exam questions

Exam N10-008 All Questions

View all questions & answers for the N10-008 exam

Exam N10-008 topic 1 question 708 discussion

Actual exam question from CompTIA's N10-008
Question #: 708
Topic #: 1
[All N10-008 Questions]

A firewall administrator observes log entries of traffic being allowed to a web server on port 80 and port 443. The policy for this server is to only allow traffic on port 443. The firewall administrator needs to investigate how this change occurred to prevent a reoccurrence. Which of the following should the firewall administrator do next?

  • A. Consult the firewall audit logs.
  • B. Change the policy to allow port 80.
  • C. Remove the server object from the firewall policy.
  • D. Check the network baseline.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
subaie503
10 months, 3 weeks ago
Selected Answer: A
A. Consult the firewall audit logs. Consulting the firewall audit logs would be the most appropriate next step for the firewall administrator. These logs typically record all changes to firewall rules and policies, including who made the changes and when they were made. By reviewing the audit logs, the administrator can determine how the change allowing traffic on port 80 occurred and take steps to prevent a reoccurrence, such as tightening access controls or implementing stricter change management procedures.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...