CS0-002 Exam Question 151

Given a packet capture of the following scan:

Which of the following should MOST likely be inferred on the scan's output?
  • CS0-002 Exam Question 152

    A centralized tool for organizing security events and managing their response and resolution is known as:
  • CS0-002 Exam Question 153

    Weeks before a proposed merger is scheduled for completion, a security analyst has noticed unusual traffic patterns on a file server that contains financial information. Routine scans are not detecting the signature of any known exploits or malware. The following entry is seen in the ftp server logs:
    tftp *I 10.1.1.1 GET fourthquarterreport.xls
    Which of the following is the BEST course of action?
  • CS0-002 Exam Question 154

    Policy allows scanning of vulnerabilities during production hours, but production servers have been crashing lately due to unauthorized scans performed by junior technicians. Which of the following is the BEST solution to avoid production server downtime due to these types of scans?
  • CS0-002 Exam Question 155

    A security analyst has received reports of very slow, intermittent access to a public-facing corporate server. Suspecting the system may be compromised, the analyst runs the following commands:

    Based on the output from the above commands, which of the following should the analyst do NEXT to further the investigation?