ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 334 - SK0-005 discussion

Report
Export

IDS alerts indicate abnormal traffic patterns are coming from a specific server in a data center that hosts sensitive dat a. Upon further investigation, the server administrator notices this server has been infected with a virus due to an exploit of a known vulnerability from its database software. Which of the following should the administrator perform after removing the virus to mitigate this issue from reoccurring and to maintain high availability? (Select three).

A.
Run a vulnerability scanner on the server.
Answers
A.
Run a vulnerability scanner on the server.
B.
Repartition the hard drive that houses the database.
Answers
B.
Repartition the hard drive that houses the database.
C.
Patch the vulnerability.
Answers
C.
Patch the vulnerability.
D.
Enable a host firewall.
Answers
D.
Enable a host firewall.
E.
Reformat the OS on the server.
Answers
E.
Reformat the OS on the server.
F.
Update the antivirus software.
Answers
F.
Update the antivirus software.
G.
Remove the database software.
Answers
G.
Remove the database software.
H.
Air gap the server from the network.
Answers
H.
Air gap the server from the network.
Suggested answer: A, C, F

Explanation:

After removing the virus from the server, the administrator should perform the following actions to mitigate the issue from reoccurring and to maintain high availability:

Run a vulnerability scanner on the server to identify any other potential weaknesses or exposures that could be exploited by attackers.

Patch the vulnerability that allowed the virus to infect the server in the first place, using the latest updates from the database software vendor or a trusted source.

Update the antivirus software on the server to ensure it has the most recent virus definitions and can detect and prevent future infections. The other options are either unnecessary or counterproductive for this scenario. Repartitioning the hard drive, reformatting the OS, removing the database software, or air gapping the server from the network would cause downtime and data loss, while enabling a host firewall would not prevent a virus infection from within the network. Reference: CompTIA Server+ Certification Exam Objectives, Domain 5.0: Security, Objective 5.2: Given a scenario involving a security threat/vulnerability/risk, implement appropriate mitigation techniques.

asked 02/10/2024
Muath Ahmed Saleh AlShuwaer
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first