Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-215 Exam - Topic 5 Question 49 Discussion

Refer to the exhibit.Which two determinations should be made about the attack from the Apache access logs? (Choose two.)
A) The attacker used r57 exploit to elevate their privilege.
B) The attacker uploaded the word press file manager trojan.
C) The attacker performed a brute force attack against word press and used sql injection against the backend database.
D) The attacker used the word press file manager plugin to upoad r57.php.
E) The attacker logged on normally to word press admin page.

Cisco 300-215 Exam - Topic 5 Question 49 Discussion

Actual exam question for Cisco's 300-215 exam
Question #: 49
Topic #: 5
[All 300-215 Questions]

Refer to the exhibit.

Which two determinations should be made about the attack from the Apache access logs? (Choose two.)

Show Suggested Answer Hide Answer
Suggested Answer: A

Contribute your Thoughts:

0/2000 characters
Soledad
10 months ago
Agreed, B and D are spot on!
upvoted 0 times
...
Danica
10 months ago
E doesn't make sense, they wouldn't log in normally after an attack.
upvoted 0 times
...
Ressie
10 months ago
Wait, are we sure about A? That seems a bit far-fetched.
upvoted 0 times
...
Brande
11 months ago
I think C is more likely, brute force and SQL injection are common.
upvoted 0 times
...
Lyla
11 months ago
Definitely B and D, those are classic signs of a compromise.
upvoted 0 times
...
Ashlyn
11 months ago
The option about using the word press file manager plugin sounds familiar; I think we covered that in a case study last week.
upvoted 0 times
...
Malinda
11 months ago
I feel like the brute force attack option is relevant, but I can't recall if we discussed it in relation to SQL injection specifically.
upvoted 0 times
...
Nadine
11 months ago
I think the word press file manager trojan was a common example in our practice questions, so that might be a good choice.
upvoted 0 times
...
Tawna
11 months ago
I remember studying about the r57 exploit, but I'm not entirely sure if it was specifically mentioned in the logs.
upvoted 0 times
...
Elvis
11 months ago
Hmm, I'm not entirely sure about this one. I'll need to review my notes on product development strategies to see which one is most suitable for dealing with complexity.
upvoted 0 times
...
Gerald
11 months ago
Based on the question, it seems like we need to identify the Cisco UCS Servers that support converged nodes in HyperFlex Data Platform. I'll focus on that and try to eliminate the options that don't fit.
upvoted 0 times
...
Buddy
11 months ago
This looks like a straightforward question on wireless authentication methods. I think the key is to identify the requirement for smart card authentication in the company's security policy.
upvoted 0 times
...
Lynda
1 year ago
I love how the question is trying to trick us with those answer choices. Gotta stay on our toes for these tricky certification exams, am I right? *chuckles*
upvoted 0 times
Ruth
1 year ago
Yeah, they definitely try to make it tricky with those answer choices. Gotta be careful with these exams.
upvoted 0 times
...
Detra
1 year ago
C) The attacker performed a brute force attack against word press and used sql injection against the backend database.
upvoted 0 times
...
Haydee
1 year ago
A) The attacker used r57 exploit to elevate their privilege.
upvoted 0 times
...
...
Allene
1 year ago
Definitely not E! Logging in normally to the admin page is not an 'attack' per se. The logs point to more sophisticated attempts to compromise the system.
upvoted 0 times
...
Ryan
1 year ago
D looks promising too. The file manager plugin could have been used to upload the r57.php shell. But I agree B and C are the best choices based on the information provided.
upvoted 0 times
Domitila
1 year ago
True, D is a possibility as well. But B and C are still the most likely determinations based on the Apache access logs.
upvoted 0 times
...
Ayesha
1 year ago
D looks promising too. The file manager plugin could have been used to upload the r57.php shell.
upvoted 0 times
...
Kassandra
1 year ago
Agreed. The brute force attack and sql injection against the backend database seem like the most likely scenarios.
upvoted 0 times
...
Brandon
1 year ago
I think B and C are the best choices. The attacker uploaded the word press file manager trojan and performed a brute force attack against word press.
upvoted 0 times
...
Julio
1 year ago
That's true, D could also be a possibility. But B and C are still the most likely determinations.
upvoted 0 times
...
Jestine
1 year ago
D looks promising too. The file manager plugin could have been used to upload the r57.php shell.
upvoted 0 times
...
Dorinda
1 year ago
Agreed, those seem to be the most likely scenarios based on the Apache access logs.
upvoted 0 times
...
Andrew
1 year ago
I think B and C are the best choices. The attacker uploaded the word press file manager trojan and performed a brute force attack with sql injection.
upvoted 0 times
...
...
Carmela
1 year ago
I think the correct answers are B and C. The access logs show clear signs of a WordPress attack, including attempted SQL injection and uploading of a malicious file.
upvoted 0 times
...
Selma
1 year ago
I agree with Rosamond and Dalene, those seem like the most likely determinations based on the Apache access logs.
upvoted 0 times
...
Dalene
1 year ago
I believe the attacker uploaded the word press file manager trojan.
upvoted 0 times
...
Rosamond
1 year ago
I think the attacker used the r57 exploit to elevate their privilege.
upvoted 0 times
...

Save Cancel