QuestionQ18

Incident Response Processes

Question Image

Refer to the exhibit. An employee observes unexpected changes and configuration modifications on their workstation and opens an incident ticket. A support specialist reviews processes and services but finds nothing suspicious. The ticket is escalated to an analyst, who reviews this event log and also finds that the workstation has multiple large data dumps on network shares. What should be determined from this information?

  • A data obfuscation
  • B reconnaissance attack
  • C brute-force attack
  • D log tampering
Explanation

Windows Eventlog Event ID 104 indicates that an event log was cleared. Clearing system logs can remove forensic evidence and is therefore an indicator of log tampering. Microsoft documents that clearing an event log deletes its entries.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!