CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 173: GCIH: GIAC Certified Incident Handler

You are a member of your organization's security team. A new ticket just came into your service desk and was escalated to you. One of the system administrators noticed the following entry in a Windows Server 2008 R2 file server Security event log:Log Name: Security -Source: Microsoft-Windows-Security-AuditingDate: 2/1…

Nội dung câu hỏi

You are a member of your organization's security team. A new ticket just came into your service desk and was escalated to you. One of the system administrators noticed the following entry in a Windows Server 2008 R2 file server Security event log:Log Name: Security -Source: Microsoft-Windows-Security-AuditingDate: 2/1/2012 2:24:07 AM -Event ID: 4674 -Task Category: Sensitive Privilege UseLevel: Information -Keywords: Audit Failure -User: N/A -Computer: somehost.somecompany.comDescription: An operation was attempted on a privileged object.Subject:Security ID: LOCAL SERVICE -Account Name: LOCAL SERVICE -Account Domain: NT AUTHORITY -Logon ID: 0x3e5 -Object:Object Server: LSA -Object Type: -Object Name: -Object Handle: 0x0 -Process Information:Process ID: 0x1d8 -Process Name: C:\Windows\System32\Isass.exeRequested Operation:Desired Access: 16777216 -Privileges: SeSecurityPrivilege -What is your next step?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Initiate the ג€Containmentג€ phase of the Incident Handling process — đáp án hiện tại
  2. B. Search Microsoft's TechNet to find out if this is a normal Windows Security event
  3. C. Disable the trusted account status of the Local Service account
  4. D. Request that all audit failure log entries be forwarded to you

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề