nerdexam
GIAC

GCIH · Question #329

Logs show that a malicious host has remotely accessed the file 'Documents and Settings:logs'. At what step of the attack process is the attacker most likely operating in?

The correct answer is E. Covering tracks. To Cover their Tracks, attackers can create additional streams associated with any file or directory name on the system. The attacker can then use these streams to hide their sensitive information, such as attack tools or sniffer logs. The attacker accessing an alternate data…

Incident Response & Cyber Kill Chain

Question

Logs show that a malicious host has remotely accessed the file 'Documents and Settings:logs'. At what step of the attack process is the attacker most likely operating in?

Options

  • AEstablishing a backdoor
  • BUsing steganography
  • CInitial reconnaissance
  • DPort scanning
  • ECovering tracks

How the community answered

(62 responses)
  • B
    5% (3)
  • C
    3% (2)
  • D
    2% (1)
  • E
    90% (56)

Explanation

To Cover their Tracks, attackers can create additional streams associated with any file or directory name on the system. The attacker can then use these streams to hide their sensitive information, such as attack tools or sniffer logs. The attacker accessing an alternate data stream named logs that is attached to the directory "Documents and Settings" indicates the attacker is trying to conceal activities.

Topics

#covering tracks#log tampering#cyber kill chain#post-exploitation

Community Discussion

No community discussion yet for this question.

Full GCIH Practice