CompTIA
CAS-003 · Question #458
While investigating suspicious activity on a server, a security administrator runs the following report: In addition, the administrator notices changes to the /etc/shadow file that were not listed…
The correct answer is A. An attacker compromised the server and may have used a collision hash in the MD5 algorithm B. An attacker compromised the server and may have also compromised the file integrity. to hide the changes to the /etc/shadow file database to hide the changes to the /etc/shadow file
Enterprise Security Operations
Question
While investigating suspicious activity on a server, a security administrator runs the following report:
In addition, the administrator notices changes to the /etc/shadow file that were not listed in the report. Which of the following BEST describe this scenario? (Choose two.)
Options
- AAn attacker compromised the server and may have used a collision hash in the MD5 algorithm
- BAn attacker compromised the server and may have also compromised the file integrity
- CAn attacker compromised the server and may have installed a rootkit to always generate valid
- DAn attacker compromised the server and may have used MD5 collision hashes to generate valid
- EAn attacker compromised the server and may have used SELinux mandatory access controls to
How the community answered
(27 responses)- A67% (18)
- C19% (5)
- D4% (1)
- E11% (3)
Explanation
to hide the changes to the /etc/shadow file database to hide the changes to the /etc/shadow file
Topics
#rootkit#file integrity monitoring#MD5 collision#forensic analysis
Community Discussion
No community discussion yet for this question.