nerdexam
CompTIA

CS0-003 · Question #437

SIMULATION An organization's website was maliciously altered. INSTRUCTIONS Review information in each tab to select the source IP the analyst should be concerned about, the indicator of compromise, an

The source IP 41.21.18.102 is an external/public IP address indicating an outside threat actor who maliciously altered the website, making it the primary concern over internal RFC 1918 addresses. The modified index.html file is the direct indicator of compromise (IoC) because it

Submitted by packet_pusher· Mar 6, 2026CompTIA Security+ Domain 4: Security Operations - Incident response procedures, identifying IoCs, and implementing appropriate corrective actions following a security incident.

Question

SIMULATION An organization's website was maliciously altered. INSTRUCTIONS Review information in each tab to select the source IP the analyst should be concerned about, the indicator of compromise, and the two appropriate corrective actions. Answer:

Exhibits

CS0-003 question #437 exhibit 1
CS0-003 question #437 exhibit 2
CS0-003 question #437 exhibit 3
CS0-003 question #437 exhibit 4

Explanation

The source IP 41.21.18.102 is an external/public IP address indicating an outside threat actor who maliciously altered the website, making it the primary concern over internal RFC 1918 addresses. The modified index.html file is the direct indicator of compromise (IoC) because it represents the actual evidence of the website defacement attack. Changing the password on the sjames account addresses a likely compromised credential used in the attack, while denying the internal 192.168.* range at the firewall would be incorrect because blocking internal traffic would disrupt legitimate operations - the correct block should target the malicious external IP.

Topics

#Incident Response#Indicators of Compromise#Web Application Security#Corrective Controls

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice