exam questions

Exam CS0-003 All Questions

View all questions & answers for the CS0-003 exam

Exam CS0-003 topic 1 question 153 discussion

Actual exam question from CompTIA's CS0-003
Question #: 153
Topic #: 1
[All CS0-003 Questions]

A web application team notifies a SOC analyst that there are thousands of HTTP/404 events on the public-facing web server. Which of the following is the next step for the analyst to take?

  • A. Instruct the firewall engineer that a rule needs to be added to block this external server
  • B. Escalate the event to an incident and notify the SOC manager of the activity
  • C. Notify the incident response team that there is a DDoS attack occurring
  • D. Identify the IP/hostname for the requests and look at the related activity
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
kmordalv
Highly Voted 1 year, 1 month ago
Selected Answer: D
Identifying the IP/hostname for the requests and looking at the related activity is the first step in understanding the nature of the issue. This step is crucial for making informed decisions about how to respond to the situation. Once the analyst has gathered more information, they can then decide whether further escalation or actions are necessary, such as alerting the incident response team or notifying higher management.
upvoted 15 times
...
CyberJackal
Most Recent 7 months ago
Selected Answer: D
Until you yourself identify that a DDoS is occurring, don't notify the incident response team. Noone likes a cybersecurity analyst who crys wolf.
upvoted 4 times
...
chaddman
1 year ago
Selected Answer: D
Identify the IP/hostname for the requests and look at the related activity (D): This is the most prudent first step. By identifying the source of the requests, the analyst can better understand whether this is benign activity, a scanning attempt, or something more malicious.
upvoted 1 times
...
Jong1
1 year ago
did someone pass the exam with the questions presented here ? I also noticed only 153 questions available but it shows 162 ? How accurate are the questions ?
upvoted 3 times
581777a
1 year ago
i'm taking mine in the morning, i will update here and on the main page. I studied both versions but this one more.
upvoted 2 times
[Removed]
11 months, 1 week ago
Did you pass?
upvoted 4 times
...
...
deeden
10 months, 3 weeks ago
I just passed! Good luck to everyone who's going to take the exam.
upvoted 7 times
...
chaddman
1 year ago
jong, i took couple weeks ago, i scored 730, failed, just found out this site, and i am seeing 90 percent of the questions that i had
upvoted 10 times
[Removed]
11 months, 1 week ago
did you study both c0-002 and c0-003 mate?
upvoted 1 times
...
RT7
11 months, 2 weeks ago
Hi chaddman, How many PBQs appeared from here? And how many questions appeared in total?
upvoted 2 times
...
NFFC91
7 months ago
90% from 003 or 002?
upvoted 1 times
...
...
...
muvisan
1 year ago
Selected Answer: C
if thousands of 404 are seen, then this is very probably a dDOS attack and the requests will come from a lot of IPs. So identifying this IPs will not help much. I would go with answer C. And after this step the FW engineer (answer A) would be involved and start mitigating the situation...
upvoted 1 times
kmordalv
1 year ago
The first task to be performed by the analyst would be to investigate the activity. Once investigated, he should perform any of the other options. The 404 error code indicates that the requested resource could not be found. The analyst must investigate whether the error is due to a bad link or a missing component. DDos attacks would be associated with 50x codes (500 Internal Server Error, 503 Service Unavailable, 504 Gateway Timeout).
upvoted 8 times
muvisan
1 year ago
ok, so 404 and DOS really usually doesn't make sense (only maybe when a proxy is between). Then answer D and investigating the activity makes most sense.
upvoted 1 times
...
...
3be4f49
7 months, 1 week ago
There's no sign it's a DDOS attack as compared to a DOS attack, which is why further analysis needs to be conducted.
upvoted 2 times
...
...
Itechcomputer
1 year ago
where are the rest of the questions? it says 162 and I only see 153 and also the simulations. I haven't see any of those.
upvoted 3 times
[Removed]
11 months, 1 week ago
same her no simulations question
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago