ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 267 - CS0-003 discussion

Report
Export

A web application team notifies a SOC analyst that there are thousands of HTTP/404 events on the public-facing web server. Which of the following is the next step for the analyst to take?

A.
Instruct the firewall engineer that a rule needs to be added to block this external server.
Answers
A.
Instruct the firewall engineer that a rule needs to be added to block this external server.
B.
Escalate the event to an incident and notify the SOC manager of the activity.
Answers
B.
Escalate the event to an incident and notify the SOC manager of the activity.
C.
Notify the incident response team that a DDoS attack is occurring.
Answers
C.
Notify the incident response team that a DDoS attack is occurring.
D.
Identify the IP/hostname for the requests and look at the related activity.
Answers
D.
Identify the IP/hostname for the requests and look at the related activity.
Suggested answer: D

Explanation:

A HTTP/404 error code means that the requested page or resource was not found on the web server. This could be caused by various reasons, such as incorrect URLs, moved or deleted pages, missing assets, or server misconfigurations123. The analyst should first identify the source of the requests and examine the related activity to determine if they are legitimate or malicious, and what actions need to be taken to resolve the issue. The other options are either premature or irrelevant without further investigation.

Reference: 1: 404 Page Not Found Error: What It Is and How to Fix It 2: 404 Error Code: What Causes Them and How To Fix It 3: About 404 errors and how to Troubleshoot it?

asked 02/10/2024
Ben Pike
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first