exam questions

Exam CS0-003 All Questions

View all questions & answers for the CS0-003 exam

Exam CS0-003 topic 1 question 224 discussion

Actual exam question from CompTIA's CS0-003
Question #: 224
Topic #: 1
[All CS0-003 Questions]

A security analyst is responding to an incident that involves a malicious attack on a network data closet. Which of the following best explains how the analyst should properly document the incident?

  • A. Back up the configuration file for all network devices.
  • B. Record and validate each connection.
  • C. Create a full diagram of the network infrastructure.
  • D. Take photos of the impacted items.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
AndreasH
Highly Voted 1 year, 2 months ago
I am not quite sure I understand the question. Taking photos makes only sense if it was a physical attack on the closet.. does that happen?
upvoted 10 times
PatrickH
1 year ago
Same here. I took it to mean a physical attack so Photos was the best answer. Question could be a bit more specific though
upvoted 2 times
...
Instguy
1 year, 2 months ago
I understand the confusion. They are talking about network and malicious attack, so we assume it is logical. However. it is mentioned that Network data closet (a physical room in a building) was maliciously attacked. I.e., cables ripped, hardware devised snatched or broken. This is a physical attack that happened to a network data room. Pictures can be taken with a camera for investigation. Hope this helps.
upvoted 10 times
JAlexander35
9 months, 2 weeks ago
oh some just CompTIA not explaining things fully again. Just referencing a physical room doesn't correlate to a physical delivery of attack
upvoted 5 times
...
...
...
Susan4041
Most Recent 1 month ago
Selected Answer: D
I change it to D not A disregard
upvoted 1 times
...
Susan4041
1 month ago
Selected Answer: A
You would record the issue and valid each connection first. Photos would be next.
upvoted 1 times
...
study_study
3 months, 2 weeks ago
Selected Answer: D
Horrible question. Assuming this is a physical closet then yes take photo's, but that is not necessarily obvious from how it is written. Do better CompTIA.
upvoted 1 times
...
Freshly
5 months, 3 weeks ago
This belongs in sec+. But yeah I was confused too. The answer is definitely "take photos".
upvoted 2 times
...
cy_analyst
7 months ago
Selected Answer: D
Network data closets are often targets for physical attacks because they contain critical networking hardware. Malicious activities in these environments often involve actions like: Unplugging or rerouting cables. Physically damaging network devices. Adding unauthorized devices (e.g., rogue access points or keyloggers). Tampering with configurations by accessing network devices physically. In this case, documenting the incident by taking photos of the impacted items (option D) would be appropriate because it helps capture evidence of physical tampering or damage, which would be relevant in a physical security breach.
upvoted 2 times
...
kinny4000
7 months ago
Selected Answer: D
Documenting the incident is about capturing evidence, taking photos will work.
upvoted 2 times
...
section8santa
1 year, 1 month ago
Selected Answer: D
Taking photos is a direct way to document the physical state of the impacted items after an incident. This can provide an immediate and clear visual record of the scene as it was found, which can be crucial for subsequent investigations and for understanding what occurred. This documentation can be especially valuable if there is any physical damage or if there are indicators of how the attackers gained access or what they might have done while inside.
upvoted 3 times
...
Franky30
1 year, 1 month ago
In the context of a malicious attack on a network data closet, recording and validating each connection (Option B) would be crucial for understanding the scope of the incident, identifying potential points of compromise, and facilitating remediation efforts.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago