Câu 25: 312-39V2: Certified SOC Analyst (CSA) v2
A SOC analyst receives an alert indicating that the system time on a critical Windows server was changed at 3:00 AM. There are no scheduled maintenance tasks at this time. Unauthorized time changes can be used to evade security controls, such as altering timestamps to obscure malicious activity. The analyst must ident…
Nội dung câu hỏi
A SOC analyst receives an alert indicating that the system time on a critical Windows server was changed at 3:00 AM. There are no scheduled maintenance tasks at this time. Unauthorized time changes can be used to evade security controls, such as altering timestamps to obscure malicious activity. The analyst must identify the relevant event codes that log system time modifications and related suspicious behavior. Which of the following Windows Security Event Codes should the analyst review to investigate potential tampering?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. 4625 and 4634
- B. 4616 and 4618 — đáp án hiện tại
- C. 4616 and 4624
- D. 4608 and 4609
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.