QuestionQ13

Threat Hunting Techniques

Refer to the exhibit.

Question Image

The SOC lead received the scope for a penetration test performed against the company's assets during the last 4 hours. The documentation does not appear to include an authorized IP address range, and the testing company may perform only a surface-level scan and database probing. While SOC analysts review server logs to determine whether recent activity indicates an authorized penetration test or a possible attack, the team discovers several suspicious entries.

Which two log entries indicate a potentially successful unauthorized attack?

Choose two
Explanation

A successful request to a CGI endpoint with cmd=cat+/etc/passwd indicates command execution and access to a sensitive system file, neither of which is authorized by a surface-scan-and-database-probing scope. A successful POST to an upload endpoint can indicate that content was accepted or uploaded; file upload is also outside that authorized scope. Database probing and surface-level scanning can be consistent with the permitted penetration-test activities.

Community Discussion

No comments yet. Be the first to start the discussion!