The company's IDS has reported an anomaly. The cloud engineer remotely accesses the cloud instance, runs a command, and receives the following information:
Which of the following is the most likely root cause of this anomaly?
The output from the 'ps' command indicates there is a process running under the UID (User ID) of 0, which is the root user, and the command that was run is '/var/www/command.py'. Given that the normal Apache processes are running under their own UID (65535), this suggests that a command was executed with root privileges that typically should not have such high-level access. This is a strong indicator of privilege escalation, where an unauthorized user or process gains elevated access to resources that are normally protected from an application or user. Reference: CompTIA Cloud+ Certification Study Guide (Exam CV0-004) by Scott Wilson and Eric Vanderburg
Antonio
7 months agoTarra
7 months agoDeonna
7 months agoDenise
6 months agoRobt
6 months agoNu
6 months agoCarline
6 months agoTawna
7 months agoGiuseppe
7 months agoElise
7 months agoSherita
7 months agoElizabeth
7 months agoMila
8 months agoJamie
8 months agoAbel
7 months agoIsidra
7 months agoDawne
7 months agoTorie
8 months agoChantay
7 months agoRosamond
7 months agoKristel
7 months agoEmerson
7 months ago