nerdexam
CompTIA

CS0-003 · Question #397

A security analyst is reviewing events that occurred during a possible compromise. The analyst obtains the following log: Which of the following is most likely occurring, based on the events in the lo

The correct answer is B. An adversary is performing a vulnerability scan.. Based on the events in the log, the most likely occurrence is that an adversary is performing a vulnerability scan. The log shows LDAP read operations and EDR enumerating local groups, which are indicative of an adversary scanning the system to find vulnerabilities or sensitive i

Submitted by weili_xi· Mar 6, 2026Security Operations

Question

A security analyst is reviewing events that occurred during a possible compromise. The analyst obtains the following log:

Which of the following is most likely occurring, based on the events in the log?

Exhibit

CS0-003 question #397 exhibit

Options

  • AAn adversary is attempting to find the shortest path of compromise.
  • BAn adversary is performing a vulnerability scan.
  • CAn adversary is escalating privileges.
  • DAn adversary is performing a password stuffing attack.

How the community answered

(31 responses)
  • A
    10% (3)
  • B
    71% (22)
  • C
    16% (5)
  • D
    3% (1)

Explanation

Based on the events in the log, the most likely occurrence is that an adversary is performing a vulnerability scan. The log shows LDAP read operations and EDR enumerating local groups, which are indicative of an adversary scanning the system to find vulnerabilities or sensitive information. The final entry shows SMB connection attempts to multiple hosts from a single host, which could be a sign of network discovery or lateral movement.

Topics

#log analysis#vulnerability scanning#reconnaissance#adversary TTPs

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice