ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 311 - SK0-005 discussion

Report
Export

The network's IDS is giving multiple alerts that unauthorized traffic from a critical application server is being sent to a known-bad public IP address.

One of the alerts contains the following information:

Exploit Alert Attempted User Privilege Gain 2/2/07-3: 09:09 10.1.200.32

--> 208.206.12.9:80

This server application is part of a cluster in which two other servers are also servicing clients. The server administrator has verified the other servers are not sending out traffic to that public IP address. The IP address subnet of the application servers is 10.1.200.0/26. Which of the following should the administrator perform to ensure only authorized traffic is being sent from the application server and downtime is minimized? (Select two).

A.
Disable all services on the affected application server.
Answers
A.
Disable all services on the affected application server.
B.
Perform a vulnerability scan on all the servers within the cluster and patch accordingly.
Answers
B.
Perform a vulnerability scan on all the servers within the cluster and patch accordingly.
C.
Block access to 208.206.12.9 from all servers on the network.
Answers
C.
Block access to 208.206.12.9 from all servers on the network.
D.
Change the IP address of all the servers in the cluster to the 208.206.12.0/26 subnet.
Answers
D.
Change the IP address of all the servers in the cluster to the 208.206.12.0/26 subnet.
E.
Enable GPO to install an antivirus on all the servers and perform a weekly reboot.
Answers
E.
Enable GPO to install an antivirus on all the servers and perform a weekly reboot.
F.
Perform an antivirus scan on all servers within the cluster and reboot each server.
Answers
F.
Perform an antivirus scan on all servers within the cluster and reboot each server.
Suggested answer: B, F

Explanation:

The administrator should perform an antivirus scan on all servers within the cluster and reboot each server, and block access to 208.206.12.9 from all servers on the network. These actions will help to remove any malware that may have infected the application server and prevent any further unauthorized traffic to the known-bad public IP address. An antivirus scan can detect and remove malicious software that may be sending data to an external source, and a reboot can clear any temporary files or processes that may be related to the malware. Blocking access to 208.206.12.9 from all servers on the network can prevent any future attempts to communicate with the malicious IP address.

Reference: CompTIA Server+ SK0-005 Certification Study Guide, Chapter 3, Lesson 3.4, Objective 3.4; Chapter 6, Lesson 6.2, Objective 6.2

asked 02/10/2024
Kushantha Gunawardana
49 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first