exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 41 discussion

Actual exam question from CompTIA's CS0-002
Question #: 41
Topic #: 1
[All CS0-002 Questions]

The SOC has received reports of slowness across all workstation network segments. The currently installed antivirus has not detected anything, but a different anti-malware product was just downloaded and has revealed a worm is spreading. Which of the following should be the NEXT step in this incident response?

  • A. Send a sample of the malware to the antivirus vendor and request urgent signature creation.
  • B. Begin deploying the new anti-malware on all uninfected systems.
  • C. Enable an ACL on all VLANs to contain each segment.
  • D. Compile a list of IoCs so the IPS can be updated to halt the spread.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
jleonard_ddc
Highly Voted 2 years, 3 months ago
Selected Answer: D
I think people are confused because all of the steps are valid ones to take. The key is the question asks which step to take NEXT. That means you have to fit the steps into the IR process. We're past identification as we have a live worm spreading. Next step is containment. A) This needs to happen, but could take a long time fo results. This is a post-incident activity. B) Changes like this are part of remediation / recovery. But it only says it revealed the worm; not that it stopped it. C) This would make sense, but slowness is being reported for "all workstation segments". In other words, it's hit every VLAN already. D) Updating your IPS is the best chance you have at stopping it. You don't need much for IOC's, just anything that you're getting from the anti-malware. An EXE, a port, a signature...
upvoted 26 times
Dutch012
1 year, 10 months ago
Your comment makes sense, thanks!
upvoted 2 times
...
uday1985
1 year, 8 months ago
Imagine ! just imagine ! that the script of the malware is obfuscated! how long it will take you to deobfuscate and extract IOC's?
upvoted 1 times
...
novolyus
1 year, 5 months ago
100%. If it is already spread in all vlans, contain each vlan would do nothing because worm will spread in the vlan itself. And that, will happen in every vlan, so you won´t stop the worm spreading.
upvoted 1 times
...
Sebatian20
1 year, 5 months ago
Can't be D. "across all workstation network segments" Can't stop something that's already been spread. I believe A or C are the better answer.
upvoted 1 times
...
...
fuzzyguzzy
Most Recent 5 months ago
A) This takes too long B) The question says all work stations are slow, implying all devices are infected. C) The malware hit all segments, so there's nothing to contain D) Again, the worm spread, so there's nothing to contain. All these options are terrible lol
upvoted 1 times
fuzzyguzzy
5 months ago
Thinking this over, I would to D. Contain the malware on each machine. This way when you clean the malware, a host doesn't get reinfected.
upvoted 1 times
...
...
zecomeia_007
9 months, 2 weeks ago
Selected Answer: C
C. Enable an ACL on all VLANs to contain each segment.
upvoted 1 times
...
Pavel019846457
1 year, 6 months ago
ChatGPT says it's C... Well, might be a point.
upvoted 1 times
...
Gwatto
1 year, 7 months ago
"Slowness across ALL network segments" Which means the worm has already spread across all work stations. You cannot halt what has already spread. I'm going with A also
upvoted 1 times
...
Pavel019846457
1 year, 9 months ago
Selected Answer: D
D is correct one for NEXT action to be taken
upvoted 1 times
...
karpal
1 year, 10 months ago
Selected Answer: C
I went several times on this question. days have passed. i looked at everyone. all answer make sense. The thing is they say all workstation segments. and while the word ALL is important, but also workstation. What about the rest that are NOT workstations ? servers , databases etc ? We want to contain it as it an WORM that spreads allone - think SQL Slammer https://en.wikipedia.org/wiki/SQL_Slammer . So I think the ACL - segmenting ALL segments is the best answer, closing the ports that the worm is using. It is fast and it contains it in the workstation segments that are already infected. the signature and the new anti malware could be done later the Remediation step.
upvoted 2 times
...
thenewpcgamer
1 year, 12 months ago
Everyone keeps saying "this has hit every vlan already" as there reasoning for not choosing C. So let me ask you this.. Do servers also live on vlan segments ... that have not potentially been affected yet?
upvoted 3 times
PartialNarwhal
1 year, 12 months ago
Yeah they're saying it's hit every network segment, but then choose D to stop the spread. It makes no sense. I'm still leaning towards C.
upvoted 2 times
...
...
Kainas
2 years ago
Selected Answer: B
B is a more immediate response to the incident. Deploying the new anti-malware on all uninfected systems will help prevent further infections and reduce the spread of the worm. D is not an immediate response to the incident and may take some time to complete. Both options are important, but in this specific scenario, B is the more urgent and effective next step to take.
upvoted 2 times
...
Joshey
2 years, 1 month ago
Selected Answer: D
C looks appealing but, why would you use ACLs on all vlans, when the IOC/Incident was identified on just the workstation subnet...even sef such action could cause lots of service outages
upvoted 1 times
...
2Fish
2 years, 2 months ago
Selected Answer: D
D. I have to agree that we can contain the spread. Then Send a sample (hashs, etc) to the vendor. Perhaps this could be done in tandem if you have more than one Analyst working on the event.
upvoted 1 times
...
tatianna
2 years, 2 months ago
Containment is key
upvoted 1 times
...
absabs
2 years, 3 months ago
Selected Answer: D
This virus already in all workstation, so not C. A is post-incident activitiy. When you deploying new anti-malware, it takes so many time. not B. D is make sense, IPS is in your system already.
upvoted 1 times
...
IanRogerStewart
2 years, 3 months ago
Selected Answer: D
Question notes it has already spread to all network segments. At this stage to quote Princess Leia, "Help me Intrusion Prevention System, you're my only hope!"
upvoted 3 times
...
NickDrops
2 years, 3 months ago
C is a bad answer " Enable an ACL on all VLANs to contain each segment.". Its already on all segments. This won't do anything.
upvoted 3 times
HereToStudy
2 years, 1 month ago
Good catch. I was leaning towards C until I noticed this
upvoted 1 times
...
...
reidsel
2 years, 4 months ago
Selected Answer: A
hard to choose, a or d is all fine. But more prefer A since slowness is already on all workstions.
upvoted 1 times
...
MrRobotJ
2 years, 5 months ago
Selected Answer: D
Should be D
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago