exam questions

Exam CS0-003 All Questions

View all questions & answers for the CS0-003 exam

Exam CS0-003 topic 1 question 55 discussion

Actual exam question from CompTIA's CS0-003
Question #: 55
Topic #: 1
[All CS0-003 Questions]

During an extended holiday break, a company suffered a security incident. This information was properly relayed to appropriate personnel in a timely manner and the server was up to date and configured with appropriate auditing and logging. The Chief Information Security Officer wants to find out precisely what happened. Which of the following actions should the analyst take first?

  • A. Clone the virtual server for forensic analysis
  • B. Log m to the affected server and begin analysis of the logs
  • C. Restore from the last known-good backup to confirm there was no loss of connectivity
  • D. Shut down the affected server immediately
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Gway
Highly Voted 1 year, 7 months ago
Selected Answer: A
A. Clone the virtual server for forensic analysis Cloning the virtual server allows the analyst to capture a snapshot of the system as it is, including all current data, configurations, and state. This cloned version can be analyzed in detail without affecting the integrity of the original server, which is crucial for any potential legal proceedings and for understanding the scope and details of the attack.
upvoted 25 times
...
kmordalv
Highly Voted 1 year, 7 months ago
Selected Answer: A
The first action that the analyst should take in this case is to clone the virtual server for forensic analysis. Cloning the virtual server can help preserve and protect any evidence or information related to the security incident, as well as prevent any tampering, contamination, or destruction of evidence.
upvoted 10 times
...
Just2a
Most Recent 4 weeks ago
Selected Answer: B
Question didnt say a VM, so why clone? Server is up to date and config for logging. So answer will be Log on to server and start analyzing logs to know what happened.
upvoted 1 times
...
scarceanimal
6 months ago
Selected Answer: A
It is NOT D if you shut it down how will you get the logs... Also not B, since you don't want to alter evidence. A is the answer. Refer to the Incident Response Order Of Operations by NIST
upvoted 2 times
...
riccardoprioleau
7 months, 2 weeks ago
The answer is D, while cloning will explain what happened, the question states what should he do FIRST....you have to shut down the server so nothing else is affected. One thing that I have learned about CompTia is the way word questions.
upvoted 1 times
...
gomet2000
8 months, 1 week ago
Selected Answer: A
D. Shut down the affected server immediately: Shutting down the server could be necessary in certain situations to prevent further damage, but it could also result in the loss of volatile data (e.g., data stored in memory). It is generally better to clone the server first, preserving all possible evidence. Given the situation, Option A is the correct first step. It allows the security team to perform a thorough forensic analysis while preserving the integrity of the evidence.
upvoted 1 times
...
kylestobaugh
8 months, 3 weeks ago
Selected Answer: A
Answer is A...alot of yall don't seem to know that vServers are a thing.
upvoted 1 times
...
zeytin7563
9 months ago
The answer is option D. stop crying
upvoted 1 times
kylestobaugh
8 months, 3 weeks ago
Provide an argument
upvoted 2 times
...
...
zee_Riddle
9 months ago
Selected Answer: A
D should not be the answer
upvoted 2 times
...
hasquaati
10 months, 1 week ago
Selected Answer: B
B: Because this is the FIRST action. When you went to go deep into forensics then you log into a VM. This question is crap by the way.
upvoted 2 times
LoneStarChief
9 months ago
To add to this, at which point does the question state its a 'Virtual Server'? Also, the question DOES state: "the server was up to date and configured with appropriate auditing and logging." Hence why my choice is 'B'. Cause lets be honest 'D' is just plain WRONG.
upvoted 1 times
...
...
152deff
11 months ago
Selected Answer: A
D is ridiculous
upvoted 5 times
Christof
10 months, 4 weeks ago
Correct!
upvoted 1 times
...
...
captaintoadyo
11 months, 3 weeks ago
Selected Answer: A
answer D is 100% incorrect the answer is again in the question
upvoted 1 times
...
Chalice
1 year ago
Why would it be A and not B? The question does not say it is a virtual machine, or what type of security incident. Wouldn't you want to first look at the logs?
upvoted 1 times
emotetsu
10 months ago
Log review is not enough. There is a lot to review such as registries, configurations and files and processes in the system. Cloning the server would help you do more analysis in a non-intrusive way, meaning not in the production or operational server. Preventing any disruption.
upvoted 3 times
...
...
CyberJackal
1 year ago
Selected Answer: A
In no world is this D.
upvoted 1 times
...
BigFoot101T
1 year, 3 months ago
Selected Answer: B
Should be B right? Investigate logs first then decide whether proceed to forensic analysis.
upvoted 3 times
Mehe323
11 months, 1 week ago
Yeah, in the answer, the server is suddenly virtual, a bit weird.
upvoted 1 times
...
...
[Removed]
1 year, 5 months ago
Selected Answer: A
Answer is A. Why in the world would you shut down a server and risk losing temporary information on it? D is NOT correct.
upvoted 3 times
[Removed]
1 year, 4 months ago
C and D are the worst options since you risk losing volatile / temporary data.
upvoted 2 times
...
...
Alizade
1 year, 5 months ago
Selected Answer: C
The answer is C. Restore from the last known-good backup to confirm there was no loss of connectivity.
upvoted 1 times
daddylonglegs
1 year, 2 months ago
I don't see how restoring from back-up ensures that there was no loss of connectivity
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago