nerdexam
Cisco

300-215 · Question #28

Refer to the exhibit. An employee notices unexpected changes and setting modifications on their workstation and creates an incident ticket. A support specialist checks processes and services but…

The correct answer is D. log tampering. The event log shown in the exhibit is Event ID 104, which in Windows indicates "The audit log was cleared." This is a significant indicator of log tampering, a common post-exploitation technique used by attackers to hide their tracks after exfiltrating data or performing…

Submitted by hassan_iq· Mar 6, 2026Forensics Techniques

Question

Refer to the exhibit. An employee notices unexpected changes and setting modifications on their workstation and creates an incident ticket. A support specialist checks processes and services but does not identify anything suspicious. The ticket was escalated to an analyst who reviewed this event log and also discovered that the workstation had multiple large data dumps on network shares. What should be determined from this information?

Exhibit

300-215 question #28 exhibit

Options

  • Adata obfuscation
  • Breconnaissance attack
  • Cbrute-force attack
  • Dlog tampering

How the community answered

(33 responses)
  • A
    3% (1)
  • B
    9% (3)
  • C
    15% (5)
  • D
    73% (24)

Explanation

The event log shown in the exhibit is Event ID 104, which in Windows indicates "The audit log was cleared." This is a significant indicator of log tampering, a common post-exploitation technique used by attackers to hide their tracks after exfiltrating data or performing unauthorized Log deletion events, especially Event ID 104, should be treated as potential evidence of malicious activity attempting to cover tracks. Combined with large data dumps to network shares, this indicates not only unauthorized activity but also deliberate efforts to erase forensic evidence--characteristic of log tampering.

Topics

#log tampering#data exfiltration#workstation compromise#incident analysis

Community Discussion

No community discussion yet for this question.

Full 300-215 Practice