🔍

CompTIA SecurityX (CAS-005) CAS-005 — Question 202

Topic 1 · Question 202 of 393

Topic 1 · Question 202

A company recently experienced an incident in which an advanced threat actor was able to shim malicious code against the hardware stack of a domain controller. The forensic team cryptographically validated that both the underlying firmware of the box and the operating system had not been compromised. However, the attacker was able to exfiltrate information from the server using a steganographic technique within LDAP. Which of the following is the best way to reduce the risk of reoccurrence?

View community discussion →