nerdexam
ExamsCAS-001Questions#530
CompTIA

CAS-001 · Question #530

CAS-001 Question #530: Real Exam Question with Answer & Explanation

Sign in or unlock CAS-001 to reveal the answer and full explanation for question #530. The question stem and answer options stay visible for context.

Question

The Information Security Officer (ISO) believes that the company has been targeted by cybercriminals and it is under a cyber attack. Internal services that are normally available to the public via the Internet are inaccessible, and employees in the office are unable to browse the Internet. The senior security engineer starts by reviewing the bandwidth at the border router, and notices that the incoming bandwidth on the router's external interface is maxed out. The security engineer then inspects the following piece of log to try and determine the reason for the downtime, focusing on the company's external router's IP which is 128.20.176.19: 11:16:22.110343 IP 90.237.31.27.19 > 128.20.176.19.19: UDP, length 1400 11:16:22.110351 IP 23.27.112.200.19 > 128.20.176.19.19: UDP, length 1400 11:16:22.110358 IP 192.200.132.213.19 > 128.20.176.19.19: UDP, length 1400 11:16:22.110402 IP 70.192.2.55.19 > 128.20.176.19.19: UDP, length 1400 11:16:22.110406 IP 112.201.7.39.19 > 128.20.176.19.19: UDP, length 1400 Which of the following describes the findings the senior security engineer should report to the ISO and the BEST solution for service restoration?

Options

  • AAfter the senior engineer used a network analyzer to identify an active Fraggle attack, the
  • BAfter the senior engineer used the above IPS logs to detect the ongoing DDOS attack, an IPS
  • CAfter the senior engineer used a mirror port to capture the ongoing amplification attack, a BGP
  • DAfter the senior engineer used a packet capture to identify an active Smurf attack, an ACL should

Unlock CAS-001 to see the answer

You've previewed enough free CAS-001 questions. Unlock CAS-001 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full CAS-001 Practice