QuestionQ19
Security OperationsA SOC analyst is investigating an incident in which a penetration tester successfully created and executed a payload. The analyst retrieves the following command history from the impacted server:
$ uname -a && env
$ vim foo.c
$ gcc foo.c /tmp/lockfile
$ chmod +x /tmp/lockfile
$ ./tmp/lockfile
Which of the following should the analyst implement to enhance the server's security?
Community Discussion