nerdexam
Cisco

350-201(NEW-127Q) · Question #50

A SIEM tool triggers an alert event due to multiple failed login attempts. The same user tried to access multiple servers within 10 minutes. Further analysis showed a specific workstation, which…

The correct answer is D. unexplained system modifications. Unexplained system modifications (D) are the hallmark indicator of a privilege escalation attack because an attacker who successfully elevates privileges must make changes - to registry keys, user accounts, scheduled tasks, or system configurations - to maintain that elevated…

Threat Detection and Response

Question

A SIEM tool triggers an alert event due to multiple failed login attempts. The same user tried to access multiple servers within 10 minutes. Further analysis showed a specific workstation, which indicates lateral movement behaviors within the network. The engineer must identify and detect the potential elevation of privilege attack. Which potential indicators must an engineer look for to detect compromised systems?

Options

  • Afailed login attempts during the last 7 days
  • Busers working or logging in outside of business hours
  • Cincreased activity on typically used ports
  • Dunexplained system modifications

How the community answered

(50 responses)
  • A
    2% (1)
  • B
    6% (3)
  • C
    8% (4)
  • D
    84% (42)

Explanation

Unexplained system modifications (D) are the hallmark indicator of a privilege escalation attack because an attacker who successfully elevates privileges must make changes - to registry keys, user accounts, scheduled tasks, or system configurations - to maintain that elevated access. These changes have no corresponding authorized change request, making them "unexplained" and directly traceable to compromise.

Why the distractors fall short:

  • (A) Failed logins over 7 days - already captured in the initial alert trigger; it describes the entry attempt, not a sign that privilege escalation succeeded
  • (B) Logins outside business hours - flags anomalous timing, which is useful for detecting initial access or insider threats, but doesn't specifically indicate privilege elevation
  • (C) Increased activity on typical ports - typical ports mean expected traffic, which is the opposite of a red flag; lateral movement and escalation more often abuse unusual ports or protocols

Memory tip: Think "escalation = modification." An attacker who climbs the privilege ladder has to nail new rungs in place - those nails are unexplained system changes. If something was modified with no ticket, no owner, and no reason, someone was there who shouldn't have been.

Topics

#Privilege Escalation Detection#System Compromise Indicators#Lateral Movement#Incident Response

Community Discussion

No community discussion yet for this question.

Full 350-201(NEW-127Q) Practice