nerdexam
GIAC

GCIH · Question #334

A host has been compromised with a rootkit through Internet activity. The analyst wishes to reconstruct the binary file used to infect the host. Which of the following sources of evidence is MOST…

The correct answer is D. Packet captures from a sensor at the network border. Since the host was infected over the network, packet captures are the most likely location to find the original binary. Alert logs and filesystem journals will retain metadata and not the actual

Malware Analysis & Advanced Persistent Threats

Question

A host has been compromised with a rootkit through Internet activity. The analyst wishes to reconstruct the binary file used to infect the host. Which of the following sources of evidence is MOST likely to produce the binary?

Options

  • AFilesystem journal entries from the compromised host
  • BAlert logs from an Intrusion detection device
  • CA memory image from a proxy server on the network
  • DPacket captures from a sensor at the network border

How the community answered

(52 responses)
  • A
    27% (14)
  • B
    10% (5)
  • C
    6% (3)
  • D
    58% (30)

Explanation

Since the host was infected over the network, packet captures are the most likely location to find the original binary. Alert logs and filesystem journals will retain metadata and not the actual

Topics

#rootkit forensics#binary reconstruction#packet capture#network evidence

Community Discussion

No community discussion yet for this question.

Full GCIH Practice