CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 68: CAS-003: CompTIA Advanced Security Practitioner (CASP) CAS-003

While investigating suspicious activity on a server, a security administrator runs the following report: In addition, the administrator notices changes to the /etc/shadow file that were not listed in the report. Which of the following BEST describe this scenario?(Choose two.)

Nội dung câu hỏi

While investigating suspicious activity on a server, a security administrator runs the following report: In addition, the administrator notices changes to the /etc/shadow file that were not listed in the report. Which of the following BEST describe this scenario?(Choose two.)

Minh họa câu hỏi

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. An attacker compromised the server and may have used a collision hash in the MD5 algorithm to hide the changes to the /etc/shadow file — đáp án hiện tại
  2. B. An attacker compromised the server and may have also compromised the file integrity database to hide the changes to the /etc/shadow file — đáp án hiện tại
  3. C. An attacker compromised the server and may have installed a rootkit to always generate valid MD5 hashes to hide the changes to the /etc/shadow file
  4. D. An attacker compromised the server and may have used MD5 collision hashes to generate valid passwords, allowing further access to administrator accounts on the server
  5. E. An attacker compromised the server and may have used SELinux mandatory access controls to hide the changes to the /etc/shadow file

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề