ExamGecko
Question list
Search
Search

Question 85 - PCDRA discussion

Report
Export

Which Exploit Protection Module (EPM) can be used to prevent attacks based on OS function?

A.
UASLR
Answers
A.
UASLR
B.
JIT Mitigation
Answers
B.
JIT Mitigation
C.
Memory Limit Heap Spray Check
Answers
C.
Memory Limit Heap Spray Check
D.
DLL Security
Answers
D.
DLL Security
Suggested answer: B

Explanation:

JIT Mitigation is an Exploit Protection Module (EPM) that can be used to prevent attacks based on OS function. JIT Mitigation protects against exploits that use the Just-In-Time (JIT) compiler of the OS to execute malicious code. JIT Mitigation monitors the memory pages that are allocated by the JIT compiler and blocks any attempts to execute code from those pages. This prevents attackers from using the JIT compiler as a way to bypass other security mechanisms such as Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR).Reference:

Palo Alto Networks. (2023). PCDRA Study Guide. PDF file. Retrieved from https://www.paloaltonetworks.com/content/dam/pan/en_US/assets/pdf/datasheets/education/pcdra-study-guide.pdf

Palo Alto Networks. (2021). Exploit Protection Modules. Web page. Retrieved from https://docs.paloaltonetworks.com/traps/6-0/traps-endpoint-security-manager-admin/traps-endpoint-security-policies/exploit-protection-modules.html

asked 23/09/2024
Mohamed Nacer Ferhi
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first