ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 569 - 312-49v10 discussion

Report
Export

An attacker successfully gained access to a remote Windows system and plans to install persistent backdoors on it. Before that, to avoid getting detected in future, he wants to cover his tracks by disabling the last-accessed timestamps of the machine. What would he do to achieve this?

A.
Set the registry value ofHKLM\SYSTEM\CurrentControlSet\Control\FileSystem\NtfsDisableLastAccessUpdate to 0
Answers
A.
Set the registry value ofHKLM\SYSTEM\CurrentControlSet\Control\FileSystem\NtfsDisableLastAccessUpdate to 0
B.
Run the command fsutil behavior set disablelastaccess 0
Answers
B.
Run the command fsutil behavior set disablelastaccess 0
C.
Set the registry value ofHKLM\SYSTEM\CurrentControlSet\Control\FileSystem\NtfsDisableLastAccessUpdate to 1
Answers
C.
Set the registry value ofHKLM\SYSTEM\CurrentControlSet\Control\FileSystem\NtfsDisableLastAccessUpdate to 1
D.
Run the command fsutil behavior set enablelastaccess 0
Answers
D.
Run the command fsutil behavior set enablelastaccess 0
Suggested answer: C
asked 18/09/2024
Ramzi Smair
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first