Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CompTIA Exam CS0-003 Topic 3 Question 45 Discussion

Actual exam question for CompTIA's CS0-003 exam
Question #: 45
Topic #: 3
[All CS0-003 Questions]

A company has the following security requirements:

. No public IPs

* All data secured at rest

. No insecure ports/protocols

After a cloud scan is completed, a security analyst receives reports that several misconfigurations are putting the company at risk. Given the following cloud scanner output:

Which of the following should the analyst recommend be updated first to meet the security requirements and reduce risks?

Show Suggested Answer Hide Answer
Suggested Answer: D

This VM has a public IP and an open port 80, which violates the company's security requirements of no public IPs and no insecure ports/protocols. It also exposes the VM to potential attacks from the internet. This VM should be updated first to use a private IP and close the port 80, or use a secure protocol such as HTTPS.

Reference[CompTIA CySA+ Study Guide: Exam CS0-003, 3rd Edition], Chapter 2: Cloud and Hybrid Environments, page 67.[What is a Public IP Address?][What is Port 80?]


Contribute your Thoughts:

William
15 hours ago
I agree with Svetlana, securing the production database should be the top priority.
upvoted 0 times
...
Svetlana
18 days ago
I think we should update VM_PRD_DB first.
upvoted 0 times
...

Save Cancel