exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 176 discussion

Actual exam question from CompTIA's CAS-004
Question #: 176
Topic #: 1
[All CAS-004 Questions]

A security analyst is reviewing the following vulnerability assessment report:

Which of the following should be patched FIRST to minimize attacks against Internet-facing hosts?

  • A. Server1
  • B. Server2
  • C. Server3
  • D. Server4
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
BiteSize
Highly Voted 1 year, 9 months ago
Selected Answer: B
Proof of Concept - Bloodhound anyone? Source: Verifying each answer against Chat GPT, my experience, other test banks, a written book, and weighing in the discussion from all users to create a 100% accurate guide for myself before I take the exam. (It isn't easy because of the time needed, but it is doing my diligence)
upvoted 6 times
...
DaleC78
Highly Voted 2 years, 4 months ago
Selected Answer: B
Agree with Andre876, not all web servers are external-facing; in this example, a private IP is shown instead of a public one. Going also with B here.
upvoted 5 times
...
Chiaretta
Most Recent 2 months, 4 weeks ago
Selected Answer: C
Which of the following should be patched FIRST to minimize attacks against Internet-facing hosts? Server1 NOT an Internet facing IP address Server2 CVSS score 6.5 [x] Internet facing IP address No known exploit (the exploit is only a proof-of-concept (POC) meaning that there is not yet a confirmed and publicly available method to exploit the vulnerability reliably) Server3 [CORRECT ANSWER] CVSS score 5.5 [x] Internet facing IP address [x] known exploit (indicating that there is a confirmed method available to exploit the vulnerability) Server4 NOT an Internet facing IP address
upvoted 2 times
...
deeden
4 months, 3 weeks ago
Selected Answer: A
Priority Order: Server1 (high, internet-facing web server with a confirmed exploit) Server2 (high, DNS potentially Internet-facing, proof-of-concept exploit) Server3 (moderate, confirmed exploit but lower exposure and CVS score) Server4 (critical, no exploit available, internal system) info: https://www.techtarget.com/searchsecurity/definition/proof-of-concept-PoC-exploit
upvoted 2 times
...
isaphiltrick
9 months, 3 weeks ago
Server3 has a CVSS score of 5.5, is remotely executable, and has an available exploit. While Server3 is indeed an Internet-facing host (207.1.5.7), its CVSS score and the lack of a proof-of-concept exploit make it a lower priority compared to Server2. The higher score and available exploit for Server2 outweigh the concerns for Server3 in this scenario.
upvoted 1 times
...
surfuganda
1 year ago
Selected Answer: C
Which of the following should be patched FIRST to minimize attacks against Internet-facing hosts? Server1 NOT an Internet facing IP address Server2 CVSS score 6.5 [x] Internet facing IP address No known exploit (the exploit is only a proof-of-concept (POC) meaning that there is not yet a confirmed and publicly available method to exploit the vulnerability reliably) Server3 [CORRECT ANSWER] CVSS score 5.5 [x] Internet facing IP address [x] known exploit (indicating that there is a confirmed method available to exploit the vulnerability) Server4 NOT an Internet facing IP address
upvoted 4 times
...
khengoolman
1 year, 3 months ago
Selected Answer: C
Choice is between B and C only, due to the IP being external. Then, you need to assess if the exploit is known and active in the wild, which means it's Server 3, as Server 2 only has a Proof of Concept exploit. If both were Yes or POC, you would go with the higher CVS score, but not when one is a zero day (essentially) and the other is not.
upvoted 4 times
...
abrub
1 year, 3 months ago
Selected Answer: C
Server 3 - email server is external facing and exploit is available, rather than just proof of concept (referencing server 2)
upvoted 1 times
...
ThatGuyOverThere
1 year, 6 months ago
Selected Answer: C
B is currently only listed as a proof of concept which indicates it isn't being actively exploited in the wild. Analysts have just shown that exploitation may be technically possible but no useful exploit has been developed or is being used for it. Patch C first as it is internet facing and active exploits are in the wild.
upvoted 3 times
...
32d799a
1 year, 6 months ago
Selected Answer: C
Though the severity score for Server2 is higher, it only has a Proof of Concept exploit, whereas Server3 has an actual known exploit available. It's a close call between Server2 and Server3 due to the available exploits and severity scores. However, since actual exploits (not just POCs) have a higher likelihood of being used in the wild, the most prudent choice would be: Answer: C. Server3.
upvoted 4 times
...
linuxG
1 year, 8 months ago
Selected Answer: C
I'm going C. Server 1 and Server 4 are not "Internet-Facing Hosts" and the second part of the question "patched first"....well Server 2 only has a PoC, it wouldn't have a patch available until the PoC has been verified.
upvoted 3 times
...
imather
1 year, 9 months ago
Selected Answer: C
I'm going with C. Server 1 and 2, while having higher CVSS have private IPs. Server 2 has a higher CVSS than 3, but the exploit is only POC, proof of concept. A POC is a demonstration of the feasibility of an exploit. Exploit = yes means there is a known exploit. So that means Server 3 is the highest priority internet facing server.
upvoted 4 times
...
nycrack
1 year, 10 months ago
Selected Answer: B
Yes B is the answer
upvoted 4 times
...
Geofab
2 years, 1 month ago
Selected Answer: B
B has external IP and higher vulnerability score compared to email server
upvoted 4 times
...
FOURDUE
2 years, 2 months ago
Selected Answer: B
due to the IP
upvoted 4 times
...
Mr_BuCk3th34D
2 years, 4 months ago
Selected Answer: C
I will go against everyone else and choose C, here's why: In a vulnerability assessment report, the "exploit" field is used to indicate whether or not a particular vulnerability can be exploited, or used to attack the system. The "Yes" value in this field indicates that the vulnerability can be exploited, while the "POC" (Proof of Concept) value indicates that a proof of concept for exploiting the vulnerability has been developed, but it is not known if the vulnerability can actually be exploited in a real-world attack. So the correct remediation priorities should be: 1) Server2 2) Server3 3) Server1 4) Server4
upvoted 2 times
Mr_BuCk3th34D
2 years, 4 months ago
My bad, that should be B. My explanation remains the same.
upvoted 4 times
...
...
kycugu
2 years, 4 months ago
its B, because it has POC ready and has route-able IP
upvoted 2 times
GoldyTwatus
1 year, 6 months ago
An exploit is more critical than a possible exploit
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago