Mile2_Security
ML0-320 · Question #206
Keen administrators (the enemy of penetration testers)will take great steps in order to collect logs on different servers.By having a detailed log of activities they may be able to detect abnormal…
The correct answer is C. Auditpol. See the full explanation below for the reasoning.
Question
Keen administrators (the enemy of penetration testers)will take great steps in order to collect logs on different servers.By having a detailed log of activities they may be able to detect abnormal activities. A skilled intruder will attempt to modify the logging policy in order to prevent the administrator from having access to his detailed log. What command line tool could an attacker use to disable auditing on a Windows server?
Options
- ASyslog
- BEventlog
- CAuditpol
- DAuditlog
How the community answered
(43 responses)- A12% (5)
- B2% (1)
- C81% (35)
- D5% (2)
Community Discussion
No community discussion yet for this question.