exam questions

Exam CV0-003 All Questions

View all questions & answers for the CV0-003 exam

Exam CV0-003 topic 1 question 254 discussion

Actual exam question from CompTIA's CV0-003
Question #: 254
Topic #: 1
[All CV0-003 Questions]

In an IaaS platform, which of the following actions would a systems administrator take FIRST to identify the scope of an incident?

  • A. Conduct a memory acquisition.
  • B. Snapshot all volumes attached to an instance.
  • C. Retrieve data from a backup.
  • D. Perform a traffic capture.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
queenbee1238
Highly Voted 1 year, 6 months ago
Selected Answer: D
The question is not asking for disaster recovery, it is asking to identify the scope of an incident, therefore it cannot be C or A. so D is the answer
upvoted 5 times
...
BigM
Most Recent 5 months, 2 weeks ago
Selected Answer: B
Explanation: In an IaaS (Infrastructure as a Service) environment, identifying the scope of an incident typically involves preserving evidence before conducting further analysis. Taking a snapshot of all volumes attached to the affected instance ensures that the current state of the system is captured, allowing for forensic analysis without altering data.
upvoted 1 times
...
Selected Answer: B
It's B, not all incidents will develop into a routine of traffic emitting from the infected endpoint. Traffic captures tend to happen in real-time and rarely are they used in the Firewall policies or anywhere else considering they bottleneck the dataplane so it's always used in troubleshooting. If there was a logic bomb for instance or something that would be more specific to targeting the machine with a rootkit without external network connections you wouldn't be able to see it through a traffic capture. B., is the answer because most the system has been targeted with a snapshot it can interrogated and sent for forensics.
upvoted 1 times
...
FrancisDrake
1 year, 6 months ago
Selected Answer: D
I would think that you would want to check traffic logs to see what your up against.
upvoted 2 times
...
Anonimo_R_de_jalisco
1 year, 11 months ago
Selected Answer: B
B. Snapshot all volumes attached to an instance. In an IaaS (Infrastructure as a Service) platform, the first step a systems administrator would usually take to identify the scope of an incident is to snapshot all volumes attached to the affected instance. This action creates a copy of the instance's storage volumes at a specific point in time, preserving the state of the data, configurations, and potential evidence related to the incident.
upvoted 1 times
...
No5172685
2 years ago
Selected Answer: B
You want to
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...