Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Broadcom 250-580 Exam - Topic 7 Question 27 Discussion

How does Memory Exploit Mitigation protect applications?
A) Injects a DLL (IPSEng32.dll or IPSEng64.dll) into protected processes and when an exploit attempt is detected, terminates the protected process to prevent the malicious code from running.
B) Injects a DLL (UMEngx86.dll) into applications that run in user mode and if the application behaves maliciously, then SEP detects it.
C) Injects a DLL (sysfer.dll) into processes being launched on the machine and if the process isn't trusted, prevents the process from running.
D) Injects a DLL (IPSEng32.dll) into browser processes and protects the machine from drive-by downloads.

Broadcom 250-580 Exam - Topic 7 Question 27 Discussion

Actual exam question for Broadcom's 250-580 exam
Question #: 27
Topic #: 7
[All 250-580 Questions]

How does Memory Exploit Mitigation protect applications?

Show Suggested Answer Hide Answer
Suggested Answer: A

Memory Exploit Mitigation in Symantec Endpoint Protection (SEP) works by injecting a DLL (Dynamic Link Library) --- specifically, IPSEng32.dll for 32-bit processes or IPSEng64.dll for 64-bit processes --- into applications that require protection. Here's how it works:

DLL Injection:

When Memory Exploit Mitigation is enabled, SEP injects IPSEng DLLs into processes that it monitors for potential exploit attempts.

This injection allows SEP to monitor the behavior of the process at a low level, enabling it to detect exploit attempts on protected applications.

Exploit Detection and Response:

If an exploit attempt is detected within a protected process, SEP will terminate the process immediately. This termination prevents malicious code from running, stopping potential exploit actions from completing.

Why This Approach is Effective:

By terminating the process upon exploit detection, SEP prevents any code injected or manipulated by an exploit from executing. This proactive approach effectively stops many types of memory-based attacks, such as buffer overflows, before they can harm the system.

Clarification on Other Options:

Option B (UMEngx86.dll) pertains to user-mode protection, which isn't used for Memory Exploit Mitigation.

Option C (sysfer.dll) is involved in file system driver activities, not direct exploit prevention.

Option D is partially correct about IPSEng32.dll but inaccurately specifies that it's for browser processes only; the DLL is used for multiple types of processes.


Contribute your Thoughts:

0/2000 characters
Bernardine
2 days ago
B is interesting too. User mode detection is crucial.
upvoted 0 times
...
Shaun
7 days ago
I agree, A seems effective. Stops the exploit immediately.
upvoted 0 times
...
Pamella
12 days ago
I think A is the best option. It directly terminates the process.
upvoted 0 times
...
Vivan
18 days ago
I feel A covers more ground. It's proactive.
upvoted 0 times
...
Brigette
23 days ago
D seems limited to browsers. Not comprehensive enough.
upvoted 0 times
...
Richelle
28 days ago
C could prevent untrusted processes from running.
upvoted 0 times
...
Jose
1 month ago
C is interesting. Trust is key in security.
upvoted 0 times
...
Sanjuana
1 month ago
But B relies on behavior, which can be tricky.
upvoted 0 times
...
Latosha
1 month ago
B sounds good too. User mode detection is important.
upvoted 0 times
...
Shayne
2 months ago
I agree, A makes sense. Stopping the exploit is crucial.
upvoted 0 times
...
Salena
2 months ago
I think A is the best answer. It directly terminates the process.
upvoted 0 times
...
Shelton
2 months ago
Wait, can a DLL really protect against all these threats? Seems too good to be true.
upvoted 0 times
...
Roy
2 months ago
D) is interesting, but does it really stop drive-by downloads?
upvoted 0 times
...
Keva
2 months ago
C) sounds right, it checks process trustworthiness.
upvoted 0 times
...
Audry
2 months ago
I think B) is more about user mode apps, not just exploits.
upvoted 0 times
...
Shawna
3 months ago
A) is correct, it terminates the process on exploit detection.
upvoted 0 times
...
Gladis
3 months ago
I vaguely remember that one of the options was related to browser protection, but I can't remember if that was the right answer for this question.
upvoted 0 times
...
Fernanda
4 months ago
I practiced a similar question, and I believe the correct answer involves terminating processes when an exploit is detected, but I’m confused about the specific DLL mentioned.
upvoted 0 times
...
Peggie
5 months ago
I think it was something about injecting a DLL to monitor application behavior, but I can't recall if it was user mode or kernel mode.
upvoted 0 times
...
Werner
5 months ago
I remember studying how Memory Exploit Mitigation works, but I’m not sure which DLL is the right one for process protection.
upvoted 0 times
...

Save Cancel