exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 73 discussion

Actual exam question from CompTIA's CS0-002
Question #: 73
Topic #: 1
[All CS0-002 Questions]

A security analyst is reviewing a vulnerability scan report and notes the following finding:

As part of the detection and analysis procedures, which of the following should the analyst do NEXT?

  • A. Patch or reimage the device to complete the recovery.
  • B. Restart the antiviruses running processes.
  • C. Isolate the host from the network to prevent exposure.
  • D. Confirm the workstation's signatures against the most current signatures.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
midouban86
Highly Voted 2 years, 7 months ago
"As part of the detection and analysis procedures", means still under detection & analysis phase. So, D.
upvoted 23 times
...
2Fish
Highly Voted 2 years, 2 months ago
Selected Answer: D
D. Even though having out of date signatures is detected here. I would confirm first and then move on. This could be a false positive, the device may not be compromised so why jump to isolation until we know what is going on.
upvoted 10 times
2Fish
2 years, 1 month ago
Additionally, remember the question says this is still part of the "detection and analysis" stage.
upvoted 2 times
...
...
AhmedSameer
Most Recent 1 year, 6 months ago
Selected Answer: C
Dears .. As cyber security analyst, I can tell you the FIRST STEP I will take after finding vulnaravity with 10 as CVSS Score, to Isolate the reason first then do any other steps..
upvoted 4 times
...
grelaman
1 year, 8 months ago
Selected Answer: C
Given the high Quality of Detection (QoD) of 97%, it's reasonable to assume that the signature is indeed out of date. In such a case, the most appropriate next step for the security analyst should be Isolating the host from the network. It is a prudent step to prevent potential threats from exploiting the vulnerability caused by the outdated antivirus signature. Once isolated, the analyst can then work on updating the antivirus signatures to address the root cause of the issue. The analyst is clearly at the step “Detection and analysis” in a Incident Response procedure, the next step in an IR procedure is “Containment”.
upvoted 5 times
...
Aliyan
1 year, 9 months ago
Selected Answer: D
I was thinking C also but Its a Vulnerability not a Compromise so you might not need to Isolate right away and as midouban86 stated "As part of the detection and analysis procedures"
upvoted 1 times
...
attesco
1 year, 9 months ago
Selected Answer: D
This question looks so confusing, but it is clear now. The questions says " As part of the detection and analysis procedures" - That means , we should analyses those step under IR - detection and Analysis step . Then answer D coming to be the right answer. Note - that answer " C" is part of the next step of IR - Eradication and Containment
upvoted 1 times
...
Stiobhan
2 years, 2 months ago
Selected Answer: C
The answer is defo C. When you find a host on the network that has little or no AV protection your first action is to isolate and then next resolve, so D would be the second action.
upvoted 2 times
...
JoInn
2 years, 2 months ago
Selected Answer: C
C is correct, because next step after detection is containment.
upvoted 2 times
josephconer1
2 years, 1 month ago
the question says this is still part of the "detection and analysis" stage. We haven't moved into containment yet.
upvoted 2 times
...
...
PhillyCheese
2 years, 2 months ago
Selected Answer: D
As part of the detection and analysis procedures, which of the following should the analyst do NEXT? Detection and analysis procedures, means verifying the threat. D.Confirm the workstation's signatures against the most current signatures.
upvoted 3 times
...
AaronS1990
2 years, 3 months ago
Selected Answer: C
C for the reasons i previously stated
upvoted 1 times
...
AaronS1990
2 years, 3 months ago
I agree you are still in the "detection and analysis" phase, but for me it's still C. Why? Because the Severity is 10.0 and a QoD score is 97%!!!! for those unaware 10 is as high as severity goes and i won't patronize you with how high the % can go Do you really think you're taking chances with that? Not for me. Get that laptop isolated ASAP
upvoted 3 times
...
lordguck
2 years, 5 months ago
D: if you isolate a system every time (C:) just because the antivirus data is out of date, which is not even 100% certain, you have nothing else to do on your job. Confirm the problem and then restart the update procedure.
upvoted 3 times
...
gwanedm
2 years, 5 months ago
You have to confirm the scan results to see if this is a true positive or a false positive.
upvoted 2 times
...
david124
2 years, 6 months ago
Selected Answer: D
guys look up NIST Frame work of Incident response plan step 2 is analysis and detection, means verifying the threat step 3 is eradication and CONTAMINATION which would would be C if we are talking about isolation this is D
upvoted 2 times
...
saintallerdyce
2 years, 6 months ago
Selected Answer: D
Detection and analysis The detection and analysis phase is where the action begins to happen in our incident response process. In this phase, we will detect the occurrence of an issue and decide whether or not it is actually an incident so that we can respond to it appropriately. https://www.sciencedirect.com/topics/computer-science/incident-response-process#:~:text=The%20detection%20and%20analysis%20phase%20is%20where%20the,so%20that%20we%20can%20respond%20to%20it%20appropriately.
upvoted 1 times
...
TeyMe
2 years, 6 months ago
Selected Answer: C
D states Workstation signature and not Antivirus Signature!
upvoted 1 times
Average_Joe
2 years, 6 months ago
WTF. ESLs need some reading comprehension. "Confirm the workstation's signatures against the most current signatures." This is heavily implied as "confirming the workstation's (anti-virus') database of signatures against the most current database of (anti-virus) signatures"
upvoted 3 times
...
...
david124
2 years, 6 months ago
Selected Answer: D
d it is
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago