Suspecting the syst...
 
Notifications
Clear all

Suspecting the system may be compromised, the analyst runs the following commands:

1 Posts
1 Users
0 Likes
66 Views
(@siwekphilip)
Posts: 730
Noble Member
Topic starter
 

A security analyst has received reports of very slow, intermittent access to a public-facing corporate server.

Suspecting the system may be compromised, the analyst runs the following commands:

Based on the output from the above commands, which of the following should the analyst do NEXT to further the investigation?

  • A . Run crontab -r; rm -rf /tmp/.t to remove and disable the malware on the system.
    B. Examine the server logs for further indicators of compromise of a web application.
    C. Run kill -9 1325 to bring the load average down so the server is usable again.
    D. Perform a binary analysis on the /tmp/.t/t file, as it is likely to be a rogue SSHD server.

Show Answer Hide Answer

Suggested Answer: B
 
Posted : 05/01/2023 3:25 pm
Topic Tags

Latest CS0-002 V2 Dumps Valid Version

Latest And Valid Q&A | Instant Download | Once Fail, Full Refund
Share: