SK0-005 · Question #297
The network's IDS is giving multiple alerts that unauthorized traffic from a critical application server is being sent to a known-bad public IP address. One of the alerts contains the following inform
Sign in or unlock SK0-005 to reveal the answer and full explanation for question #297. The question stem and answer options stay visible for context.
Question
The network's IDS is giving multiple alerts that unauthorized traffic from a critical application server is being sent to a known-bad public IP address. One of the alerts contains the following information:
Exploit Alert Attempted User Privilege Gain 2/2/07-3:09:09 10.1.200.32 --> 208.206.12.9:80 This server application is part of a cluster in which two other servers are also servicing clients. The server administrator has verified the other servers are not sending out traffic to that public IP address. The IP address subnet of the application servers is 10.1.200.0/26. Which of the following should the administrator perform to ensure only authorized traffic is being sent from the application server and downtime is minimized? (Choose two.)
Options
- ADisable all services on the affected application server.
- BPerform a vulnerability scan on all the servers within the cluster and patch accordingly.
- CBlock access to 208.206.12.9 from all servers on the network.
- DChange the IP address of all the servers in the cluster to the 208.206.12.0/26 subnet.
- EEnable GPO to install an antivirus on all the servers and perform a weekly reboot.
- FPerform an antivirus scan on all servers within the cluster and reboot each server.
Unlock SK0-005 to see the answer
You've previewed enough free SK0-005 questions. Unlock SK0-005 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.