CAS-002 · Question #813
A security analyst, Ann, states that she believes Internet facing file transfer servers are being attacked. Which of the following is evidence that would aid Ann in making a case to management that…
The correct answer is D. Compare the current activity to the baseline of normal activity. Comparing current server activity against a known baseline is the strongest evidence of an attack because it quantifies the deviation from normal behavior, giving management concrete data to act on.
Question
A security analyst, Ann, states that she believes Internet facing file transfer servers are being attacked. Which of the following is evidence that would aid Ann in making a case to management that action needs to be taken to safeguard these servers?
Options
- AProvide a report of all the IP addresses that are connecting to the systems and their locations
- BEstablish alerts at a certain threshold to notify the analyst of high activity
- CProvide a report showing the file transfer logs of the servers
- DCompare the current activity to the baseline of normal activity
How the community answered
(42 responses)- A12% (5)
- B2% (1)
- C5% (2)
- D81% (34)
Why each option
Comparing current server activity against a known baseline is the strongest evidence of an attack because it quantifies the deviation from normal behavior, giving management concrete data to act on.
A list of connecting IP addresses and geolocations provides context but does not by itself demonstrate malicious behavior or prove the servers are under attack.
Setting up future alerting thresholds is a remediation step, not evidence of an ongoing or past attack that can be presented to management.
Raw file transfer logs show what happened but without a baseline for comparison they cannot distinguish abnormal attack traffic from normal high-volume usage.
A baseline represents the established normal traffic and usage patterns for the file transfer servers - comparing current activity to that baseline objectively highlights anomalies such as unusual connection volumes, transfer sizes, or timing that indicate an active attack. This approach transforms subjective concern into measurable, documentable evidence that management can evaluate and act upon.
Concept tested: Baseline comparison as evidence of anomalous server activity
Source: https://csrc.nist.gov/publications/detail/sp/800-92/final
Topics
Community Discussion
No community discussion yet for this question.