Câu 173: GCIH: GIAC Certified Incident Handler
You are a member of your organization's security team. A new ticket just came into your service desk and was escalated to you. One of the system administrators noticed the following entry in a Windows Server 2008 R2 file server Security event log:Log Name: Security -Source: Microsoft-Windows-Security-AuditingDate: 2/1…
Nội dung câu hỏi
You are a member of your organization's security team. A new ticket just came into your service desk and was escalated to you. One of the system administrators noticed the following entry in a Windows Server 2008 R2 file server Security event log:Log Name: Security -Source: Microsoft-Windows-Security-AuditingDate: 2/1/2012 2:24:07 AM -Event ID: 4674 -Task Category: Sensitive Privilege UseLevel: Information -Keywords: Audit Failure -User: N/A -Computer: somehost.somecompany.comDescription: An operation was attempted on a privileged object.Subject:Security ID: LOCAL SERVICE -Account Name: LOCAL SERVICE -Account Domain: NT AUTHORITY -Logon ID: 0x3e5 -Object:Object Server: LSA -Object Type: -Object Name: -Object Handle: 0x0 -Process Information:Process ID: 0x1d8 -Process Name: C:\Windows\System32\Isass.exeRequested Operation:Desired Access: 16777216 -Privileges: SeSecurityPrivilege -What is your next step?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. Initiate the ג€Containmentג€ phase of the Incident Handling process — đáp án hiện tại
- B. Search Microsoft's TechNet to find out if this is a normal Windows Security event
- C. Disable the trusted account status of the Local Service account
- D. Request that all audit failure log entries be forwarded to you
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.