Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam CS0-001 topic 1 question 253 discussion

Actual exam question from CompTIA's CS0-001
Question #: 253
Topic #: 1
[All CS0-001 Questions]

A company's computer was recently infected with ransomware. After encrypting all documents, the malware logs a random AES-128 encryption key and associated unique identifier onto a compromised remote website. A ransomware code snippet is shown below:

Based on the information from the code snippet, which of the following is the BEST way for a cybersecurity professional to monitor for the same malware in the future?

  • A. Configure the company proxy server to deny connections to www.malwaresite.com.
  • B. Reconfigure the enterprise antivirus to push more frequent to the clients.
  • C. Write an ACL to block the IP address of www.malwaresite.com at the gateway firewall.
  • D. Use an IDS custom signature to create an alert for connections to www.malwaresite.com.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
s3curity1
Highly Voted 3 years, 10 months ago
This is tricky. Question only asks for a way to monitor for the same malware in the future - then D should be the answer. But if they want to prevent this kind of malware infection from happening again, then A is the best choice. Letter C won't block all connections of malwaresite if the IP address changes in the future.
upvoted 5 times
Blind_Hatred
3 years, 9 months ago
My guts are telling me to go with D on this one. They're asking for the BEST way to monitor it, right? Not the MOST SECURE way to deal with it. Maybe another control is set in place (like a Sinkhole) and the analyst just wants be notified about activity related to the ransomware strain? In which case D would be better, because it includes alerting.
upvoted 3 times
...
...
cusase
Most Recent 3 years, 6 months ago
I feel it's A because proxy servers can monitor and control
upvoted 1 times
...
[Removed]
3 years, 7 months ago
A - Remediation action makes it A. On a proxy dashboard, you should still be able to see real-time traffic to that domain but it won't show alerts. D - Using an IDS custom signature to create alert for connections to the malicious site is better for monitoring since you get alerts upon connections Therefore, D is the best answer
upvoted 4 times
...
TheThreatGuy
3 years, 10 months ago
Based on the word “monitor”, I agree it has to be A.... here’s where we have to hope we think the same as the test maker....
upvoted 2 times
...
shoop
3 years, 10 months ago
I thought D because it said 'monitor'!!! otherwise A
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...