Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CompTIA CS0-003 Exam - Topic 2 Question 54 Discussion

During a training exercise, a security analyst must determine the vulnerabilities to prioritize. The analyst reviews the following vulnerability scan output:Which of the following issues should the analyst address first?
A) Allows anonymous read access to /etc/passwd
B) Allows anonymous read access via any FTP connection
C) Microsoft Defender security definition updates disabled
D) less command allows for escape exploit via terminal

CompTIA CS0-003 Exam - Topic 2 Question 54 Discussion

Actual exam question for CompTIA's CS0-003 exam
Question #: 54
Topic #: 2
[All CS0-003 Questions]

During a training exercise, a security analyst must determine the vulnerabilities to prioritize. The analyst reviews the following vulnerability scan output:

Which of the following issues should the analyst address first?

Show Suggested Answer Hide Answer
Suggested Answer: A

Allowing anonymous read access to /etc/passwd is a critical vulnerability because it can expose user account details, aiding attackers in password cracking and privilege escalation.

Option B (Anonymous FTP access) is a risk, but /etc/passwd exposure is more critical as it directly affects user authentication.

Option C (Defender updates disabled) is important, but it does not present an immediate attack vector like credential exposure.

Option D (less escape exploit) is significant, but it requires user interaction, making it less immediate than a global credential leak.

Thus, A is the correct answer, as it represents an immediate, high-impact security risk.


Contribute your Thoughts:

0/2000 characters
Mona
4 hours ago
I agree, but B is also a big risk. FTP access can expose a lot.
upvoted 0 times
...
Belen
5 days ago
I think option A is critical. /etc/passwd is sensitive.
upvoted 0 times
...
Vannessa
10 days ago
Totally agree with A), that's a classic vulnerability!
upvoted 0 times
...
Nickolas
16 days ago
D) is surprising, didn't know less could be exploited like that!
upvoted 0 times
...
Annita
2 months ago
C) seems serious, but is it really a top priority?
upvoted 0 times
...
Vonda
2 months ago
I think B) is worse, FTP access is a big deal.
upvoted 0 times
...
Tiera
2 months ago
A) is a huge risk, gotta fix that first!
upvoted 0 times
...
Madonna
3 months ago
I disagree, I’d prioritize C) for immediate protection.
upvoted 0 times
...
Edna
3 months ago
D) is surprising, didn’t know less had that exploit!
upvoted 0 times
...
Renea
3 months ago
C) is concerning, but it’s not as urgent as A).
upvoted 0 times
...
Rodolfo
3 months ago
I think B) is worse, FTP access is a big deal.
upvoted 0 times
...
Victor
3 months ago
A) is a huge risk, gotta fix that first!
upvoted 0 times
...
Glenn
3 months ago
The escape exploit via the less command sounds dangerous, but I wonder if it’s as critical as the anonymous access issues. I need to double-check how those exploits work.
upvoted 0 times
...
Toshia
4 months ago
I practiced a similar question where we had to choose between access issues and software updates. I think keeping Microsoft Defender updated is crucial, but it might not be the immediate threat.
upvoted 0 times
...
Laine
4 months ago
I'm not entirely sure, but I feel like the FTP access issue might be a bigger risk since it could expose multiple files, right?
upvoted 0 times
...
Brice
4 months ago
I remember we discussed prioritizing vulnerabilities based on potential impact. I think allowing anonymous read access to /etc/passwd could be really serious.
upvoted 0 times
...

Save Cancel