GCIH · Question #378
As an incident handler for the xyz widget company, you have responded to the breach of your mail server. The server is not in a DMZ but on your internal network and was being used as a launching…
The correct answer is C. dd. The second sub phase is backup. Of the listed tools only dd can be used to create a backup of the compromised hard drive. Cain and Enum are tools used to attack systems and Wireshark is a network sniffer.
Question
As an incident handler for the xyz widget company, you have responded to the breach of your mail server. The server is not in a DMZ but on your internal network and was being used as a launching point to attack other systems on the same network. The compromise was discovered quickly and the network cable was disconnected from the mail server. Which of the following tools will allow you to complete the next sub phase, following short-term containment activities, on the server in its current state?
Options
- AWireshark
- BEnum
- Cdd
- DCain
How the community answered
(48 responses)- A6% (3)
- B10% (5)
- C81% (39)
- D2% (1)
Explanation
The second sub phase is backup. Of the listed tools only dd can be used to create a backup of the compromised hard drive. Cain and Enum are tools used to attack systems and Wireshark is a network sniffer.
Topics
Community Discussion
No community discussion yet for this question.