41 questions in this subject. The stream loops continuously.
Question 16 of 84
Medium difficultyThis system was recently patched following the exploitation of a vulnerability by an attacker to enable data exfiltration.
Despite the vulnerability being patched, it is likely that a malicious TCP service is still running and the adversary has achieved persistence by creating a systemd service.
Using the following credentials: Username: labadmin; Password: Passw0rd!. Investigate to identify indicators of compromise and then remediate them. You will need to make at least two changes. End the compromised process that is using a malicious TCP service. Remove the malicious persistence agent by disabling the service's ability to start on boot. Do not disable ssh or systemd, alter network adapter 172.162.0.0, or change the password in the labadmin account. These changes cause the virtual environment to fail and prevent proper scoring. Once you have completed the item in the virtual environment, you will not be allowed to return to this item.
Using the following credentials: Username: labadmin; Password: Passw0rd!. Investigate to identify indicators of compromise and then remediate them. You will need to make at least two changes. End the compromised process that is using a malicious TCP service. Remove the malicious persistence agent by disabling the service's ability to start on boot. Do not disable ssh or systemd, alter network adapter 172.162.0.0, or change the password in the labadmin account. These changes cause the virtual environment to fail and prevent proper scoring. Once you have completed the item in the virtual environment, you will not be allowed to return to this item.
0 characters · 0 lines
Loading discussion