ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 123 - SY0-701 discussion

Report
Export

Malware spread across a company's network after an employee visited a compromised industry blog. Which of the following best describes this type of attack?

A.
Impersonation
Answers
A.
Impersonation
B.
Disinformation
Answers
B.
Disinformation
C.
Watering-hole
Answers
C.
Watering-hole
D.
Smishing
Answers
D.
Smishing
Suggested answer: C

Explanation:

A watering-hole attack is a type of cyberattack that targets groups of users by infecting websites that they commonly visit. The attackers exploit vulnerabilities to deliver a malicious payload to the organization's network. The attack aims to infect users' computers and gain access to a connected corporate network. The attackers target websites known to be popular among members of a particular organization or demographic.The attack differs from phishing and spear-phishing attacks, which typically attempt to steal data or install malware onto users' devices1

In this scenario, the compromised industry blog is the watering hole that the attackers used to spread malware across the company's network. The attackers likely chose this blog because they knew that the employees of the company were interested in its content and visited it frequently. The attackers may have injected malicious code into the blog or redirected the visitors to a spoofed website that hosted the malware. The malware then infected the employees' computers and propagated to the network.

Reference 1:Watering Hole Attacks: Stages, Examples, Risk Factors & Defense ...

asked 02/10/2024
Bas Vogel
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first