Which technique would a threat actor use to disguise traces of an ongoing exploit?
- Create an invisible iFrame on a web page.
- Corrupt time information by attacking the NTP infrastructure.
- Encapsulate other protocols within DNS to evade security measures.
- Use SSL to encapsulate malware.
Explanation: The Network Time Protocol (NTP) uses a hierarchy of time sources to provide a consistent time clock to network infrastructure devices. Threat actors may attack the NTP infrastructure in order to corrupt time information that is used in network logs.
Related exam: Modules 24 - 25: Protocols and Log Files Group Exam
Related exam: Network Defense - Checkpoint Exam: Evaluating Security Alerts Answers
Related exam: Cybersecurity Essentials - Checkpoint Exam: Evaluating Security Alerts (Module 19 – 21 Exam)
