Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil 312-39 Exam - Topic 7 Question 119 Discussion

A mid-sized hospital's SOC team has recently detected multiple malware incidents that disrupted access to patient records and caused operational inefficiencies. The SOC analysts have been tasked with eradicating current infections and preventing future attacks by addressing the underlying vulnerabilities that allowed the malware to breach defenses. As a SOC analyst, you need to recommend a step that directly targets weaknesses in the hospital's network infrastructure or system configurations exploited by the malware. Which eradication step would best address these root causes?
A) Fixing devices
B) Using antivirus tools for quarantine
C) Updating the malware database with vendor signatures
D) Implementing blacklist techniques for file execution

Eccouncil 312-39 Exam - Topic 7 Question 119 Discussion

Actual exam question for Eccouncil's 312-39 exam
Question #: 119
Topic #: 7
[All 312-39 Questions]

A mid-sized hospital's SOC team has recently detected multiple malware incidents that disrupted access to patient records and caused operational inefficiencies. The SOC analysts have been tasked with eradicating current infections and preventing future attacks by addressing the underlying vulnerabilities that allowed the malware to breach defenses. As a SOC analyst, you need to recommend a step that directly targets weaknesses in the hospital's network infrastructure or system configurations exploited by the malware. Which eradication step would best address these root causes?

Show Suggested Answer Hide Answer
Suggested Answer: A

Eradication is about removing the threat and eliminating the conditions that allowed it to persist or recur. ''Fixing devices'' best aligns with addressing root causes because it implies remediating exploited weaknesses: patching vulnerable software, correcting misconfigurations, removing persistence mechanisms, hardening endpoints/servers, and restoring secure baselines. In healthcare environments, malware frequently exploits unpatched systems, exposed services, weak segmentation, permissive scripting policies, or inadequate least privilege. Quarantining with antivirus is helpful for immediate removal but may not eliminate the exploited vulnerability or persistence path; attackers can reinfect if the underlying gap remains. Updating signatures improves detection for known malware but does not address a misconfiguration or missing patch and will not reliably stop novel variants. Blacklisting file execution can reduce risk but is typically a partial, reactive control and can be bypassed by renaming, living-off-the-land tools, or script-based payloads. From a SOC analyst perspective, the most durable eradication action is to ''fix the device'' by restoring trusted configuration and closing the exploit vector, combined with validation scans and monitoring to confirm the environment is clean and hardened.


Contribute your Thoughts:

0/2000 characters
Erick
5 hours ago
Blacklist techniques? Not sure that’s enough.
upvoted 0 times
...
Peter
5 days ago
I think updating the malware database is more effective.
upvoted 0 times
...
Fletcher
11 days ago
Definitely fixing devices is key!
upvoted 0 times
...
Kati
16 days ago
Implementing blacklist techniques sounds familiar, but I wonder if that really targets the vulnerabilities or just prevents known threats.
upvoted 0 times
...
Tuyet
2 months ago
I feel like updating the malware database is more about detection than actually fixing the underlying issues. It might not be the best choice.
upvoted 0 times
...
Glenn
2 months ago
I'm not entirely sure, but I think using antivirus tools might just be a temporary fix. We need to address the root cause, right?
upvoted 0 times
...
Catarina
2 months ago
I remember we discussed the importance of fixing devices to close vulnerabilities. That seems like a solid option here.
upvoted 0 times
...

Save Cancel