exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 179 discussion

Actual exam question from CompTIA's CS0-002
Question #: 179
Topic #: 1
[All CS0-002 Questions]

A security analyst observes a large amount of scanning activity coming from an IP address outside the organization's environment. Which of the following should the analyst do to block this activity?

  • A. Create an IPS rule to block the subnet.
  • B. Sinkhole the IP address.
  • C. Create a firewall rule to block the IP address.
  • D. Close all unnecessary open ports.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
TheStudiousPeepz
2 years, 6 months ago
Selected Answer: C
You never want to block a subnet so C
upvoted 3 times
2Fish
2 years, 1 month ago
Correct. Blocking a whole subnet is bad practice.
upvoted 1 times
...
uday1985
1 year, 7 months ago
what if the threat actor changed the IP one minute later. But true... you cannot block a subnet! since many of those are Microsoft! and threat actors love them! since MS takes ages to take down a malicious IP!
upvoted 1 times
...
...
marc4354345
2 years, 7 months ago
Selected Answer: C
C. Simple and straightforward.
upvoted 3 times
...
Cizzla7049
2 years, 7 months ago
Selected Answer: A
I choose A. IPS rule will detect and prevent any malicious activity plus it blocks the subnet, which means every IP in that range coming from the source. But i'm not sure on this. A firewall block means attacker can change IP in same range and keep going
upvoted 2 times
Tag
2 years, 7 months ago
blocking the entire subnet without knowing for certain that the other addresses within that block are also involved in malicious activity is a bad way to go. It can even end up impacting the business itself as there might be a chance that legitimate services they need also come from servers that also reside in that subnet . so the safest and simplest way to go would be to block the individual address.
upvoted 3 times
...
...
Adrian831
2 years, 7 months ago
Selected Answer: C
C for sure
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago