Courseiva
hardMultiple ChoiceObjective-mapped

SSCP Practice Question: Has suffered a sophisticated attack where the…

An organization has suffered a sophisticated attack where the attacker compromised a domain controller and used it to move laterally to several file servers. The incident response team has isolated the domain controller and some file servers, but they suspect that the attacker may have created hidden accounts and modified permissions to maintain access. The team needs to ensure that the attacker's access is entirely removed before restoring operations. The organization has a large number of users and complex Active Directory structure. The incident response plan outlines containment, eradication, recovery, and post-incident analysis. The team has forensic imaging of the domain controller and file servers. What is the MOST comprehensive approach to eradicate the attacker's presence?

⚠ Common exam trap

Candidates often choose password resets or backup restoration as a quick fix, but fail to recognize that sophisticated attackers implant multiple persistence mechanisms (e.g., hidden accounts, modified ACLs, domain-level backdoors) that survive these actions without a comprehensive forensic analysis.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Perform a forensic analysis of the domain controller to identify all backdoors, hidden accounts, and unauthorized permission changes.

The most comprehensive approach to eradicate an attacker's presence after a domain controller compromise is to perform a forensic analysis of the domain controller. This analysis can identify all backdoors, hidden accounts (e.g., accounts with the 'ACCOUNTDISABLE' flag removed or created via 'net user' with hidden attributes), unauthorized permission changes (e.g., modified ACLs on AD objects), and other persistence mechanisms like scheduled tasks or service principal name (SPN) modifications. Without this deep analysis, the attacker's access may persist even after password resets or server rebuilds.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Reset all domain user passwords and force a password change at next logon.

    Why it's wrong here

    Incorrect: Passwords reset does not address hidden accounts or modified permissions.

  • Use a tool to scan for hidden accounts and reset permissions on all file servers.

    Why it's wrong here

    Incorrect: This addresses only part of the issue; domain controller may have additional backdoors.

  • Perform a forensic analysis of the domain controller to identify all backdoors, hidden accounts, and unauthorized permission changes.

    Why this is correct

    Correct: Forensic analysis provides a complete picture of the attacker's actions and allows targeted eradication.

  • Rebuild the domain controller from a known good backup and reset all service account passwords.

    Why it's wrong here

    Incorrect: Backup may not be clean; rebuilding without full analysis could miss backdoors in other systems.

About these practice questions

This SSCP question is part of Courseiva's 920-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.