Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

ECCouncil Certified Ethical Hacker Exam (CEHv13) 312-50v13 Question # 148 Topic 15 Discussion

ECCouncil Certified Ethical Hacker Exam (CEHv13) 312-50v13 Question # 148 Topic 15 Discussion

312-50v13 Exam Topic 15 Question 148 Discussion:
Question #: 148
Topic #: 15

A security analyst is investigating a network compromise where malware communicates externally using common protocols such as HTTP and DNS. The malware operates stealthily, modifies system components, and avoids writing payloads to disk. What is the most effective action to detect and disrupt this type of malware communication?


A.

Blocking commonly known malware ports such as 6667 and 12345.


B.

Relying solely on frequent antivirus signature updates.


C.

Using behavioral analytics to monitor abnormal outbound traffic and application behavior.


D.

Blocking all unencrypted HTTP traffic at the proxy level.


Get Premium 312-50v13 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.