Which category describes systems that are currently running malware?

Study for the SANS Advanced Incident Response, Threat Hunting, and Digital Forensics (FOR508) Test. Prepare with comprehensive materials, flashcards, and multiple choice questions with hints and explanations. Ace your exam with confidence!

Multiple Choice

Which category describes systems that are currently running malware?

Explanation:
The key idea is distinguishing by whether the malware is actively executing on a host. When malware is currently running, the system is described as having active malware. Dormant malware is present but not executing, and Living off the Land refers to attackers using legitimate tools rather than indicating the malware’s running state. Isolated systems describe containment status and can be either clean or infected, but isolation doesn’t imply malware is actively running. So the description for systems where malware is actually running is the one with active malware.

The key idea is distinguishing by whether the malware is actively executing on a host. When malware is currently running, the system is described as having active malware. Dormant malware is present but not executing, and Living off the Land refers to attackers using legitimate tools rather than indicating the malware’s running state. Isolated systems describe containment status and can be either clean or infected, but isolation doesn’t imply malware is actively running. So the description for systems where malware is actually running is the one with active malware.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy