Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CompTIA CS0-003 Exam - Topic 2 Question 57 Discussion

While reviewing web server logs, an analyst notices several entries with the same time stamps, but all contain odd characters in the request line. Which of the following steps should be taken next?
B) Determine what attack the odd characters are indicative of
A) Shut the network down immediately and call the next person in the chain of command.
C) Utilize the correct attack framework and determine what the incident response will consist of.
D) Notify the local law enforcement for incident response

CompTIA CS0-003 Exam - Topic 2 Question 57 Discussion

Actual exam question for CompTIA's CS0-003 exam
Question #: 57
Topic #: 2
[All CS0-003 Questions]

While reviewing web server logs, an analyst notices several entries with the same time stamps, but all contain odd characters in the request line. Which of the following steps should be taken next?

Show Suggested Answer Hide Answer
Suggested Answer: B

Determining what attack the odd characters are indicative of is the next step that should be taken after reviewing web server logs and noticing several entries with the same time stamps, but all contain odd characters in the request line. This step can help the analyst identify the type and severity of the attack, as well as the possible source and motive of the attacker. The odd characters in the request line may indicate that the attacker is trying to exploit a vulnerability or inject malicious code into the web server or application, such as SQL injection, cross-site scripting, buffer overflow, or command injection. The analyst can use tools and techniques such as log analysis, pattern matching, signature detection, or threat intelligence to determine what attack the odd characters are indicative of, and then proceed to the next steps of incident response, such as containment, eradication, recovery, and lessons learned. Official Reference:

https://partners.comptia.org/docs/default-source/resources/comptia-cysa-cs0-002-exam-objectives

https://www.comptia.org/certifications/cybersecurity-analyst

https://www.comptia.org/blog/the-new-comptia-cybersecurity-analyst-your-questions-answered


Contribute your Thoughts:

0/2000 characters
Eleonora
1 month ago
I think shutting down the network immediately is too drastic. We should first analyze the logs before taking such extreme measures, right?
upvoted 0 times
...
Cory
1 month ago
I’m not entirely sure, but I feel like we practiced a similar question where we had to analyze logs for potential threats. Maybe using an attack framework is important?
upvoted 0 times
...
Elena
1 month ago
I remember discussing how odd characters in logs could indicate an injection attack, so I think option B makes sense.
upvoted 0 times
...

Save Cancel