CAS-003 · Question #465
A government contractor was the victim of a malicious attack that resulted in the theft of sensitive information. An analyst's subsequent investigation of sensitive systems led to the following…
The correct answer is D. After successfully using a watering hole attack to deliver an exploit to a machine, which belongs. A watering hole attack (D) is the most likely explanation given all four conditions: no credential compromise, no anomalous database activity, fully patched systems, and no insider involvement. In a watering hole attack, the adversary compromises a website or online resource…
Question
A government contractor was the victim of a malicious attack that resulted in the theft of sensitive information. An analyst's subsequent investigation of sensitive systems led to the following discoveries:
- There was no indication of the data owner's or user's accounts being
compromised.
- No database activity outside of previous baselines was discovered.
- All workstations and servers were fully patched for all known
vulnerabilities at the time of the attack.
- It was likely not an insider threat, as all employees passed
polygraph tests. Given this scenario, which of the following is the MOST likely attack that occurred?
Options
- AThe attacker harvested the hashed credentials of an account within the database administrators
- BAn account, which belongs to an administrator of virtualization infrastructure, was compromised
- CA shared workstation was physically accessible in a common area of the contractor's office space
- DAfter successfully using a watering hole attack to deliver an exploit to a machine, which belongs
How the community answered
(65 responses)- A9% (6)
- B15% (10)
- C28% (18)
- D48% (31)
Explanation
A watering hole attack (D) is the most likely explanation given all four conditions: no credential compromise, no anomalous database activity, fully patched systems, and no insider involvement. In a watering hole attack, the adversary compromises a website or online resource that targeted employees frequently visit, then delivers a browser or application exploit to their machines. If the exploit leveraged a zero-day vulnerability, it would bypass all current patches. The malware would operate within the victim's normal user context, generating no unusual database queries and requiring no credential theft. This accounts for why all traditional detection indicators were clean. Credential harvesting (A), virtualization compromise (B), and physical workstation access (C) are all contradicted by at least one of the stated findings.
Topics
Community Discussion
No community discussion yet for this question.