nerdexam
CompTIA

SK0-003 · Question #463

When a technician left the server room Monday evening everything was operational. When the technician returned Tuesday morning, the front bezel was off of the mail server, and it had been powered off.

The correct answer is D. Server room access log. Given that a server's front bezel was removed and it was powered off overnight, the server room access log should be checked first to identify who might have physically accessed the server and why. This is a security and incident response issue before it is a technical troublesho

Security and disaster recovery

Question

When a technician left the server room Monday evening everything was operational. When the technician returned Tuesday morning, the front bezel was off of the mail server, and it had been powered off. Which of the following should be checked FIRST?

Options

  • ATCP/IP settings
  • BRAID configuration
  • CWhether the power cord is attached
  • DServer room access log

How the community answered

(35 responses)
  • A
    17% (6)
  • B
    6% (2)
  • C
    9% (3)
  • D
    69% (24)

Why each option

Given that a server's front bezel was removed and it was powered off overnight, the server room access log should be checked first to identify who might have physically accessed the server and why. This is a security and incident response issue before it is a technical troubleshooting one.

ATCP/IP settings

TCP/IP settings are software configurations and would not explain the physical tampering or unexpected power-off of the server.

BRAID configuration

The RAID configuration relates to disk storage and redundancy, which is not the immediate concern when a server is physically tampered with and powered off.

CWhether the power cord is attached

While the power cord might be detached, the more pressing concern is *why* someone would access the server and detach it, which is addressed by checking the access log.

DServer room access logCorrect

The physical tampering (bezel off) and unexpected power-off suggest unauthorized physical access or malicious activity. Checking the server room access log first is crucial to identify who entered the room and at what time, which can help determine the cause of the server's state and rule out a security breach.

Concept tested: Incident response and physical security

Topics

#physical security#server room access#incident response#troubleshooting methodology

Community Discussion

No community discussion yet for this question.

Full SK0-003 Practice