A security administrator sees several hundred entries in a web server security log that are similar to the following: The network source varies, but the URL, status, and user agent are the same. Which of the following would BEST protect the web server without blocking legitimate traffic?

QuestionsCategory: CAS-004A security administrator sees several hundred entries in a web server security log that are similar to the following: The network source varies, but the URL, status, and user agent are the same. Which of the following would BEST protect the web server without blocking legitimate traffic?
Admin Staff asked 6 months ago
A security administrator sees several hundred entries in a web server security log that are similar to the following:
 Image
The network source varies, but the URL, status, and user agent are the same. Which of the following would BEST protect the web server without blocking legitimate traffic?

A. Replace the file xmlrpc.php with a honeypot form to collect further IOCs.

B. Automate the addition of bot IP addresses into a deny list for the web host.

C. Script the daily collection of the WHOIS ranges to add to the WAF as a denied ACL.

D. Block every subnet that is identified as having a bot that is a source of the traffic.








 

Suggested Answer: B

Community Answer: B



This question is in CAS-004 CompTIA Advanced Security Practitioner (CASP+) Exam
For getting CompTIA Advanced Security Practitioner (CASP+) Certificate


Disclaimers:
The website is not related to, affiliated with, endorsed or authorized by CompTIA. 
Trademarks, certification & product names are used for reference only and belong to CompTIA.
The website does not contain actual questions and answers from CompTIA's Certification Exams.

Next Post

Recommended

Welcome Back!

Login to your account below

Create New Account!

Fill the forms below to register

Retrieve your password

Please enter your username or email address to reset your password.