term infection detection product.
c. All data is examined and recorded to discover automatically generated malicious code.
d. When a pattern or subset of it appears, a counter is incremented.

Himanshu Kushwaha
Himanshu Kushwaha
Numerade Educator

Problem 26

Which description is the BEST definition of a Category 2 mobile code?
a. Mobile code that has known security vulnerabilities with few or no countermeasures once it begins executing
b. Mobile code supporting limited functionality, with no capability for unmediated access to workstation, host, and remote system services and resources
c. Mobile code having full functionality, allowing mediated or controlled access to workstation, host, and remote system services and resources
d. Mobile code exhibiting a broad functionality, allowing unmediated access to workstation, host, and remote system services and resources

Check back soon!
01:17

Problem 27

Which choice is a property of immediate virus detection products?
a. Immediate virus detection products are used to detect an infection very soon after the infection has occurred.
b. Immediate virus detection products periodically scan the entire system to search out malicious code.
c. Immediate virus detection is used to identify specific malicious code on a system.
d. Immediate virus detection is not functional on Category 1 mobile code.

Joanna Quigley
Joanna Quigley
Numerade Educator
01:17

Problem 28

Which choice below is NOT a property of permanent virus detection products?
a. Permanent virus detection usually removes malicious code after a scan and returns the system to its prior functionality.
b. Permanent virus detection products detect an infection quickly after infection.
c. Permanent virus detection periodically scans the entire system.
d. Permanent virus detection can be used to identify specific malicious code on a system.

Joanna Quigley
Joanna Quigley
Numerade Educator

Problem 29

Which choice would NOT be an example of a proper enterprise-wide security procedure?
a. Encourage the distribution of spam to increase the company's name recognition.
b. Restrict users from bringing uncontrolled floppies from home to the office.
c. Discourage blind downloading of software from unregulated Internet sites.
d. Regulate access to Internet sites to reputable URLs only.

Check back soon!

Problem 30

Why should an organization discourage users from forwarding email chain letters?
a. The company does not want you wasting time on fun stuff.
b. They waste computer system resources.
c. They can contain false information to mislead people.
d. They do not increase the company's name recognition.

Check back soon!