QuestionQ52

Threat Hunting Outcomes

Refer to the exhibit.

Question Image

A cybersecurity team receives an Intrusion Prevention System alert about multiple file changes on a file server. Before those changes, the team detected a successful remote sign-in to the server from a user account.

Which type of threat occurred?

Explanation

A remote sign-in followed by unauthorized alteration or deletion of server files is an intrusion: access and actions were performed without evidence of approved testing authority. A penetration test requires defined authorization and constraints; black-box and white-box classifications instead describe how much information an authorized tester has about the target.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!