ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
While reviewing CloudTrail logs and EDR telemetry for a Windows-based EC2 instance that hosts an internal web application, you see that WinRM spawned powershell.exe, which downloaded obfuscated script blocks from the registry, injected shellcode into memory, and opened an outbound HTTPS reverse shell. No unknown executables remain on the volume after a system reboot. According to SSCP malware categories, which type of malware is most likely responsible for this activity?
Kernel-level rootkit implanted in the Master Boot Record
The indicators point to malicious code that operates almost entirely in memory: it is launched through a legitimate interpreter (PowerShell), stores its payload in the registry, executes without writing new files to disk, and leaves no persistent binaries after reboot. These are hallmark behaviors of fileless malware. Rootkits usually modify the kernel or boot records and leave components on disk; worms focus on self-propagation across hosts; ransomware's primary goal is to encrypt on-disk data and reveal itself for ransom. Therefore, fileless malware is the best fit for the observed attack pattern.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is fileless malware?
Open an interactive chat with Bash
How does PowerShell enable fileless malware attacks?
Open an interactive chat with Bash
What are some common detection techniques for fileless malware?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Systems and Application Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .