During an incident, a cybersecurity analyst found several entries in the web server logs that are related to an IP with a bad reputation. Which of the following would cause the analyst to further review the incident?
A) BadReputationIp - - [2019-04-12 10:43Z] "GET /etc/passwd" 403 1023
B) BadReputationIp - - [2019-04-12 10:43Z] "GET /index.html?src=../.ssh/id_rsa" 401 17044
C) BadReputationIp - - [2019-04-12 10:43Z] "GET /a.php?src=/etc/passwd" 403 11056
D) BadReputationIp - - [2019-04-12 10:43Z] "GET /a.php?src=../../.ssh/id_rsa" 200 15036
E) BadReputationIp - - [2019-04-12 10:43Z] "GET /favicon.ico?src=../usr/share/icons" 200 19064
Correct Answer:
Verified
Q57: A cybersecurity analyst is supporting an incident
Q58: A security analyst is conducting a post-incident
Q59: An analyst is investigating an anomalous event
Q60: A user receives a potentially malicious email
Q61: An analyst has been asked to provide
Q63: A developer wrote a script to make
Q64: A security analyst discovered a specific series
Q65: As part of a review of incident
Q66: A cybersecurity analyst needs to rearchitect the
Q67: A security analyst is investigating a compromised
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents