CS0-003 Exam Question 56

An attacker has just gained access to the syslog server on a LAN. Reviewing the syslog entries has allowed the attacker to prioritize possible next targets. Which of the following is this an example of?
  • CS0-003 Exam Question 57

    A security analyst scans a host and generates the following output:

    Which of the following best describes the output?
  • CS0-003 Exam Question 58

    An analyst suspects cleartext passwords are being sent over the network. Which of the following tools would best support the analyst ' s investigation?
  • CS0-003 Exam Question 59

    During normal security monitoring activities, the following activity was observed:
    cd C:\Users\Documents\HR\Employees
    takeown/f .*
    SUCCESS:
    Which of the following best describes the potentially malicious activity observed?
  • CS0-003 Exam Question 60

    A security analyst needs to identify a computer based on the following requirements to be mitigated:
    * The attack method is network-based with low complexity.
    * No privileges or user action is needed.
    * The confidentiality and availability level is high, with a low integrity level.
    Given the following CVSS 3.1 output:
    * Computer1: CVSS3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:H
    * Computer2: CVSS3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
    * Computer3: CVSS3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H
    * Computer4: CVSS3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
    Which of the following machines should the analyst mitigate?