exam questions

Exam CS0-003 All Questions

View all questions & answers for the CS0-003 exam

Exam CS0-003 topic 1 question 96 discussion

Actual exam question from CompTIA's CS0-003
Question #: 96
Topic #: 1
[All CS0-003 Questions]

A security analyst at a company called ACME Commercial notices there is outbound traffic to a host IP that resolves to https://office365password.acme.co. The site’s standard VPN logon page is www.acme.com/logon. Which of the following is most likely true?

  • A. This is a normal password change URL.
  • B. The security operations center is performing a routine password audit.
  • C. A new VPN gateway has been deployed.
  • D. A social engineering attack is underway.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
throughthefray
Highly Voted 1 year, 4 months ago
How interesting that after stressing the importance of gathering intelligence before making a decision on what is occuring, CompTIA then asks us to make an assumption about what is happening based on vague and limited information and with no intelligence gathering first. Which of the following is likely true? Well... do we know what the URL is for resetting a password? No. Do we know which user, or what the user did before making the request to this website? Also no. Next time you forget your password and a link is sent to your email to reset it look at the URL that you go to. It wont be the same as the login pages URL. It could be either A or D but, again, CompTIA refuses to give us enough information.
upvoted 15 times
...
kmordalv
Highly Voted 1 year, 8 months ago
Selected Answer: D
The URL "https://office365password.acme.co" does not match the standard VPN logon page "www.acme.com/logon,"
upvoted 6 times
...
pinderanttal
Most Recent 7 months ago
Selected Answer: D
No one in the comment section describes one thing: a mismatched domain name. One is *.acme.co and *.acme.com. So, they are identical but not from the same host. "m" is missing on the suspicious one.
upvoted 1 times
...
chaddman
1 year, 6 months ago
D. A social engineering attack is underway. The scenario you describe, where outbound traffic is going to a host IP that resolves to a domain similar to "office365password.acme.co," while the standard VPN logon page is "www.acme.com/logon," suggests a potential social engineering attack. Attackers often create deceptive domains that mimic legitimate ones to trick users into revealing sensitive information such as usernames and passwords. In this case, the similarity in domain names raises suspicion that it could be an attempt to phish login credentials from employees. Security analysts should investigate and take appropriate measures to mitigate the threat.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago