Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CompTIA Exam CS0-003 Topic 2 Question 20 Discussion

Actual exam question for CompTIA's CS0-003 exam
Question #: 20
Topic #: 2
[All CS0-003 Questions]

An analyst has discovered the following suspicious command:

Which of the following would best describe the outcome of the command?

Show Suggested Answer Hide Answer
Suggested Answer: B

The security analyst is validating a Local File Inclusion (LFI) vulnerability, as indicated by the ''/.../.../.../'' in the GET request which is a common indicator of directory traversal attempts associated with LFI. The other options are not relevant for this purpose: SQL injection involves injecting malicious SQL statements into a database query; XSS involves injecting malicious scripts into a web page; CSRF involves tricking a user into performing an unwanted action on a web application.


According to the CompTIA CySA+ Study Guide: Exam CS0-003, 3rd Edition1, one of the objectives for the exam is to ''use appropriate tools and methods to manage, prioritize and respond to attacks and vulnerabilities''. The book also covers the usage and syntax of Burp Suite, a tool used for testing web application security, in chapter 6. Specifically, it explains the meaning and function of each component in Burp Suite, such as Repeater, which allows the security analyst to modify and resend individual requests1, page 239. Therefore, this is a reliable source to verify the answer to the question.

Contribute your Thoughts:

Aja
2 days ago
Haha, a logic bomb? Really? That's just too funny. I'm gonna have to go with B - Reverse shell. Can't mess around with that kind of stuff!
upvoted 0 times
...
Shawna
6 days ago
I'm not sure, but I think it could also be a backdoor attempt.
upvoted 0 times
...
Delisa
7 days ago
Hmm, I'm not sure if that's a reverse shell or a backdoor attempt. Either way, it's not good news! C seems like the safest bet here.
upvoted 0 times
...
Erin
8 days ago
Oh man, that command looks super shady! I'm gonna go with B - Reverse shell. Sounds like someone's trying to get remote access to the system.
upvoted 0 times
...
Marcos
11 days ago
I agree with Peggie, it does look like a reverse shell.
upvoted 0 times
...
Peggie
14 days ago
I think the outcome of the command is a reverse shell.
upvoted 0 times
...

Save Cancel