Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Broadcom 250-580 Exam - Topic 7 Question 27 Discussion

How does Memory Exploit Mitigation protect applications?
A) Injects a DLL (IPSEng32.dll or IPSEng64.dll) into protected processes and when an exploit attempt is detected, terminates the protected process to prevent the malicious code from running.
B) Injects a DLL (UMEngx86.dll) into applications that run in user mode and if the application behaves maliciously, then SEP detects it.
C) Injects a DLL (sysfer.dll) into processes being launched on the machine and if the process isn't trusted, prevents the process from running.
D) Injects a DLL (IPSEng32.dll) into browser processes and protects the machine from drive-by downloads.

Broadcom 250-580 Exam - Topic 7 Question 27 Discussion

Actual exam question for Broadcom's 250-580 exam
Question #: 27
Topic #: 7
[All 250-580 Questions]

How does Memory Exploit Mitigation protect applications?

Show Suggested Answer Hide Answer
Suggested Answer: A

Memory Exploit Mitigation in Symantec Endpoint Protection (SEP) works by injecting a DLL (Dynamic Link Library) --- specifically, IPSEng32.dll for 32-bit processes or IPSEng64.dll for 64-bit processes --- into applications that require protection. Here's how it works:

DLL Injection:

When Memory Exploit Mitigation is enabled, SEP injects IPSEng DLLs into processes that it monitors for potential exploit attempts.

This injection allows SEP to monitor the behavior of the process at a low level, enabling it to detect exploit attempts on protected applications.

Exploit Detection and Response:

If an exploit attempt is detected within a protected process, SEP will terminate the process immediately. This termination prevents malicious code from running, stopping potential exploit actions from completing.

Why This Approach is Effective:

By terminating the process upon exploit detection, SEP prevents any code injected or manipulated by an exploit from executing. This proactive approach effectively stops many types of memory-based attacks, such as buffer overflows, before they can harm the system.

Clarification on Other Options:

Option B (UMEngx86.dll) pertains to user-mode protection, which isn't used for Memory Exploit Mitigation.

Option C (sysfer.dll) is involved in file system driver activities, not direct exploit prevention.

Option D is partially correct about IPSEng32.dll but inaccurately specifies that it's for browser processes only; the DLL is used for multiple types of processes.


Contribute your Thoughts:

0/2000 characters
Shayne
54 minutes ago
I agree, A makes sense. Stopping the exploit is crucial.
upvoted 0 times
...
Salena
5 days ago
I think A is the best answer. It directly terminates the process.
upvoted 0 times
...
Shelton
10 days ago
Wait, can a DLL really protect against all these threats? Seems too good to be true.
upvoted 0 times
...
Roy
16 days ago
D) is interesting, but does it really stop drive-by downloads?
upvoted 0 times
...
Keva
21 days ago
C) sounds right, it checks process trustworthiness.
upvoted 0 times
...
Audry
26 days ago
I think B) is more about user mode apps, not just exploits.
upvoted 0 times
...
Shawna
1 month ago
A) is correct, it terminates the process on exploit detection.
upvoted 0 times
...
Gladis
1 month ago
I vaguely remember that one of the options was related to browser protection, but I can't remember if that was the right answer for this question.
upvoted 0 times
...
Fernanda
3 months ago
I practiced a similar question, and I believe the correct answer involves terminating processes when an exploit is detected, but I’m confused about the specific DLL mentioned.
upvoted 0 times
...
Peggie
3 months ago
I think it was something about injecting a DLL to monitor application behavior, but I can't recall if it was user mode or kernel mode.
upvoted 0 times
...
Werner
3 months ago
I remember studying how Memory Exploit Mitigation works, but I’m not sure which DLL is the right one for process protection.
upvoted 0 times
...

Save Cancel