100-160 exam dumps

100-160 practice question 120 of 265

Cisco Certified Support Technician (CCST) Cybersecurity. Associate level, Cisco. Free question with the correct answer and a full explanation.

100-160 Question 120

Select 3

A company suspects that an attacker has gained unauthorized access to a Windows server by escalating privileges. As a cybersecurity technician, you are asked to investigate. Which of the following actions will best help you identify evidence of privilege escalation on the system?

  1. A

    Check the Event Viewer for logs of privilege escalation activities.

  2. B

    Analyze the local firewall rules configured in Windows Defender.

  3. C

    Inspect the file and directory permissions on critical system files.

  4. D

    Scan the system for unauthorized changes to user account privileges.

  5. E

    Use PowerShell to review the list of installed antivirus software.

Show answer and explanation

Correct answers: A, C, D

Explanation

Privilege escalation involves gaining higher-level access to a system, often by exploiting vulnerabilities or misconfigurations. To investigate, checking the Event Viewer for logs, inspecting file and directory permissions, and scanning for changes to user privileges are effective techniques. These methods provide critical evidence of unauthorized access or modifications to the system that could indicate privilege escalation.

  • A. Correct.

    Checking the Event Viewer can help you identify suspicious activities such as privilege escalation attempts by reviewing security logs.

  • B. Incorrect.

    Analyzing local firewall rules is not directly related to detecting privilege escalation, though it may reveal other suspicious network activities.

  • C. Correct.

    Inspecting file and directory permissions on system files can reveal unauthorized changes that indicate privilege escalation.

  • D. Correct.

    Scanning for unauthorized changes to user account privileges is a direct method to identify signs of privilege escalation.

  • E. Incorrect.

    Using PowerShell to review antivirus software may provide insight into system protections but does not help identify privilege escalation evidence.

Timed practice exam

Take a 100-160 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam