GCIH · Question #317
John is a malicious attacker. He illegally accesses the server of We-are-secure Inc. He then places a backdoor in the We-are-secure server and alters its log files. Which of the following steps of…
The correct answer is B. Covering tracks. In the malicious hacking methodology, covering tracks refers to any action taken to hide evidence of unauthorized access, including altering or deleting log files.
Question
John is a malicious attacker. He illegally accesses the server of We-are-secure Inc. He then places a backdoor in the We-are-secure server and alters its log files. Which of the following steps of malicious hacking includes altering the server log files?
Options
- AMaintaining access
- BCovering tracks
- CGaining access
- DReconnaissance
How the community answered
(26 responses)- B88% (23)
- C8% (2)
- D4% (1)
Why each option
In the malicious hacking methodology, covering tracks refers to any action taken to hide evidence of unauthorized access, including altering or deleting log files.
Maintaining access involves installing backdoors, rootkits, or Trojans to ensure continued entry into the system, not erasing evidence.
Covering tracks is the phase where an attacker removes or modifies evidence of their intrusion to avoid detection and forensic analysis. Altering server log files directly serves this purpose by erasing records of login events, commands executed, and files accessed. This step occurs after the attacker has already gained and maintained access, distinguishing it from the other phases.
Gaining access is the phase where vulnerabilities are exploited to initially compromise the target system.
Reconnaissance is the information-gathering phase conducted before any intrusion attempt, involving scanning and footprinting.
Concept tested: Malicious hacking phases - covering tracks
Source: https://www.eccouncil.org/cybersecurity-exchange/ethical-hacking/hacking-phases/
Topics
Community Discussion
No community discussion yet for this question.