During security testing, you use virus code that rewrites itself entirely and changes the signatures with each infection but preserves functionality. What type of virus is this?

Enhance your knowledge as a Computer Hacking Forensic Investigator with the CHFI v11 Test. Use flashcards and multiple-choice questions, complete with hints and detailed explanations, to prepare effectively and ace your exam!

Multiple Choice

During security testing, you use virus code that rewrites itself entirely and changes the signatures with each infection but preserves functionality. What type of virus is this?

Explanation:
Mutating code that rewrites its entire body with every infection while keeping the same functionality is a metamorphic virus. It essentially reconstitutes itself into a completely new form each time, so there’s no stable signature to rely on for detection. Yet the actions it performs remain the same, so its behavior isn’t altered even though the code looks different. Oligomorphic malware switches among a small set of decryptors; polymorphic malware mutates its decryptor and uses encryption, but doesn’t rewrite the entire program; transmorphic isn’t a standard term for this behavior. Therefore, metamorphic is the best fit.

Mutating code that rewrites its entire body with every infection while keeping the same functionality is a metamorphic virus. It essentially reconstitutes itself into a completely new form each time, so there’s no stable signature to rely on for detection. Yet the actions it performs remain the same, so its behavior isn’t altered even though the code looks different.

Oligomorphic malware switches among a small set of decryptors; polymorphic malware mutates its decryptor and uses encryption, but doesn’t rewrite the entire program; transmorphic isn’t a standard term for this behavior. Therefore, metamorphic is the best fit.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy