medium
Single Answer
0As part of his incident response process, Alekos securely wipes the drive of a compromised machine and reinstalls the operating system (OS) from original media. Once he is done, he patches the machine fully and applies his organization's security templates before reconnecting the system to the network. Almost immediately after the system is returned to service, he discovers that it has reconnected to the same botnet it was part of before. Where should Alekos look for the malware that is causing this behavior?
Answer Options
A
The operating system partition
B
The system BIOS or firmware
C
The system memory
D
The installation media
Correct Answer: B
Explanation
The system Alekos is remediating may have a firmware or BIOS infection, with malware resident on the system board. While uncommon, this type of malware can be difficult to find and remove. Since he used original media, it is unlikely that the malware came from the software vendor. Alekos wiped the system partition, and the system would have been rebooted before being rebuilt, thus clearing system memory.