nerdexam
Mile2_Security

ML0-320 · Question #173

If an attacker gets Adminsitrative-level access, why cant the entries in the Event log be trusted with certainty? Choose two.

The correct answer is B. The attacker may have been able to simply clear the event log, thus erasing evidence of the C. Tools like Winzapper allow the attacker to selectively delete log entries associated with the initial. See the full explanation below for the reasoning.

Question

If an attacker gets Adminsitrative-level access, why cant the entries in the Event log be trusted with certainty? Choose two.

Options

  • AEntries in the event log are not digitally signed
  • BThe attacker may have been able to simply clear the event log, thus erasing evidence of the
  • CTools like Winzapper allow the attacker to selectively delete log entries associated with the initial
  • DEvent logs have NTFS permissions of Everyone Full Control and thus can be easily edited.

How the community answered

(65 responses)
  • A
    14% (9)
  • B
    80% (52)
  • D
    6% (4)

Community Discussion

No community discussion yet for this question.

Full ML0-320 Practice