nerdexam
CompTIA

PT0-003 · Question #78

During a security assessment, a penetration tester gains access to an internal server and manipulates some data to hide its presence. Which of the following is the best way for the penetration…

The correct answer is A. Clear the Windows event logs. Clearing the event logs can effectively remove traces of the tester's activities, making it difficult for the system administrators to detect what actions were performed. While modifying the system time, altering log permissions, or reducing log retention settings could…

Submitted by certguy· Mar 6, 2026Post-exploitation and Lateral Movement

Question

During a security assessment, a penetration tester gains access to an internal server and manipulates some data to hide its presence. Which of the following is the best way for the penetration tester to hide the activities performed?

Options

  • AClear the Windows event logs.
  • BModify the system time.
  • CAlter the log permissions.
  • DReduce the log retention settings.

How the community answered

(26 responses)
  • A
    69% (18)
  • B
    19% (5)
  • C
    8% (2)
  • D
    4% (1)

Explanation

Clearing the event logs can effectively remove traces of the tester's activities, making it difficult for the system administrators to detect what actions were performed. While modifying the system time, altering log permissions, or reducing log retention settings could potentially obscure or reduce the logging of activities, they are less direct and can be more easily detected by system

Topics

#anti-forensics#log clearing#post-exploitation

Community Discussion

No community discussion yet for this question.

Full PT0-003 Practice