CS0-002 Exam Question 91

A company's incident response team is handling a threat that was identified on the network. Security analysts have determined a web server is making multiple connections from TCP port 445 outbound to servers inside its subnet as well as at remote sites. Which of the following is the MOST appropriate next step in the incident response plan?
  • CS0-002 Exam Question 92

    While reviewing web server logs, a security analyst notices the following code:

    Which of the following would prevent this code from performing malicious actions?
  • CS0-002 Exam Question 93

    A small organization has proprietary software that is used internally. The system has not been well maintained and cannot be updated with the rest of the environment Which of the following is the BEST solution?
  • CS0-002 Exam Question 94

    A system administrator has reviewed the following output:

    Which of the following can a system administrator infer from the above output?
  • CS0-002 Exam Question 95

    A system administrator is doing network reconnaissance of a company's external network to determine the vulnerability of various services that are running. Sending some sample traffic to the external host, the administrator obtains the following packet capture:

    Based on the output, which of the following services should be further tested for vulnerabilities?