CS0-003 Exam Question 196

After a risk assessment, a server was found hosting a vulnerable legacy system that has the following characteristics:
* There is no patch or official fix available from the vendor.
* There is no official support provided by the vendor.
* Customers consider the system mission critical.
Which of the following actions will best decrease the risk posed by the legacy system?
  • CS0-003 Exam Question 197

    A security analyst needs to identify a computer based on the following requirements to be mitigated:
    * The attack method is network-based with low complexity.
    * No privileges or user action is needed.
    * The confidentiality and availability level is high, with a low integrity level.
    Given the following CVSS 3.1 output:
    * Computer1: CVSS3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:H
    * Computer2: CVSS3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
    * Computer3: CVSS3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H
    * Computer4: CVSS3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
    Which of the following machines should the analyst mitigate?
  • CS0-003 Exam Question 198

    An analyst is examining events in multiple systems but is having difficulty correlating data points. Which of the following is most likely the issue with the system?
  • CS0-003 Exam Question 199

    A security team is concerned about recent Layer 4 DDoS attacks against the company website. Which of the following controls would best mitigate the attacks?
  • CS0-003 Exam Question 200

    A cybersecurity analyst is recording the following details
    * ID
    * Name
    * Description
    * Classification of information
    * Responsible party
    In which of the following documents is the analyst recording this information?