I love how the question is trying to trick us with those answer choices. Gotta stay on our toes for these tricky certification exams, am I right? *chuckles*
Definitely not E! Logging in normally to the admin page is not an 'attack' per se. The logs point to more sophisticated attempts to compromise the system.
D looks promising too. The file manager plugin could have been used to upload the r57.php shell. But I agree B and C are the best choices based on the information provided.
I think the correct answers are B and C. The access logs show clear signs of a WordPress attack, including attempted SQL injection and uploading of a malicious file.
Lynda
3 days agoAllene
7 days agoRyan
11 days agoCarmela
13 days agoSelma
20 days agoDalene
22 days agoRosamond
24 days ago