Answered step by step
Verified Expert Solution
Link Copied!

Question

1 Approved Answer

A security analyst is investigating an incident to determine what an attacker was able to do on a compromised laptop. The analyst reviews the following

A security analyst is investigating an incident to determine what an attacker was able to do on a compromised laptop. The analyst reviews the following SIEM log:
\table[[Host,Event ID,Event source,Description],[PC1,865,\table[[Microsoft-windows-],[SoftwareRestrictionpolicies]],\table[[C: \asdf 234?? asdf 234,exe],[was blocked by Group],[policy]]],[PC1,4608,\table[[Microsoft-Windows-Security-],[Auditing]],\table[[A new process has been],[created.],[New Process],[Name:powershell.exe],[Creator Process],[Name: outlook.exe]]],[PC1,4688,\table[[Microsoft-windows-Security-],[Auditing]],\table[[A new process has been],[created.],[New Process Name:lat.psl],[Creator Process],[Name:powershell.exe]]],[PC2,4625,\table[[Microsoft-Windows-Security-],[Auditing]],\table[[An account failed to log],[on.],[LogonType: 3],[SecurityID:Null SID],[Workstation Name:PC1],[Authentication Package],[Name:NTLM]]]]
Which of the following describes the method that was used to compromise the laptop?
A. An attacker was able to move laterally from PC1 to PC2 using a pass-the-hash attack.
B. An attacker was able to bypass the application approve list by emailing a spreadsheet attachment with an embedded PowerShell in the file.
C. An attacker was able to install malware to the C:lasdif234 folder and use it to gain administrator rights and launch Outiook.
D. An attacker was able to phish user credentials successfully from an Outlook user proflle.
image text in transcribed

Step by Step Solution

There are 3 Steps involved in it

Step: 1

blur-text-image

Get Instant Access with AI-Powered Solutions

See step-by-step solutions with expert insights and AI powered tools for academic success

Step: 2

blur-text-image

Step: 3

blur-text-image

Ace Your Homework with AI

Get the answers you need in no time with our AI-driven, step-by-step assistance

Get Started

Students also viewed these Databases questions