CS0-002 Exam Question 116

A security analyst determines that several workstations are reporting traffic usage on port 3389.
All workstations are running the latest OS patches according to patch reporting. The help desk manager reports some users are getting logged off of their workstations, and network access is running slower than normal. The analyst believes a zero-day threat has allowed remote attackers to gain access to the workstations. Which of the following are the BEST steps to stop the threat without impacting all services? (Choose two.)
  • CS0-002 Exam Question 117

    A vulnerability scanner has identified an out-of-support database software version running on a server. The software update will take six to nine months to complete. The management team has agreed to a one-year extended support contract with the software vendor. Which of the following BEST describes the risk treatment in this scenario?
  • CS0-002 Exam Question 118

    A security analyst performs various types of vulnerability scans. Review the vulnerability scan results to determine the type of scan that was executed and if a false positive occurred for each device.
    Instructions:
    Select the Results Generated drop-down option to determine if the results were generated from a credentialed scan, non-credentialed scan, or a compliance scan.
    For ONLY the credentialed and non-credentialed scans, evaluate the results for false positives and check the findings that display false positives. NOTE: If you would like to uncheck an option that is currently selected, click on the option a second time.
    Lastly, based on the vulnerability scan results, identify the type of Server by dragging the Server to the results.
    The Linux Web Server, File-Print Server and Directory Server are draggable.
    If at any time you would like to bring back the initial state of the simulation, please select the Reset All button. When you have completed the simulation, please select the Done button to submit. Once the simulation is submitted, please select the Next button to continue.

    CS0-002 Exam Question 119

    An information security analyst is compiling data from a recent penetration test and reviews the following output:

    The analyst wants to obtain more information about the web-based services that are running on the target.
    Which of the following commands would MOST likely provide the needed information?
  • CS0-002 Exam Question 120

    A system administrator who was using an account with elevated privileges deleted a large amount of log files generated by a virtual hypervisor in order to free up disk space.
    These log files are needed by the security team to analyze the health of the virtual machines.
    Which of the following compensating controls would help prevent this from reoccurring? (Select two.)