200-201 · Question #413
An employee reports that someone has logged into their system and made unapproved changes, files are out of order, and several documents have been placed in the recycle bin. The security specialist…
The correct answer is B. The threat actor gained access to the system by known credentials. If a threat actor gains access to a system using legitimate or known credentials, security logs might not capture this as an anomaly or suspicious activity. When an attacker uses valid credentials, the system interprets the login as legitimate, causing the lack of failed login…
Question
An employee reports that someone has logged into their system and made unapproved changes, files are out of order, and several documents have been placed in the recycle bin. The security specialist reviewed the system logs, found nothing suspicious, and was not able to determine what occurred. The software is up to date; there are no alerts from antivirus and no failed login attempts. What is causing the lack of data visibility needed to detect the attack?
Options
- AThe threat actor used a dictionary-based password attack to obtain credentials.
- BThe threat actor gained access to the system by known credentials.
- CThe threat actor used the teardrop technique to confuse and crash login services.
- DThe threat actor used an unknown vulnerability of the operating system that went undetected.
How the community answered
(27 responses)- A7% (2)
- B63% (17)
- C7% (2)
- D22% (6)
Explanation
If a threat actor gains access to a system using legitimate or known credentials, security logs might not capture this as an anomaly or suspicious activity. When an attacker uses valid credentials, the system interprets the login as legitimate, causing the lack of failed login attempts or unusual login activity in the logs. This method of unauthorized access using valid credentials could bypass traditional security monitoring or detection systems, making it challenging to detect the attack solely based on system logs or failed login attempts.
Topics
Community Discussion
No community discussion yet for this question.