GIAC Certified Incident Handler GCIH Question # 31 Topic 3 Discussion

GIAC Certified Incident Handler GCIH Question # 31 Topic 3 Discussion

GCIH Exam Topic 3 Question 31 Discussion:
Question #: 31
Topic #: 3

Your IDS discovers that an intruder has gained access to your system. You immediately stop that access, change passwords for administrative accounts, and secure your network. You discover an odd account (not administrative) that has permission to remotely access the network. What is this most likely?


A.

An example of privilege escalation.


B.

A normal account you simply did not notice before. Large networks have a number of accounts; it is hard to track them all.


C.

A backdoor the intruder created so that he can re-enter the network.


D.

An example of IP spoofing.


Get Premium GCIH Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.