What provides the best defense against the introduction of malware in end-user computers via the internet browser?

Prepare for CISSP Domain 2 Information Risk Management. Study with multiple choice questions, each question offers insights and explanations. Ace your exam!

Restricting execution of mobile code is a highly effective defensive measure against malware intrusion through internet browsers. Mobile code refers to software that can be transmitted across the internet and executed on the user's machine, such as Java applets, ActiveX controls, and scripts in various programming languages. By restricting or controlling the execution of this type of code, organizations can significantly reduce the risk that malicious software will be able to run on end-user systems.

Malware often exploits mobile code vulnerabilities to download and execute harmful software unknowingly. When execution is restricted, even if a user unknowingly visits a compromised site or downloads suspicious content, the potential for malware to operate on the user's machine is mitigated. This creates a barrier that helps in protecting systems from attacks that could lead to data breaches, losses, or other infection vectors.

In contrast, the other choices either focus on mitigating specific types of threats or do not directly address protecting against malware introduced through browsers. Input validation checks are vital for preventing SQL injection attacks but do not specifically counteract browser-based malware threats. Restricting access to social media might reduce exposure to phishing attacks but does not encompass all vectors for malware. Deleting temporary files can help clear out some malware remnants but would not prevent its entry in the

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy