ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 158 - CV0-004 discussion

Report
Export

The company's IDS has reported an anomaly. The cloud engineer remotely accesses the cloud instance, runs a command, and receives the following information:

Which of the following is the most likely root cause of this anomaly?

A.
Privilege escalation
Answers
A.
Privilege escalation
B.
Leaked credentials
Answers
B.
Leaked credentials
C.
Cryptojacking
Answers
C.
Cryptojacking
D.
Defaced website
Answers
D.
Defaced website
Suggested answer: A

Explanation:

The output from the 'ps' command indicates there is a process running under the UID (User ID) of 0, which is the root user, and the command that was run is '/var/www/command.py'. Given that the normal Apache processes are running under their own UID (65535), this suggests that a command was executed with root privileges that typically should not have such high-level access. This is a strong indicator of privilege escalation, where an unauthorized user or process gains elevated access to resources that are normally protected from an application or user.

Reference: CompTIA Cloud+ Certification Study Guide (Exam CV0-004) by Scott Wilson and Eric Vanderburg

asked 02/10/2024
evalson martin laplap
49 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first