CS0-003 · Question #376
An analyst views the following log entries: The organization has a partner vendor with hosts in the 216.122.5.x range. This partner vendor is required to have access to monthly reports and is the only
The correct answer is A. 121.19.30.221. Option A (121.19.30.221) is correct because this host falls outside both the organization's internal network range and the authorized partner vendor range (216.122.5.x), making it an unauthorized external host - which directly signals a potential unauthorized data disclosure. Sin
Question
An analyst views the following log entries:
The organization has a partner vendor with hosts in the 216.122.5.x range. This partner vendor is required to have access to monthly reports and is the only external vendor with authorized access. The organization prioritizes incident investigation according to the following hierarchy:
- unauthorized data disclosure is more critical than denial of service
attempts.
- which are more important than ensuring vendor data access.
Based on the log files and the organization's priorities, which of the following hosts warrants additional investigation?
Exhibit
Options
- A121.19.30.221
- B134.17.188.5
- C202.180.1582
- D216.122.5.5
How the community answered
(20 responses)- A80% (16)
- B5% (1)
- C10% (2)
- D5% (1)
Explanation
Option A (121.19.30.221) is correct because this host falls outside both the organization's internal network range and the authorized partner vendor range (216.122.5.x), making it an unauthorized external host - which directly signals a potential unauthorized data disclosure. Since the organization's highest priority is unauthorized data disclosure, this unknown external IP accessing organizational resources demands immediate investigation.
Option D (216.122.5.5) is incorrect because this host belongs to the authorized partner vendor subnet (216.122.5.x) and has legitimate, sanctioned access to monthly reports - no investigation needed. Option B (134.17.188.5) may represent a denial-of-service attempt, which is the organization's second priority, but if Option A represents unauthorized disclosure, it must be investigated first per the stated hierarchy. Option C (202.180.1582) contains an invalid IP address (the third octet "1582" exceeds the maximum value of 255), making it a malformed/non-actionable log entry that would not warrant investigation.
Memory Tip: Think "Unknown = #1 threat." When prioritizing incidents, always map IP addresses to authorized ranges first. Any unrecognized external IP accessing sensitive data jumps to the top of the investigation list - before DoS attempts and vendor access issues.
Topics
Community Discussion
No community discussion yet for this question.
