nerdexam
CompTIA

CS0-003 · Question #153

While reviewing web server logs, an analyst notices several entries with the same time stamps, but all contain odd characters in the request line. Which of the following steps should be taken next?

The correct answer is B. Determine what attack the odd characters are indicative of.. Determining what attack the odd characters are indicative of is the next step that should be taken after reviewing web server logs and noticing several entries with the same time stamps, but all contain odd characters in the request line. This step can help the analyst identify t

Submitted by hans_de· Mar 6, 2026Incident Response and Management

Question

While reviewing web server logs, an analyst notices several entries with the same time stamps, but all contain odd characters in the request line. Which of the following steps should be taken next?

Options

  • AShut the network down immediately and call the next person in the chain of command.
  • BDetermine what attack the odd characters are indicative of.
  • CUtilize the correct attack framework and determine what the incident response will consist of.
  • DNotify the local law enforcement for incident response.

How the community answered

(58 responses)
  • A
    2% (1)
  • B
    90% (52)
  • C
    2% (1)
  • D
    7% (4)

Explanation

Determining what attack the odd characters are indicative of is the next step that should be taken after reviewing web server logs and noticing several entries with the same time stamps, but all contain odd characters in the request line. This step can help the analyst identify the type and severity of the attack, as well as the possible source and motive of the attacker. The odd characters in the request line may indicate that the attacker is trying to exploit a vulnerability or inject malicious code into the web server or application, such as SQL injection, cross-site scripting, buffer overflow, or command injection. The analyst can use tools and techniques such as log analysis, pattern matching, signature detection, or threat intelligence to determine what attack the odd characters are indicative of, and then proceed to the next steps of incident response, such as containment, eradication, recovery, and lessons learned.

Topics

#log analysis#attack identification#web server security

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice