Exam SY0-701 Topic 1 Question 168 Discussion
Actual exam question for CompTIA's SY0-701 exam
Question #: 168
Topic #: 1
Question #: 168
Topic #: 1
Malware spread across a company's network after an employee visited a compromised industry blog. Which of the following best describes this type of attack?
Suggested Answer: C Vote an answer
A watering-hole attack is a type of cyberattack that targets groups of users by infecting websites that they commonly visit. The attackers exploit vulnerabilities to deliver a malicious payload to the organization's network. The attack aims to infect users' computers and gain access to a connected corporate network. The attackers target websites known to be popular among members of a particular organization or demographic. The attack differs from phishing and spear-phishing attacks, which typically attempt to steal data or install malware onto users' devices1 In this scenario, the compromised industry blog is the watering hole that the attackers used to spread malware across the company's network. The attackers likely chose this blog because they knew that the employees of the company were interested in its content and visited it frequently. The attackers may have injected malicious code into the blog or redirected the visitors to a spoofed website that hosted the malware. The malware then infected the employees' computers and propagated to the network.
References1: Watering Hole Attacks: Stages, Examples, Risk Factors & Defense ...
References1: Watering Hole Attacks: Stages, Examples, Risk Factors & Defense ...
by Ruby at Jun 27, 2024, 04:06 AM
Contact Us
If you have any question please leave me your email address, we will reply and send email to you in 12 hours.
Our Working Time: ( GMT 0:00-15:00 ) From Monday to Saturday
Support: Contact now
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).