ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 37 - SK0-005 discussion

Report
Export

A large number of connections to port 80 is discovered while reviewing the log files on a server. The server is not functioning as a web server. Which of the following represent the BEST immediate actions to prevent unauthorized server access? (Choose two.)

A.
Audit all group privileges and permissions
Answers
A.
Audit all group privileges and permissions
B.
Run a checksum tool against all the files on the server
Answers
B.
Run a checksum tool against all the files on the server
C.
Stop all unneeded services and block the ports on the firewall
Answers
C.
Stop all unneeded services and block the ports on the firewall
D.
Initialize a port scan on the server to identify open ports
Answers
D.
Initialize a port scan on the server to identify open ports
E.
Enable port forwarding on port 80
Answers
E.
Enable port forwarding on port 80
F.
Install a NIDS on the server to prevent network intrusions
Answers
F.
Install a NIDS on the server to prevent network intrusions
Suggested answer: C, F

Explanation:

The best immediate actions to prevent unauthorized server access are to stop all unneeded services and block the ports on the firewall. Stopping unneeded services reduces the attack surface of the server by eliminating potential entry points for attackers. For example, if the server is not functioning as a web server, there is no need to run a web service on port 80. Blocking ports on the firewall prevents unauthorized network traffic from reaching the server. For example, if port 80 is not needed for any legitimate purpose, it can be blocked on the firewall to deny any connection attempts on that port.

asked 02/10/2024
Shoban Babu
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first