exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 5 discussion

Actual exam question from CompTIA's CS0-002
Question #: 5
Topic #: 1
[All CS0-002 Questions]

A consultant is evaluating multiple threat intelligence feeds to assess potential risks for a client. Which of the following is the BEST approach for the consultant to consider when modeling the client's attack surface?

  • A. Ask for external scans from industry peers, look at the open ports, and compare information with the client.
  • B. Discuss potential tools the client can purchase to reduce the likelihood of an attack.
  • C. Look at attacks against similar industry peers and assess the probability of the same attacks happening.
  • D. Meet with the senior management team to determine if funding is available for recommended solutions.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
msey2
Highly Voted 2 years, 8 months ago
Selected Answer: C
A is an absurd answer. "Hi company B, I'm from your rival, company A. Would you mind giving us scans of your network so we can see which ports you keep open? It's not for anything sinister, I promise."
upvoted 29 times
kill_chain
2 years, 1 month ago
no... a consultant is not working for company A or B. he is consulting for Company A and probably many others along with his peers. His peers in this case are fellow consultants who are also not attached to company A or B.
upvoted 3 times
...
Stiobhan
2 years, 6 months ago
Love the feedback 😂
upvoted 3 times
...
...
KhanhMicheal
Most Recent 11 months, 1 week ago
Selected Answer: C
why this so correct answer is A
upvoted 1 times
...
goku1
2 years, 3 months ago
How do you "Look at attacks against similar industry peers"? You google it?
upvoted 2 times
...
JoInn
2 years, 4 months ago
Selected Answer: A
I think the key word here is consultant. They are looking for the best way to find out as much as possible, so actual scans would be it. They aren't asking competitors, but other consultants. This would be sharing, in the same fashion as threat intelligence. That's at least how I see it.
upvoted 2 times
...
2Fish
2 years, 5 months ago
Selected Answer: C
C is the most reasonable answer here. Agree with msey2, A is absurd.
upvoted 2 times
...
DrVoIP
2 years, 5 months ago
C. Look at attacks against similar industry peers and assess the probability of the same attacks happening would be the best approach for the consultant to consider when modeling the client's attack surface. By examining similar industry peers, the consultant can gain insight into what types of threats and attacks are most prevalent in that industry, and use that information to assess the potential risks for the client. This approach can help the consultant to identify which threats are most likely to impact the client and prioritize the resources needed to mitigate those risks. - ChtGPT
upvoted 3 times
...
prud31
2 years, 8 months ago
Selected Answer: C
External scans details cannot be disclosed for comparison with other clients. This will be a security breach for a companies scan reports being accessible for comparison.
upvoted 3 times
...
SolventCourseisSCAM
2 years, 9 months ago
Selected Answer: C
this is about industry specific feeds about threat intelligence, so it should be C.
upvoted 4 times
...
MortG7
2 years, 10 months ago
You cannot just ask for External scans from peers. This needs approval and paperwork..it is not your peers that have been tasked with this job, it is you...Answer is C
upvoted 4 times
...
Cizzla7049
2 years, 10 months ago
Selected Answer: C
C is correct. Look for vuln and attacks that affect your industry the most
upvoted 2 times
...
sh4dali
2 years, 10 months ago
Selected Answer: C
I would say C. Asking scans from other companies would reveal their vulnerabilities and impossible to get.
upvoted 2 times
...
Belijmag
2 years, 11 months ago
Selected Answer: C
It is C
upvoted 2 times
...
EAart
2 years, 11 months ago
Selected Answer: A
A. This answer satisfies the attack surface of the client and potential risks faced by industry.
upvoted 2 times
...
Adonist
2 years, 11 months ago
Selected Answer: C
C makes more sense to me
upvoted 1 times
...
Laudy
2 years, 11 months ago
Selected Answer: A
I'm really torn with A and C. Only picking A because it asks specifically asks about modelling their attack surface. This question seems like one of those stupid comptia questions where you shouldn't over think things.... With that said - if I was a consultant, I would rather perform C and help my client build and develop their network. Plus, just because others have a certain attack surface, it doesn't mean we should mirror it. It may not work for the client or simply be poorly configured. Smh.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...