exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 367 discussion

Actual exam question from CompTIA's CS0-002
Question #: 367
Topic #: 1
[All CS0-002 Questions]

A company is moving from the use of web servers hosted in an internal data center to a containerized cloud platform. An analyst has been asked to identify indicators of compromise in the containerized environment. Which of the following would best indicate a running container has been compromised?

  • A. A container from an approved software image has drifted.
  • B. An approved software orchestration container is running with root privileges.
  • C. A container from an approved software image has stopped responding.
  • D. A container from an approved software image fails to start.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
yanyan20
Highly Voted 1 year, 11 months ago
Selected Answer: A
https://www.examtopics.com/discussions/comptia/view/54001-exam-cs0-002-topic-1-question-189-discussion/
upvoted 5 times
...
Aliyan
Most Recent 1 year, 8 months ago
Dion says you dont need these for containers. So there is no reason there should be Root privilege's. forget root there shouldn't even be an admin user. ▪No patching ▪ No administration ▪ No file system monitoring Even if i didnt read dions note i still would pick B because least privilege enforcement is breached.
upvoted 1 times
...
SimonR2
1 year, 9 months ago
Answer A An example of a container-specific IOCs might include unauthorized container image changes: Modifications or updates to container images without proper authorization or outside of the usual update cycle. Running a container as the root user is not necessarily an Indicator of Compromise (IOC) on its own, but it can be considered a security best practice to avoid running containers with elevated privileges whenever possible.
upvoted 2 times
...
CyberCEH
1 year, 11 months ago
Sorry Answer B
upvoted 1 times
...
CyberCEH
1 year, 11 months ago
Answer A
upvoted 2 times
...
ZUL01
1 year, 11 months ago
Selected Answer: A
https://www.examtopics.com/discussions/comptia/view/54001-exam-cs0-002-topic-1-question-189-discussion/
upvoted 3 times
...
PartialNarwhal
2 years ago
Selected Answer: B
Running a container with root privileges means that the container has access to the entire host system and can perform any operation. This is a major security risk because if the container is compromised, the attacker would also have access to the entire host system. It is recommended that containers are run with the least amount of privilege necessary to perform their functions. Options A, C, and D are not necessarily indicators of compromise. A container drifting from an approved software image means that the container has been modified, but this modification may be intentional. A container that stops responding or fails to start may simply be experiencing technical issues and not necessarily a result of a compromise. -ChatGPT
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago