問題文
Why does the "persistent" part of an advanced persistent threat change what defenders need to be able to do?
選択肢
- Because persistence means the malicious code reinstalls itself, the only necessary response is to rebuild each affected host from a known image.
- Because the adversary may be present for months, defenders need visibility and records that reach back far enough to reconstruct what happened.
- Because the adversary stays for a long time, the defenders can safely wait for the next scheduled quarterly review before investigating, since a long campaign will still be there when the review begins and nothing is lost by waiting.
- Because a long campaign is always detected by antivirus in the end, which means the records only have to cover the days after the signature was published.