Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

GIAC Exam GCCC Topic 8 Question 66 Discussion

Actual exam question for GIAC's GCCC exam
Question #: 66
Topic #: 8
[All GCCC Questions]

A breach was discovered after several customers reported fraudulent charges on their accounts. The attacker had exported customer logins and cracked passwords that were hashed but not salted. Customers were made to reset their passwords.

Shortly after the systems were cleaned and restored to service, it was discovered that a compromised system administrator's account was being used to give the attacker continued access to the network. Which CIS Control failed in the continued access to the network?

Show Suggested Answer Hide Answer
Suggested Answer: C

Contribute your Thoughts:

Artie
5 days ago
The answer is clearly B) Controlled Use of Administrative Privilege. The attacker gained continued access through a compromised admin account, so the organization failed to properly manage and restrict administrative privileges.
upvoted 0 times
...
Ty
19 days ago
I believe the answer is A) Maintenance, Monitoring, and Analysis of Audit Logs. If the logs were properly monitored, the suspicious activity could have been detected earlier.
upvoted 0 times
...
Ruthann
23 days ago
I agree with Filiberto. The compromised system administrator's account being used shows a lack of control over administrative privileges.
upvoted 0 times
...
Filiberto
25 days ago
I think the answer is B) Controlled Use of Administrative Privilege.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77