nerdexam
CompTIA

SK0-005 · Question #421

IDS alerts indicate abnormal traffic patterns are coming from a specific server in a data center that hosts sensitive data. Upon further investigation, the server administrator notices this server…

The correct answer is A. Run a vulnerability scanner on the server. C. Patch the vulnerability. F. Update the antivirus software. After removing the virus from the server, the administrator should perform the following actions to mitigate the issue from reoccurring and to maintain high availability: Run a vulnerability scanner on the server to identify any other potential weaknesses or exposures that…

Security and disaster recovery

Question

IDS alerts indicate abnormal traffic patterns are coming from a specific server in a data center that hosts sensitive data. Upon further investigation, the server administrator notices this server has been infected with a virus due to an exploit of a known vulnerability from its database software. Which of the following should the administrator perform after removing the virus to mitigate this issue from reoccurring and to maintain high availability? (Choose three.)

Options

  • ARun a vulnerability scanner on the server.
  • BRepartition the hard drive that houses the database.
  • CPatch the vulnerability.
  • DEnable a host firewall.
  • EReformat the OS on the server.
  • FUpdate the antivirus software.
  • GRemove the database software.
  • HAir gap the server from the network.

How the community answered

(38 responses)
  • A
    74% (28)
  • B
    3% (1)
  • D
    5% (2)
  • E
    16% (6)
  • H
    3% (1)

Explanation

After removing the virus from the server, the administrator should perform the following actions to mitigate the issue from reoccurring and to maintain high availability: Run a vulnerability scanner on the server to identify any other potential weaknesses or exposures that could be exploited by attackers. Patch the vulnerability that allowed the virus to infect the server in the first place, using the latest updates from the database software vendor or a trusted source. Update the antivirus software on the server to ensure it has the most recent virus definitions and can detect and prevent future infections. The other options are either unnecessary or counterproductive for this scenario. Repartitioning the hard drive, reformatting the OS, removing the database software, or air gapping the server from the network would cause downtime and data loss, while enabling a host firewall would not prevent a virus infection from within the network.

Topics

#Vulnerability Management#Patch Management#Incident Response#Malware Protection

Community Discussion

No community discussion yet for this question.

Full SK0-005 Practice