nerdexam
CompTIA

CAS-003 · Question #458

While investigating suspicious activity on a server, a security administrator runs the following report: In addition, the administrator notices changes to the /etc/shadow file that were not listed…

The correct answer is A. An attacker compromised the server and may have used a collision hash in the MD5 algorithm B. An attacker compromised the server and may have also compromised the file integrity. to hide the changes to the /etc/shadow file database to hide the changes to the /etc/shadow file

Enterprise Security Operations

Question

While investigating suspicious activity on a server, a security administrator runs the following report:

In addition, the administrator notices changes to the /etc/shadow file that were not listed in the report. Which of the following BEST describe this scenario? (Choose two.)

Options

  • AAn attacker compromised the server and may have used a collision hash in the MD5 algorithm
  • BAn attacker compromised the server and may have also compromised the file integrity
  • CAn attacker compromised the server and may have installed a rootkit to always generate valid
  • DAn attacker compromised the server and may have used MD5 collision hashes to generate valid
  • EAn attacker compromised the server and may have used SELinux mandatory access controls to

How the community answered

(27 responses)
  • A
    67% (18)
  • C
    19% (5)
  • D
    4% (1)
  • E
    11% (3)

Explanation

to hide the changes to the /etc/shadow file database to hide the changes to the /etc/shadow file

Topics

#rootkit#file integrity monitoring#MD5 collision#forensic analysis

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice