ボストンのサイバーセキュリティコンサルティング会社で、シニアアナリストのアマンダ・リューは、地域の医療機関に影響を与えているマルウェア感染の調査に招聘されました。最新のウイルス対策ツールを使用しているにもかかわらず、セキュリティチームは感染したエンドポイント間で検出結果に一貫性がないことに気付きました。システムファイルの改ざんや不審なアウトバウンドトラフィックといった悪意のある動作は一貫しているものの、マルウェアサンプルごとにコード構造がわずかに異なり、従来のハッシュベースの比較では検出されないことをアマンダは発見しました。静的解析の結果、基盤となるロジックは変わっていないものの、コードパターンは感染ごとに予測不能なほど変化していることが明らかになりました。この動作の原因は、どのような種類のウイルスである可能性が高いのでしょうか?
正解:C
A polymorphic virus is specifically designed to change its code appearance while keeping the same underlying functionality, which aligns exactly with the scenario. In CEH terms, polymorphism allows malware to mutate its decryptor routine, instruction ordering, register usage, junk code insertion, and other syntactic elements every time it propagates or executes. This causes each instance to look different at the binary level, producing different hashes and signatures, even though the malicious payload and behavior remain the same. That is why the security team sees inconsistent antivirus detection and why "traditional hash- based comparison" fails. The key indicator is that static analysis shows the "underlying logic remains unchanged," but "code patterns vary unpredictably," which is the hallmark of polymorphism: behavior stays consistent, signature changes.
The other options do not fit as well. A cavity virus typically hides by inserting itself into unused spaces within legitimate executable files to avoid changing the overall file size, but it does not inherently generate unpredictable code variants per infection. A macro virus primarily targets macro-enabled documents and spreads through document templates and user actions, which is not suggested here. A stealth virus focuses on evading detection by intercepting system calls and hiding its presence, such as returning "clean" file reads, but it does not necessarily produce many structurally different binaries that break hash matching. Therefore, the most likely cause of the described outbreak is a polymorphic virus.