The company's IDS has reported an anomaly. The cloud engineer remotely accesses the cloud instance, runs a command, and receives the following information:
Which of the following is the most likely root cause of this anomaly?
The output from the 'ps' command indicates there is a process running under the UID (User ID) of 0, which is the root user, and the command that was run is '/var/www/command.py'. Given that the normal Apache processes are running under their own UID (65535), this suggests that a command was executed with root privileges that typically should not have such high-level access. This is a strong indicator of privilege escalation, where an unauthorized user or process gains elevated access to resources that are normally protected from an application or user. Reference: CompTIA Cloud+ Certification Study Guide (Exam CV0-004) by Scott Wilson and Eric Vanderburg
Antonio
10 months agoTarra
10 months agoDeonna
10 months agoDenise
9 months agoRobt
9 months agoNu
10 months agoCarline
10 months agoTawna
10 months agoGiuseppe
10 months agoElise
11 months agoSherita
11 months agoElizabeth
11 months agoMila
11 months agoJamie
11 months agoAbel
10 months agoIsidra
10 months agoDawne
10 months agoTorie
11 months agoChantay
10 months agoRosamond
10 months agoKristel
10 months agoEmerson
10 months ago