nerdexam
CompTIA

PT0-003 · Question #311

A tester compromises a shared host that is manually audited every week due to the absence of a SIEM. Which of the following is the best way to reduce the chances of being detected? Modify files…

The correct answer is C. Perform commands under one of the developer accounts. Operating under an account that normally performs administrative or development activity helps actions blend into expected user behavior and reduces the likelihood that weekly manual reviews will flag the activity as anomalous.

Submitted by andreas_gr· Mar 6, 2026Post-exploitation and Lateral Movement

Question

A tester compromises a shared host that is manually audited every week due to the absence of a SIEM. Which of the following is the best way to reduce the chances of being detected? Modify files located in the directory.

Options

  • A/var/log
  • BUse the clear command to remove recent terminal activity.
  • CPerform commands under one of the developer accounts.
  • DDisable all logging services on the host.

How the community answered

(40 responses)
  • A
    8% (3)
  • B
    3% (1)
  • C
    73% (29)
  • D
    18% (7)

Explanation

Operating under an account that normally performs administrative or development activity helps actions blend into expected user behavior and reduces the likelihood that weekly manual reviews will flag the activity as anomalous.

Topics

#evasion#log tampering#anti-forensics#post-exploitation

Community Discussion

No community discussion yet for this question.

Full PT0-003 Practice