nerdexam
CompTIA

CAS-005 · Question #24

A security analyst received a notification from a cloud service provider regarding an attack detected on a web server. The cloud service provider shared the following information about the attack: - T

Sign in or unlock CAS-005 to reveal the answer and full explanation for question #24. The question stem and answer options stay visible for context.

Submitted by daniela_cl· Mar 6, 2026Security Operations

Question

A security analyst received a notification from a cloud service provider regarding an attack detected on a web server. The cloud service provider shared the following information about the attack:

  • The attack came from inside the network.
  • The attacking source IP was from the internal vulnerability scanners
  • The scanner is not configured to target the cloud servers.

Which of the following actions should the security analyst take first?

Options

  • ACreate an allow list for the vulnerability scanner IPs m order to avoid false positives
  • BConfigure the scan policy to avoid targeting an out-of-scope host
  • CSet network behavior analysis rules
  • DQuarantine the scanner sensor to perform a forensic analysis

Unlock CAS-005 to see the answer

You've previewed enough free CAS-005 questions. Unlock CAS-005 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full CAS-005 Practice