nerdexam
Mile2_Security

MK0-201 · Question #5

If an attacker gets Administrative-level access, why cant the entries in the Event log be trusted with certainty? Choose two.

See the full explanation below for the reasoning.

Question

If an attacker gets Administrative-level access, why cant the entries in the Event log be trusted with certainty? Choose two.

Options

  • AEntries in the event log are not digitally signed
  • BThe attacker may have been able to simply clear the event log, thus erasing evidence of the
  • CTools like Winzapper allow the attacker to selectively delete log entries associated with the
  • DEvent logs have NTFS permissions of Everyone Full Control and thus can be easily edited

Community Discussion

No community discussion yet for this question.

Full MK0-201 Practice