Mile2_Security
ML0-320 · Question #173
If an attacker gets Adminsitrative-level access, why cant the entries in the Event log be trusted with certainty? Choose two.
The correct answer is B. The attacker may have been able to simply clear the event log, thus erasing evidence of the C. Tools like Winzapper allow the attacker to selectively delete log entries associated with the initial. See the full explanation below for the reasoning.
Question
If an attacker gets Adminsitrative-level access, why cant the entries in the Event log be trusted with certainty? Choose two.
Options
- AEntries in the event log are not digitally signed
- BThe attacker may have been able to simply clear the event log, thus erasing evidence of the
- CTools like Winzapper allow the attacker to selectively delete log entries associated with the initial
- DEvent logs have NTFS permissions of Everyone Full Control and thus can be easily edited.
How the community answered
(65 responses)- A14% (9)
- B80% (52)
- D6% (4)
Community Discussion
No community discussion yet for this question.