Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-215 Exam - Topic 3 Question 80 Discussion

An engineer received a call to assist with an ongoing DDoS attack. The Apache server is being targeted, and availability is compromised. Which step should be taken to identify the origin of the threat?
B) An engineer should check the server's processes by running commands ps -aux and sudo ps -a.
A) An engineer should check the list of usernames currently logged in by running the command $ who | cut -- d' ' -f1| sort | uniq
C) An engineer should check the services on the machine by running the command service -status-all.
D) An engineer should check the last hundred entries of a web server with the command sudo tail -100 /var/ log/apache2/access.log.

Cisco 300-215 Exam - Topic 3 Question 80 Discussion

Actual exam question for Cisco's 300-215 exam
Question #: 80
Topic #: 3
[All 300-215 Questions]

An engineer received a call to assist with an ongoing DDoS attack. The Apache server is being targeted, and availability is compromised. Which step should be taken to identify the origin of the threat?

Show Suggested Answer Hide Answer
Suggested Answer: B

Contribute your Thoughts:

0/2000 characters
Mattie
9 months ago
D definitely gives you the most insight into traffic patterns.
upvoted 0 times
...
Hui
9 months ago
Wait, can you really trace it just from access logs?
upvoted 0 times
...
Zoila
10 months ago
A seems kinda off for a DDoS attack.
upvoted 0 times
...
Nadine
10 months ago
I think B is more relevant for processes.
upvoted 0 times
...
Lisha
10 months ago
D is the best choice to find the source!
upvoted 0 times
...
Adelina
10 months ago
I think looking at the server processes might give some insight, but I feel like the access log is more directly related to identifying the attack's origin.
upvoted 0 times
...
Samira
11 months ago
I’m a bit confused about whether checking logged-in users would really help with a DDoS attack. It seems more relevant for security breaches.
upvoted 0 times
...
Terrilyn
11 months ago
I remember practicing a similar question where we had to analyze logs to find suspicious activity. I feel like option D makes the most sense here.
upvoted 0 times
...
James
11 months ago
I think checking the access log could help identify the source of the DDoS attack, but I'm not entirely sure if it's the best first step.
upvoted 0 times
...
Narcisa
11 months ago
This seems straightforward. I'd go with option D and check the Apache access logs to try to trace the origin of the DDoS attack.
upvoted 0 times
...
Floyd
11 months ago
I've got a strategy in mind - I'll check the Apache server logs to see if I can find any suspicious activity or IP addresses that could be the source of the attack.
upvoted 0 times
...
King
11 months ago
I'm not totally sure about this one. Maybe I should review the material on DDoS attacks again before attempting to answer.
upvoted 0 times
...
Cruz
11 months ago
Okay, let's see. I think checking the server processes and logs would be a good place to start to identify the source of the attack.
upvoted 0 times
...
Yvette
11 months ago
Hmm, this seems like a tricky one. I'll need to think carefully about the best approach here.
upvoted 0 times
...
Goldie
11 months ago
I'm a little confused by the wording of the question. Does "recommend a solution" mean I need to explain the pros and cons of each option, or just identify the correct one? I want to make sure I understand the task properly before answering.
upvoted 0 times
...
Cherrie
11 months ago
This is a tricky one. The supplier's history of overestimating volume is a major concern, so I'll need to dig into that and see what kind of mitigation strategies I can come up with. Hopefully I can find the right balance of monitoring and control.
upvoted 0 times
...
Anika
1 year ago
I'm just glad I didn't try to fix this by turning it off and on again. That's the IT version of 'thoughts and prayers'.
upvoted 0 times
...
Thomasena
1 year ago
Bingo! Checking the Apache access logs is the way to go. I bet we'll find some juicy information there.
upvoted 0 times
...
Vicente
1 year ago
Hmm, I'm not sure checking the service status will really help us identify the origin of the DDoS attack. We need to dig deeper into the server logs.
upvoted 0 times
Mattie
1 year ago
I agree, we need to analyze the server logs to track down the source of the attack.
upvoted 0 times
...
Armando
1 year ago
D) An engineer should check the last hundred entries of a web server with the command sudo tail -100 /var/ log/apache2/access.log.
upvoted 0 times
...
Gracia
1 year ago
B) An engineer should check the server's processes by running commands ps -aux and sudo ps -a.
upvoted 0 times
...
Susy
1 year ago
A) An engineer should check the list of usernames currently logged in by running the command $ who | cut -- d' ' -f1| sort | uniq
upvoted 0 times
...
...
Beata
1 year ago
Yes, checking the server processes is a great idea! That should give us some clues about what's causing the issue.
upvoted 0 times
Norah
1 year ago
Engineer 1: Agreed, let's see if we can pinpoint the problem.
upvoted 0 times
...
Precious
1 year ago
Engineer 2: Good idea, that should help us identify the source of the DDoS attack.
upvoted 0 times
...
Oliva
1 year ago
Engineer 1: Let's check the server processes by running ps -aux and sudo ps -a.
upvoted 0 times
...
...
Rosenda
1 year ago
I think checking the list of logged-in usernames is a bit overkill for a DDoS attack. Let's focus on the server processes and logs instead.
upvoted 0 times
Timothy
1 year ago
I agree, focusing on server processes and logs is more relevant for identifying the origin of the DDoS attack.
upvoted 0 times
...
Carmelina
1 year ago
B) An engineer should check the last hundred entries of a web server with the command sudo tail -100 /var/ log/apache2/access.log.
upvoted 0 times
...
Hollis
1 year ago
B) An engineer should check the last hundred entries of a web server with the command sudo tail -100 /var/ log/apache2/access.log.
upvoted 0 times
...
Noah
1 year ago
A) An engineer should check the server's processes by running commands ps -aux and sudo ps -a.
upvoted 0 times
...
Alyce
1 year ago
A) An engineer should check the server's processes by running commands ps -aux and sudo ps -a.
upvoted 0 times
...
...
Chantell
1 year ago
That's a good point, Ricarda. It's important to consider all options before making a decision.
upvoted 0 times
...
Ricarda
1 year ago
I disagree, I believe option B is more effective. Checking the server's processes can give us insight into any suspicious activity.
upvoted 0 times
...
Chantell
1 year ago
I think option D is the best choice. Checking the last hundred entries of the web server can help identify the source of the attack.
upvoted 0 times
...
Alaine
1 year ago
I'm not sure, but I think option B could also be useful. Checking the server's processes might give us some clues about the attack.
upvoted 0 times
...
Sherman
1 year ago
I agree with Geoffrey. Option D seems like the most effective way to track down the source of the DDoS attack.
upvoted 0 times
...
Geoffrey
1 year ago
I think option D is the best choice. Checking the last hundred entries of the web server can help identify the origin of the threat.
upvoted 0 times
...

Save Cancel