CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 49: GCIH: GIAC Certified Incident Handler

An organization has an SSH server that was compromised, but later eradicated and recovered. The system disks were wiped clean, the OS reinstalled, and patches re-applied. After this process is complete, a security analyst noticed multiple simultaneous SSH logins from a single, valid, user-account on that system. Which…

Nội dung câu hỏi

An organization has an SSH server that was compromised, but later eradicated and recovered. The system disks were wiped clean, the OS reinstalled, and patches re-applied. After this process is complete, a security analyst noticed multiple simultaneous SSH logins from a single, valid, user-account on that system. Which of the following is the most likely explanation?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Proper action was not taken on the firewall or router to block SSH traffic
  2. B. An attacker is accessing the system through a backdoor using netcat
  3. C. Not all of the attackers artifacts have been removed from the system
  4. D. The SSH user account credentials have been compromised — đáp án hiện tại

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề