nerdexam
GIAC

GCIH · Question #43

Jason, a Malicious Hacker, is a student of Baker university. He wants to perform remote hacking on the server of DataSoft Inc. to hone his hacking skills. The company has a Windows-based network…

The correct answer is D. Jason did not perform covering tracks. Jason was caught because he failed to cover his tracks after the intrusion, leaving behind log files and Trojan artifacts that forensic investigators used to identify and attribute the attack. Covering tracks - clearing logs and removing evidence - is a critical step in…

Incident Response & Cyber Kill Chain

Question

Jason, a Malicious Hacker, is a student of Baker university. He wants to perform remote hacking on the server of DataSoft Inc. to hone his hacking skills. The company has a Windows-based network. Jason successfully enters the target system remotely by using the advantage of vulnerability. He places a Trojan to maintain future access and then disconnects the remote session. The employees of the company complain to Mark, who works as a Professional Ethical Hacker for DataSoft Inc., that some computers are very slow. Mark diagnoses the network and finds that some irrelevant log files and signs of Trojans are present on the computers. He suspects that a malicious hacker has accessed the network. Mark takes the help from Forensic Investigators and catches Jason. Which of the following mistakes made by Jason helped the Forensic Investigators catch him?

Options

  • AJason did not perform a vulnerability assessment.
  • BJason did not perform OS fingerprinting.
  • CJason did not perform foot printing.
  • DJason did not perform covering tracks.
  • EJason did not perform port scanning.

How the community answered

(64 responses)
  • A
    13% (8)
  • B
    2% (1)
  • C
    3% (2)
  • D
    77% (49)
  • E
    6% (4)

Why each option

Jason was caught because he failed to cover his tracks after the intrusion, leaving behind log files and Trojan artifacts that forensic investigators used to identify and attribute the attack. Covering tracks - clearing logs and removing evidence - is a critical step in avoiding post-intrusion detection.

AJason did not perform a vulnerability assessment.

Jason did perform vulnerability assessment implicitly - he identified and exploited a vulnerability to gain remote access, so this was not his mistake.

BJason did not perform OS fingerprinting.

OS fingerprinting is a reconnaissance step; the scenario shows Jason already knew it was a Windows-based network, so this was not the gap that led to his capture.

CJason did not perform foot printing.

Jason did perform some footprinting since he targeted a specific company and found an exploitable vulnerability, making this not the key mistake.

DJason did not perform covering tracks.Correct

Covering tracks involves deleting or modifying system logs, audit trails, and other forensic artifacts that could reveal an attacker's presence and identity. Jason left both log files and Trojan signatures on the compromised machines, which gave forensic investigators the direct evidence needed to detect, attribute, and prosecute the intrusion.

EJason did not perform port scanning.

Port scanning is part of reconnaissance; Jason successfully exploited the system, implying he had already identified open ports and services.

Concept tested: Covering tracks to avoid post-intrusion forensic detection

Source: https://www.eccouncil.org/cybersecurity-exchange/ethical-hacking/covering-tracks-in-ethical-hacking/

Topics

#covering tracks#cyber kill chain#post-exploitation#incident indicators

Community Discussion

No community discussion yet for this question.

Full GCIH Practice