nerdexam
CompTIA

CS0-003 · Question #105

A security analyst at example.com receives SIEM alert for an IDS signature and reviews the associated packet capture and TCP stream: Packet capture: TCP stream: Which of the following actions should t

The correct answer is B. Contact the application owner for connect.example.local for additional information.. Anytime we receive alerts/offenses that appears to be a potential scan (interna/external), we already verify with the app owner/client if this was expected activity. We never close a ticket without confirmation, even its from an approved source.

Submitted by hassan_iq· Mar 6, 2026Incident Response and Management

Question

A security analyst at example.com receives SIEM alert for an IDS signature and reviews the associated packet capture and TCP stream:

Packet capture:

TCP stream:

Which of the following actions should the security analyst take NEXT?

Exhibits

CS0-003 question #105 exhibit 1
CS0-003 question #105 exhibit 2

Options

  • AReview the known Apache vulnerabilities to determine if a compromise actually occurred
  • BContact the application owner for connect.example.local for additional information.
  • CMark the alert as a false positive scan coming from an approved source.
  • DRaise a request to the firewall team to block 203.0.113.15.

How the community answered

(21 responses)
  • B
    86% (18)
  • C
    5% (1)
  • D
    10% (2)

Explanation

Anytime we receive alerts/offenses that appears to be a potential scan (interna/external), we already verify with the app owner/client if this was expected activity. We never close a ticket without confirmation, even its from an approved source.

Topics

#Incident triage#SIEM analysis#Packet analysis#Stakeholder communication

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice