Câu 49: GCIH: GIAC Certified Incident Handler
An organization has an SSH server that was compromised, but later eradicated and recovered. The system disks were wiped clean, the OS reinstalled, and patches re-applied. After this process is complete, a security analyst noticed multiple simultaneous SSH logins from a single, valid, user-account on that system. Which…
Nội dung câu hỏi
An organization has an SSH server that was compromised, but later eradicated and recovered. The system disks were wiped clean, the OS reinstalled, and patches re-applied. After this process is complete, a security analyst noticed multiple simultaneous SSH logins from a single, valid, user-account on that system. Which of the following is the most likely explanation?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. Proper action was not taken on the firewall or router to block SSH traffic
- B. An attacker is accessing the system through a backdoor using netcat
- C. Not all of the attackers artifacts have been removed from the system
- D. The SSH user account credentials have been compromised — đáp án hiện tại
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.