nerdexam
Cisco

350-201 · Question #107

Refer to the exhibit. An engineer received multiple reports from employees unable to log into systems with the error: The Group Policy Client service failed to logon ?Access is denied. Through…

The correct answer is C. elevation of privileges. The combination of 'Group Policy Client service failed to logon - Access is denied' errors and unexpected system setting modifications indicates an attacker has escalated privileges to alter security policy configurations.

Host-Based Analysis

Question

Refer to the exhibit. An engineer received multiple reports from employees unable to log into systems with the error: The Group Policy Client service failed to logon ?Access is denied. Through further analysis, the engineer discovered several unexpected modifications to system settings. Which type of breach is occurring?

Exhibit

350-201 question #107 exhibit

Options

  • Amalware break
  • Bdata theft
  • Celevation of privileges
  • Ddenial-of-service

How the community answered

(17 responses)
  • A
    12% (2)
  • C
    82% (14)
  • D
    6% (1)

Why each option

The combination of 'Group Policy Client service failed to logon - Access is denied' errors and unexpected system setting modifications indicates an attacker has escalated privileges to alter security policy configurations.

Amalware break

A malware break describes general malware-induced system disruption and does not account for the specific pattern of Group Policy tampering and deliberate access control changes seen here.

Bdata theft

Data theft focuses on unauthorized exfiltration of information, whereas the observed symptoms involve manipulation of authentication and authorization policies, not data removal.

Celevation of privilegesCorrect

Elevation of privileges occurs when an attacker acquires access rights beyond what was originally granted, enabling them to modify protected system configurations such as Group Policy objects. The 'Access is denied' error for legitimate users paired with unauthorized system setting changes is a hallmark indicator that an attacker elevated their privileges to manipulate Group Policy, effectively locking out normal accounts.

Ddenial-of-service

Denial-of-service attacks make resources unavailable through flooding or resource exhaustion, not through privilege escalation and targeted Group Policy modifications.

Concept tested: Identifying privilege escalation via Group Policy modification

Source: https://attack.mitre.org/tactics/TA0004/

Topics

#elevation of privileges#Group Policy#unauthorized system modifications#breach classification

Community Discussion

No community discussion yet for this question.

Full 350-201 Practice