nerdexam
CompTIA

PT0-002 · Question #353

A penetration tester gains access to a web server and notices a large number of devices in the system ARP table. Upon scanning the web server, the tester determines that many of the devices are user w

The correct answer is C. Place the web server in a screened subnet. Placing the web server in a screened subnet (also known as a DMZ, or demilitarized zone) is a network security measure that isolates the web server from the internal network. This setup limits the ability of an attacker who gains access to the web server to move laterally and com

Reporting and Communication

Question

A penetration tester gains access to a web server and notices a large number of devices in the system ARP table. Upon scanning the web server, the tester determines that many of the devices are user workstations. Which of the following should be included in the recommendations for remediation?

Options

  • AStart a training program on proper access to the web server.
  • BBuild a patch-management program for the web server.
  • CPlace the web server in a screened subnet
  • DImplement endpoint protection on the workstations.

How the community answered

(29 responses)
  • A
    17% (5)
  • B
    7% (2)
  • C
    72% (21)
  • D
    3% (1)

Explanation

Placing the web server in a screened subnet (also known as a DMZ, or demilitarized zone) is a network security measure that isolates the web server from the internal network. This setup limits the ability of an attacker who gains access to the web server to move laterally and compromise other devices on the internal network, such as user workstations. It helps contain any potential breaches and adds an extra layer of security.

Topics

#Network segmentation#DMZ#Web server security#Remediation

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice