QuestionQ20

Network Security

Process checking is used to determine whether abnormal processes exist and whether the service host has been compromised or implanted with Trojan horses or backdoor programs. However, it cannot detect malicious programs that are not running and are hidden within the system.

Explanation

Process checking examines active, running processes. It can reveal suspicious executing programs, including active Trojans or backdoors, but dormant malware that is not running does not appear as a process and therefore cannot be detected by this method alone.

Community Discussion

No comments yet. Be the first to start the discussion!