nerdexam
CompTIA

CAS-002 · Question #813

A security analyst, Ann, states that she believes Internet facing file transfer servers are being attacked. Which of the following is evidence that would aid Ann in making a case to management that…

The correct answer is D. Compare the current activity to the baseline of normal activity. Comparing current server activity against a known baseline is the strongest evidence of an attack because it quantifies the deviation from normal behavior, giving management concrete data to act on.

Research and Analysis

Question

A security analyst, Ann, states that she believes Internet facing file transfer servers are being attacked. Which of the following is evidence that would aid Ann in making a case to management that action needs to be taken to safeguard these servers?

Options

  • AProvide a report of all the IP addresses that are connecting to the systems and their locations
  • BEstablish alerts at a certain threshold to notify the analyst of high activity
  • CProvide a report showing the file transfer logs of the servers
  • DCompare the current activity to the baseline of normal activity

How the community answered

(42 responses)
  • A
    12% (5)
  • B
    2% (1)
  • C
    5% (2)
  • D
    81% (34)

Why each option

Comparing current server activity against a known baseline is the strongest evidence of an attack because it quantifies the deviation from normal behavior, giving management concrete data to act on.

AProvide a report of all the IP addresses that are connecting to the systems and their locations

A list of connecting IP addresses and geolocations provides context but does not by itself demonstrate malicious behavior or prove the servers are under attack.

BEstablish alerts at a certain threshold to notify the analyst of high activity

Setting up future alerting thresholds is a remediation step, not evidence of an ongoing or past attack that can be presented to management.

CProvide a report showing the file transfer logs of the servers

Raw file transfer logs show what happened but without a baseline for comparison they cannot distinguish abnormal attack traffic from normal high-volume usage.

DCompare the current activity to the baseline of normal activityCorrect

A baseline represents the established normal traffic and usage patterns for the file transfer servers - comparing current activity to that baseline objectively highlights anomalies such as unusual connection volumes, transfer sizes, or timing that indicate an active attack. This approach transforms subjective concern into measurable, documentable evidence that management can evaluate and act upon.

Concept tested: Baseline comparison as evidence of anomalous server activity

Source: https://csrc.nist.gov/publications/detail/sp/800-92/final

Topics

#baseline analysis#network monitoring#incident response#threat evidence

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice