CS0-002 Exam Question 126

During a routine review of service restarts a security analyst observes the following in a server log:

Which of the following is the GREATEST security concern?
  • CS0-002 Exam Question 127

    An organization was alerted to a possible compromise after its proprietary data was found for sale on the Internet. An analyst is reviewing the logs from the next-generation UTM in an attempt to find evidence of this breach. Given the following output:

    Which of the following should be the focus of the investigation?
  • CS0-002 Exam Question 128

    After detecting possible malicious external scanning, an internal vulnerability scan was performed, and a critical server was found with an outdated version of JBoss. A legacy application that is running depends on that version of JBoss. Which of the following actions should be taken FIRST to prevent server compromise and business disruption at the same time?
  • CS0-002 Exam Question 129

    An organization has several systems that require specific logons Over the past few months, the security analyst has noticed numerous failed logon attempts followed by password resets. Which of the following should the analyst do to reduce the occurrence of legitimate failed logons and password resets?
  • CS0-002 Exam Question 130

    Which of the following sets of attributes BEST illustrates the characteristics of an insider threat from a security perspective?