ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 285 - CS0-003 discussion

Report
Export

During normal security monitoring activities, the following activity was observed:

cd C:\Users\Documents\HR\Employees

takeown/f .*

SUCCESS:

Which of the following best describes the potentially malicious activity observed?

A.
Registry changes or anomalies
Answers
A.
Registry changes or anomalies
B.
Data exfiltration
Answers
B.
Data exfiltration
C.
Unauthorized privileges
Answers
C.
Unauthorized privileges
D.
File configuration changes
Answers
D.
File configuration changes
Suggested answer: C

Explanation:

The takeown command is used to take ownership of a file or folder that previously was denied access to the current user or group12. The activity observed indicates that someone has taken ownership of all files and folders under the C:\Users\Documents\HR\Employees directory, which may contain sensitive or confidential information. This could be a sign of unauthorized privileges, as the user or group may not have the legitimate right or need to access those files or folders. Taking ownership of files or folders could also enable the user or group to modify or delete them, which could affect the integrity or availability of the data.

asked 02/10/2024
karl hickey
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first