300-215 exam dumps

300-215 practice question 19 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 19

Select 3

An attacker has compromised a server within your organization and is using antiforensic tactics to evade detection. During your forensic analysis, you observe that certain log files have been deleted, timestamps on files have been altered, and encryption has been applied to key files on the server. Which of the following antiforensic tactics, techniques, and procedures are being used by the attacker?

  1. A

    Log file manipulation

  2. B

    Timestamp alteration

  3. C

    Data obfuscation through encryption

  4. D

    Privilege escalation

  5. E

    Network segmentation

Show answer and explanation

Correct answers: A, B, C

Explanation

The attacker is employing multiple antiforensic tactics to evade detection, including log file manipulation (deleting logs), timestamp alteration (modifying file metadata), and encryption (obfuscating data). These techniques make forensic analysis more challenging by removing evidence, misleading investigators, and rendering data inaccessible.

  • A. Correct.

    Log file manipulation is a common antiforensic tactic where attackers delete or modify logs to hide their activities, matching the scenario described.

  • B. Correct.

    Timestamp alteration is a technique used to modify file metadata, such as creation or modification dates, to mislead forensic investigators or hide traces of the attack.

  • C. Correct.

    Data obfuscation through encryption is a method where attackers encrypt files to prevent forensic analysts from accessing the data, which aligns with the scenario.

  • D. Incorrect.

    Privilege escalation refers to gaining higher-level access to a system, which is not directly related to antiforensic tactics in this context.

  • E. Incorrect.

    Network segmentation is a defensive security measure to limit the spread of attacks and is not an antiforensic tactic used by attackers.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam