Mile2_Security
MK0-201 · Question #5
If an attacker gets Administrative-level access, why cant the entries in the Event log be trusted with certainty? Choose two.
See the full explanation below for the reasoning.
Question
If an attacker gets Administrative-level access, why cant the entries in the Event log be trusted with certainty? Choose two.
Options
- AEntries in the event log are not digitally signed
- BThe attacker may have been able to simply clear the event log, thus erasing evidence of the
- CTools like Winzapper allow the attacker to selectively delete log entries associated with the
- DEvent logs have NTFS permissions of Everyone Full Control and thus can be easily edited
Community Discussion
No community discussion yet for this question.