Exam objective
Core 2 2.0: Malware Types, Detection, and Prevention
Malware Types, Detection, and Prevention for A+
This A+ topic covers technician-level recognition of common malware families, stealth/persistence categories, unwanted software (adware/PUP), named detection/response/protection tools, prevention methods oriented to users and small networks, and recovery-oriented options (recovery console and OS reinstallation) at a recognition level. The goal is to enable correct identification and appropriate next-step decisions, not to teach forensic analysis or vendor-specific tool usage.
Start first lesson6 lessons in this topic
Common mistakes to avoid
- Using 'virus' as a catchall term for all malware. Emphasize replication behavior for viruses. - Confusing Trojans with worms; Trojans need a user to install them, worms self-propagate.
- Believing a clean AV scan proves no compromise; many stealth threats evade signature-based scans. - Treating fileless behavior as harmless; fileless threats can be highly persistent and evade traditional scanning.
- Users may think adware is harmless; explain privacy and performance impacts. - Technicians might miss PUPs during scans if they are low-severity; include behavioral indicators when assessing.
- Treating MDR as a product rather than a service model. - Expecting antivirus alone to catch fileless or advanced persistence attacks; such cases often need EDR/XDR.