List of questions
Related questions
Question 569 - 312-49v10 discussion
An attacker successfully gained access to a remote Windows system and plans to install persistent backdoors on it. Before that, to avoid getting detected in future, he wants to cover his tracks by disabling the last-accessed timestamps of the machine. What would he do to achieve this?
A.
Set the registry value ofHKLM\SYSTEM\CurrentControlSet\Control\FileSystem\NtfsDisableLastAccessUpdate to 0
B.
Run the command fsutil behavior set disablelastaccess 0
C.
Set the registry value ofHKLM\SYSTEM\CurrentControlSet\Control\FileSystem\NtfsDisableLastAccessUpdate to 1
D.
Run the command fsutil behavior set enablelastaccess 0
Your answer:
0 comments
Sorted by
Leave a comment first