Question 316

A security analyst, who is working for a company that utilizes Linux servers, receives the following results from a vulnerability scan:

Which of the following is MOST likely a false positive?
  • Question 317

    An organization prohibits users from logging in to the administrator account. If a user requires elevated permissions. the user's account should be part of an administrator group, and the user should escalate permission only as needed and on a temporary basis. The organization has the following reporting priorities when reviewing system activity:
    * Successful administrator login reporting priority - high
    * Failed administrator login reporting priority - medium
    * Failed temporary elevated permissions - low
    * Successful temporary elevated permissions - non-reportable
    A security analyst is reviewing server syslogs and sees the following:
    Which of the following events is the HIGHEST reporting priority?
  • Question 318

    A vulnerability scanner has identified an out-of-support database software version running on a server. The software update will take six to nine months to complete. The management team has agreed to a one-year extended support contract with the software vendor. Which of the following BEST describes the risk treatment in this scenario?
  • Question 319

    A company discovers an unauthorized device accessing network resources through one of many network drops in a common area used by visitors.
    The company decides that is wants to quickly prevent unauthorized devices from accessing the network but policy prevents the company from making changes on every connecting client.
    Which of the following should the company implement?
  • Question 320

    A security administrator has uncovered a covert channel used to exfiltrate confidential data from an internal database server through a compromised corporate web server. Ongoing exfiltration is accomplished by embedding a small amount of data extracted from the database into the metadata of images served by the web server. File timestamps suggest that the server was initially compromised six months ago using a common server misconfiguration. Which of the following BEST describes the type of threat being used?