A security investigation revealed that malicious software was installed on a server using a server administrator's credentials. During the investigation, the server administrator explained that Telnet was regularly used to log in. Which of the following most likely occurred?
Choose an answer
Tap an option to check your answer.
Correct answer: A packet capture tool was used to steal the password..
Why this is the answer
Telnet transmits data, including login credentials, in plaintext. A packet capture tool (sniffer) on the network could easily intercept and read these unencrypted packets, revealing the server administrator's password. Once the attacker had the password, they could log in and install malware using legitimate credentials. A spraying attack attempts a few common passwords against many accounts, which is less likely to directly compromise a single administrator's unique password after they've already logged in. A remote-access Trojan (RAT) is a type of malware itself; while it could be used to install other malware, the question implies the initial compromise was to gain access to install the malware, not that a RAT was the initial compromise vector. A dictionary attack tries many common passwords against a single account; while possible, it's less direct than simply capturing a plaintext password already in transit.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed