exam questions

Exam CS0-003 All Questions

View all questions & answers for the CS0-003 exam

Exam CS0-003 topic 1 question 69 discussion

Actual exam question from CompTIA's CS0-003
Question #: 69
Topic #: 1
[All CS0-003 Questions]

A cybersecurity analyst notices unusual network scanning activity coming from a country that the company does not do business with. Which of the following is the best mitigation technique?

  • A. Geoblock the offending source country.
  • B. Block the IP range of the scans at the network firewall.
  • C. Perform a historical trend analysis and look for similar scanning activity.
  • D. Block the specific IP address of the scans at the network firewall.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
[Removed]
Highly Voted 1 year, 4 months ago
Selected Answer: A
A is correct! Based on my work experience as an information security analyst. Re-read the question carefully. There's a reason it states the business does NOT conduct business with them. So the reasoning about it blocking legitimate traffic from users there or the CEO going on vacation there go out the window. Why would you allow incoming connections from a country you do no business with? Additionally, blocking just the range of IPs isn't a good option since the attacker can just use an IP outside of that range and they are in. Blocking by geolocation is a common practice. China, Russia, Moldova, etc.
upvoted 21 times
JimmyJohnSubs
11 months, 3 weeks ago
In my opinion, this is a trick question. They are leading you to believe the country is an unfriendly country like Russia or China but what if you are not doing business with Canada and you geoblock the country. This will have an impact where users won't be able to browse certain websites or use certain services like VoIP Trunking just to list as an example. Microsoft products communicate with IPs in many different countries around the world. The two possible answers are A or D. I believe the answer is D in this case. B doesn't make sense since the scan source will either be a single IP or it will come from many random IPs that are not in any particular subnet that can be blocked.
upvoted 3 times
...
bmadajczyk
1 year, 4 months ago
What if the country isn't China, Russia, Moldova? Based on my working experience it would be B. A is way to broad and blocking whole country based on 1 scanning IP is straight up stupid if it's not a high risk country.
upvoted 1 times
...
[Removed]
1 year, 4 months ago
Also, this is common practice to block countries conducting unauthorized port scanning. Lookup recyber.net on Reddit. https://www.reddit.com/r/pfBlockerNG/comments/x0gty6/anyone_else_getting_a_ton_of_recyber_pings/ They have a lot of reports on AbuseIPDB for that exact reason. Port scanning.
upvoted 4 times
...
...
LiteralGod
Highly Voted 1 year, 5 months ago
Selected Answer: A
There's a reason the question mentions them not having any business in the source IP's country.
upvoted 7 times
...
Susan4041
Most Recent 4 days, 9 hours ago
Selected Answer: A
They can always change their IP so A is right its a country they do not do business with.
upvoted 1 times
...
Susan4041
2 weeks, 3 days ago
Selected Answer: B
A is too aggressive B makes more sense.
upvoted 1 times
...
GDLY
4 months, 3 weeks ago
Selected Answer: A
A is correct. Multi-billion dollar organization that I work for blocks every country we do not do business with. We make exceptions on a per user basis when they are out of the country
upvoted 3 times
...
8f1fc75
7 months ago
Another poorly worded question here. It could be A or B.
upvoted 1 times
...
Lilik
8 months, 1 week ago
Selected Answer: A
unusual network scanning activity - red flag. country i dont do business with - red flag. geoblock!
upvoted 2 times
...
mmsbaseball3
8 months, 3 weeks ago
Selected Answer: A
There is literally ZERO reason to have any traffic coming from that source country as they do not conduct business with them. If you block a specific IP range then the attacker can just spoof or obtain new IPs from the source country and continue their attack. Blocking the country as a whole will mitigate the risk forcing the attacker to utilize other TTPs. For those who are arguing for option 'B' because maybe the CEO may travel; in the real world the CEO will typically get with the SOC to advise of their ypcoming vacation and ask for apolicy or exception to be put in place for his network access.
upvoted 2 times
...
cartman_sc
11 months ago
Selected Answer: A
A CompTIA tratou como geoblock a melhor opção no exame da Security+, então seguirei dessa forma.
upvoted 1 times
...
MMK777
11 months, 1 week ago
Selected Answer: B
when you block the IP range for a public from that country will be as good as block the whole country
upvoted 1 times
...
bettyboo
1 year, 1 month ago
Selected Answer: A
I choose A. Geoblock the offending source country, because we do it at my work and because the question specifically mentions that the company does not do business with that WHOLE country, and we know how CompTIA plays this game.
upvoted 4 times
...
sheilawu
1 year, 3 months ago
Selected Answer: A
I vote for A, cus our company is doing this so.
upvoted 5 times
...
Budin
1 year, 3 months ago
Selected Answer: A
Blocking high risk country that you did not have “business relation”
upvoted 1 times
...
bmadajczyk
1 year, 4 months ago
Selected Answer: B
I would agree with A if the country would be specify as a high risk country. In this case let's say you are german company not doing business in Belgium. Isn't geoblocking whole Belgium after 1 scan like shooting a fly with the nuke?
upvoted 1 times
voiddraco
1 year, 1 month ago
I choose A but I also understand your point but you are reading more into it. With Comptia you gotta take it as it is in the question, thats what I got from taking all their certs, never over analyze.
upvoted 2 times
...
...
[Removed]
1 year, 5 months ago
A is correct! Based on my work experience as an information security analyst. Re-read the question carefully. There's a reason it states the business does NOT conduct business with them. So the reasoning about it blocking legitimate traffic from users there or the CEO going on vacation there go out the window. Why would you allow incoming connections from a country you do no business with? Additionally, blocking just the range of IPs isn't a good option since the attacker can just use an IP outside of that range and they are in. Blocking by geolocation is a common practice. China, Russia, Moldova, etc.
upvoted 3 times
...
DanJia
1 year, 5 months ago
A. based on my working experience
upvoted 2 times
...
Saleh00
1 year, 6 months ago
I see that banning the geographical scope is better and it is true because in Sario, he explained to us important data that he does not deal with this company and that there is no dealing with this country with a company, that is, why I only ban IP may be an intruder or a hacker who wants to collect information or hack my company's system, and if I block ABB, I will not benefit, I may have a thousand IP deceive or in other ways as long as I do not work with us, take a geographical domain and there is no work in my company with them, I see that the best solution is the best closure or a geographical ban, so the answer to a geographical ban
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago