exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 162 discussion

Actual exam question from CompTIA's CS0-002
Question #: 162
Topic #: 1
[All CS0-002 Questions]

During a review of recent network traffic, an analyst realizes the team has seen this same traffic multiple times in the past three weeks, and it resulted in confirmed malware activity. The analyst also notes there is no other alert in place for this traffic. After resolving the security incident, which of the following would be the
BEST action for the analyst to take to increase the chance of detecting this traffic in the future?

  • A. Share details of the security incident with the organization's human resources management team.
  • B. Note the security incident so other analysts are aware the traffic is malicious.
  • C. Communicate the security incident to the threat team for further review and analysis.
  • D. Report the security incident to a manager for inclusion in the daily report.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Tag
Highly Voted 2 years, 8 months ago
Selected Answer: B
B is most in line of sight to what the question is asking. best chance of detecting this activity in the first line it says "the team has seen this same traffic" prior to that it says "an analyst realizes" this indicates to me that only 1 person on the team has become aware of it and the next thing he should do is make it known to the rest of the team. it was already deduced that the traffic was related to malicious activity so i dont think the threat team needs to analyze it more plus that still wont allow them to actually detect it faster and more often
upvoted 11 times
forklord72
2 years, 8 months ago
my thought process exactly, not sure how C would spread awareness of the traffic
upvoted 1 times
...
Comptia_Secret_Service
2 years, 7 months ago
Humans are most often more susceptible to mistakes than systems, the line "The analyst also notes there is no other alert in place for this traffic" suggests that there is currently no detection or alerts in place to trigger and support analysts. Further review of the incident could help create rules and alerts that automatically trigger if the same incident happens again, analyst don't often monitor raw logs and events as there could be tens of millions of logs generated every minute. I am a security analyst myself, this is what we do in SOC. Answer is C.
upvoted 5 times
...
...
d8viey
Most Recent 1 year, 7 months ago
Seems like if an analyst has seen this 3 times in a week and it resulted in confirmed malware activity, then it should be actively communicated to the threat team so they take some proactive actions for it (like create an alert???). Noting the incident seems like a passive response to a known threat for this repetative issue. Especially since there have been 3 other incidents...apparently no one is reading the incident reports... I also understand these test questions sometimes don't quite line up with reality. So I see how it could also be B.
upvoted 1 times
...
HereToStudy
2 years, 3 months ago
Selected Answer: C
Duplicate question but answer B is different which is what I was leaning towards. So i guess it’s C #333
upvoted 1 times
...
Alizade
2 years, 3 months ago
Selected Answer: C
C. Communicate the security incident to the threat team for further review and analysis. By communicating the security incident to the threat team, the analyst ensures that the traffic patterns and indicators of compromise are properly analyzed and documented. The threat team can then work on developing and implementing appropriate detection and alerting mechanisms to identify similar traffic in the future, thus increasing the chance of detecting such incidents. This approach helps to improve the overall security posture of the organization.
upvoted 2 times
...
AaronS1990
2 years, 4 months ago
Selected Answer: C
C seems the most textbook way of responding to the incident rather than "taking note"
upvoted 3 times
2Fish
2 years, 3 months ago
Agree, Threat team would be able to make adjustments to help "detect" this in the future.
upvoted 1 times
...
...
White_T_10
2 years, 7 months ago
C. Incident has been resolved.
upvoted 1 times
...
mrodmv
2 years, 7 months ago
Selected Answer: C
C, because the incident has been resolved already therefore it has been communicated to the team which means a post mortem (b) has been done already.
upvoted 3 times
...
Cizzla7049
2 years, 7 months ago
Selected Answer: C
And what will seal the deal for C is there is no other alert for this . Threat team can create that rule/alert for the SIEM and have the engineers implement it. The rule alerts everyone automatically. Definitely C if you read the question very well.
upvoted 2 times
...
Cizzla7049
2 years, 7 months ago
Selected Answer: C
C. Threat team can review it and give every other IOC related to it and they can be blocked either by automation or by spreading the word to other analysts. I know telling other analysts is how it works in real life but you can never tell with comptia. The most simple answer is never always right lol
upvoted 3 times
...
DaroKa
2 years, 7 months ago
Selected Answer: B
"increase the chance of detecting this traffic in the future"
upvoted 1 times
...
anap2022
2 years, 8 months ago
Selected Answer: B
I believe it would be B. The quickest way is to notify other analyst of the traffic so they can watch for it. Usually analyst notes are made and shared.
upvoted 1 times
...
TheStudiousPeepz
2 years, 8 months ago
Selected Answer: C
B doesn't help.
upvoted 1 times
...
R00ted
2 years, 8 months ago
Selected Answer: C
I am voting for C.
upvoted 1 times
Abyad
2 years, 7 months ago
C says for further review and analysis and the question says after resolving so we don't need further analysis!!!!!
upvoted 1 times
...
...
amateurguy
2 years, 9 months ago
Selected Answer: C
C is the smartest choice.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...