exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 82 discussion

Actual exam question from CompTIA's CS0-002
Question #: 82
Topic #: 1
[All CS0-002 Questions]

During an investigation, a security analyst determines suspicious activity occurred during the night shift over the weekend. Further investigation reveals the activity was initiated from an internal IP going to an external website. Which of the following would be the MOST appropriate recommendation to prevent similar activity from happening in the future?

  • A. An IPS signature modification for the specific IP addresses
  • B. An IDS signature modification for the specific IP addresses
  • C. A firewall rule that will block port 80 traffic
  • D. Implement a web proxy to restrict malicious web content
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
PatrickC_IT
Highly Voted 2 years, 7 months ago
Selected Answer: D
I chose D: A - IPS could prevent an intrusion, but this shows that it's going from internal to external. B - IDS does nothing to prevent intrusions, only detects. C - Overkill. You don't want to block ALL http traffic. D - The web proxy can make a more intelligent decision on if a site is malicious or not and can block accordingly. Proxies often can update automatically as well, so they can keep on top of potentially malicious locations.
upvoted 20 times
...
Laudy
Highly Voted 2 years, 8 months ago
Blocking all port 80 seems detrimental. There's many other ports too.... I feel you should add an IPS signature modification for the specific IP addresses/domains that the host is trying to beacon to. Any other takes? Am I missing something?
upvoted 5 times
ProNerd
1 year, 9 months ago
Blocking 80 isn't an option. IDS and IPS are for inbound traffic, not outbound. Only a web proxy can be the solution.
upvoted 1 times
...
...
Junior24
Most Recent 1 year, 7 months ago
D is correct
upvoted 1 times
...
2Fish
2 years, 1 month ago
Selected Answer: D
D. This is the Best answer here, IPS and IDS are ingress and reactive, not a proactive approach.
upvoted 3 times
...
encxorblood
2 years, 2 months ago
Selected Answer: A
Therefore, option D is the correct answer. A web proxy can be used to inspect and filter all web traffic, allowing the security team to block access to known malicious websites and to detect and block attempts to exfiltrate data from the organization. By implementing a web proxy, the organization can prevent similar suspicious activity from occurring in the future, and better protect its sensitive data.
upvoted 1 times
...
forest111
2 years, 5 months ago
Selected Answer: D
there wasn't mention port 80
upvoted 1 times
...
MortG7
2 years, 6 months ago
Selected Answer: D
I agree with D. IPS - Intrusion (Ingress traffic) IDS - Intrusion (ingress traffic) The direction of this traffic is from an internal IP outbound. So it cannot be either of the above. Blocking port 80 blocks everyone and at all times (not just off hours and weekends)
upvoted 1 times
...
Ryukendo
2 years, 7 months ago
Selected Answer: D
I chose D It says internal IP to an external website, not external IP. I could just use a web proxy to restrict access
upvoted 1 times
...
gwanedm
2 years, 7 months ago
D makes more sense
upvoted 3 times
...
Fastytop
2 years, 7 months ago
Selected Answer: A
A- An IPS signature modification for the specific IP addresses.
upvoted 1 times
A_Shadows_Soul
2 years, 6 months ago
Problem is its internal going to external. IPS doesn't stop that. Process of elimination says D
upvoted 2 times
...
...
cyberseckid
2 years, 7 months ago
Im feeling D , you don't want to block only a specific website but all malicious websites , not sure though.
upvoted 2 times
...
amateurguy
2 years, 8 months ago
Selected Answer: A
A is the BEST choice.
upvoted 3 times
Treymb6
2 years, 7 months ago
What type of intrusion are you preventing when it was internal to external??
upvoted 7 times
...
...
maxi99
2 years, 8 months ago
Blocking Port 80 makes no sense. Adding an IPS signature for that IP makes more sense.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago