CS0-003 Exam Question 61

A company is concerned with finding sensitive file storage locations that are open to the public. The current internal cloud network is flat. Which of the following is the best solution to secure the network?
  • CS0-003 Exam Question 62

    A security analyst reviews the following extract of a vulnerability scan that was performed against the web server:
    Which of the following recommendations should the security analyst provide to harden the web server?
  • CS0-003 Exam Question 63

    A development team is preparing to roll out a beta version of a web application and wants to quickly test for vulnerabilities, including SQL injection, path traversal, and cross-site scripting. Which of the following tools would the security team most likely recommend to perform this test?
  • CS0-003 Exam Question 64

    A security analyst recently used Arachni to perform a vulnerability assessment of a newly developed web application. The analyst is concerned about the following output:
    [+] XSS: In form input 'txtSearch' with action https://localhost/search.aspx
    [-] XSS: Analyzing response #1...
    [-] XSS: Analyzing response #2...
    [-] XSS: Analyzing response #3...
    [+] XSS: Response is tainted. Looking for proof of the vulnerability.
    Which of the following is the most likely reason for this vulnerability?
  • CS0-003 Exam Question 65

    A company recently removed administrator rights from all of its end user workstations. An analyst uses CVSSv3.1 exploitability metrics to prioritize the vulnerabilities for the workstations and produces the following information:

    Which of the following vulnerabilities should be prioritized for remediation?