exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 2 discussion

Actual exam question from CompTIA's CS0-002
Question #: 2
Topic #: 1
[All CS0-002 Questions]

A security analyst discovers the following firewall log entries during an incident:

Which of the following is MOST likely occurring?

  • A. Banner grabbing
  • B. Port scanning
  • C. Beaconing
  • D. Data exfiltration
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
AlexR76
Highly Voted 2 years, 8 months ago
Selected Answer: B
This is a typical SYN scan. Beaconing is when the malware communicates with a C2 server asking for instructions or to exfiltrate collected data on some predetermined asynchronous interval
upvoted 17 times
...
Joluve
Most Recent 1 year, 3 months ago
Selected Answer: B
multiple ports and zero data tranfered
upvoted 1 times
...
Achilles69
1 year, 4 months ago
Zero data transferred: port scanning
upvoted 1 times
...
m025
1 year, 6 months ago
Selected Answer: B
It's a port scanning, there sin't nothing of others
upvoted 1 times
...
CySAIsHard
1 year, 8 months ago
Selected Answer: B
Port Scanning ftw
upvoted 1 times
...
Ayben
1 year, 8 months ago
Selected Answer: B
This is port scanning.
upvoted 2 times
...
rphadol
1 year, 9 months ago
definetly port Scanning
upvoted 1 times
...
ReaperDeathSeal
1 year, 11 months ago
This is port scanning.
upvoted 3 times
...
Temickey
2 years, 2 months ago
I strongly believe that this is port scanning
upvoted 4 times
...
JokerRWild
2 years, 2 months ago
Why is the answer wrong. Is this meant to spark a discussion with the community?
upvoted 1 times
...
2Fish
2 years, 3 months ago
Selected Answer: B
This is typical port scanning, most beacons will use specific ports and will not show this type of behavior.
upvoted 3 times
...
omer123456
2 years, 3 months ago
Selected Answer: B
I think it is port scan not beaconing
upvoted 1 times
...
iraidesc
2 years, 5 months ago
Selected Answer: C
In networking, beaconing is a term used to describe a continuous cadence of communication between two systems. In the context of malware, beaconing is when malware periodically calls out to the attacker's C2 server to get further instructions on tasks to perform on the victim machine.
upvoted 2 times
...
kopib21961
2 years, 6 months ago
I also think the answer is C.
upvoted 1 times
kopib21961
2 years, 6 months ago
Sorry I meant Port Scanning NOT beaconing
upvoted 2 times
...
...
sho123
2 years, 6 months ago
Selected Answer: B
it is Syn - 3 way tcp hanshake has not yet completed. it is port scan
upvoted 2 times
...
AndyM112
2 years, 8 months ago
B: SYN Scan, sometimes called half-open scanning
upvoted 2 times
...
35nerd7
2 years, 8 months ago
B. Port scanning makes the most sense.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...