Systems Security Certified Practitioner – SSCP – Question1066

Which virus category has the capability of changing its own code, making it harder to detect by anti-virus software?

A.
Stealth viruses
B. Polymorphic viruses
C. Trojan horses
D. Logic bombs

Correct Answer: B

Explanation:

A polymorphic virus has the capability of changing its own code, enabling it to have many different variants, making it harder to detect by anti-virus software. The particularity of a stealth virus is that it tries to hide its presence after infecting a system. A Trojan horse is a set of unauthorized instructions that are added to or replacing a legitimate program. A logic bomb is a set of instructions that is initiated when a specific event occurs. Source: HARRIS, Shon, All-In-One CISSP Certification Exam Guide, McGraw-Hill/Osborne, 2002, chapter 11: Application and System Development (page 786).