PT0-003 · Question #78
During a security assessment, a penetration tester gains access to an internal server and manipulates some data to hide its presence. Which of the following is the best way for the penetration…
The correct answer is A. Clear the Windows event logs. Clearing the event logs can effectively remove traces of the tester's activities, making it difficult for the system administrators to detect what actions were performed. While modifying the system time, altering log permissions, or reducing log retention settings could…
Question
During a security assessment, a penetration tester gains access to an internal server and manipulates some data to hide its presence. Which of the following is the best way for the penetration tester to hide the activities performed?
Options
- AClear the Windows event logs.
- BModify the system time.
- CAlter the log permissions.
- DReduce the log retention settings.
How the community answered
(26 responses)- A69% (18)
- B19% (5)
- C8% (2)
- D4% (1)
Explanation
Clearing the event logs can effectively remove traces of the tester's activities, making it difficult for the system administrators to detect what actions were performed. While modifying the system time, altering log permissions, or reducing log retention settings could potentially obscure or reduce the logging of activities, they are less direct and can be more easily detected by system
Topics
Community Discussion
No community discussion yet for this question.