350-201 · Question #107
Refer to the exhibit. An engineer received multiple reports from employees unable to log into systems with the error: The Group Policy Client service failed to logon ?Access is denied. Through…
The correct answer is C. elevation of privileges. The combination of 'Group Policy Client service failed to logon - Access is denied' errors and unexpected system setting modifications indicates an attacker has escalated privileges to alter security policy configurations.
Question
Refer to the exhibit. An engineer received multiple reports from employees unable to log into systems with the error: The Group Policy Client service failed to logon ?Access is denied. Through further analysis, the engineer discovered several unexpected modifications to system settings. Which type of breach is occurring?
Exhibit
Options
- Amalware break
- Bdata theft
- Celevation of privileges
- Ddenial-of-service
How the community answered
(17 responses)- A12% (2)
- C82% (14)
- D6% (1)
Why each option
The combination of 'Group Policy Client service failed to logon - Access is denied' errors and unexpected system setting modifications indicates an attacker has escalated privileges to alter security policy configurations.
A malware break describes general malware-induced system disruption and does not account for the specific pattern of Group Policy tampering and deliberate access control changes seen here.
Data theft focuses on unauthorized exfiltration of information, whereas the observed symptoms involve manipulation of authentication and authorization policies, not data removal.
Elevation of privileges occurs when an attacker acquires access rights beyond what was originally granted, enabling them to modify protected system configurations such as Group Policy objects. The 'Access is denied' error for legitimate users paired with unauthorized system setting changes is a hallmark indicator that an attacker elevated their privileges to manipulate Group Policy, effectively locking out normal accounts.
Denial-of-service attacks make resources unavailable through flooding or resource exhaustion, not through privilege escalation and targeted Group Policy modifications.
Concept tested: Identifying privilege escalation via Group Policy modification
Source: https://attack.mitre.org/tactics/TA0004/
Topics
Community Discussion
No community discussion yet for this question.
