Question 16 of 160 from exam CS0-002: CompTIA CySA+

Question 16 of 160 from exam CS0-002: CompTIA CySA+

Question

A security analyst reviews the following aggregated output from an Nmap scan and the border firewall ACL:

Serverl Server2 Pcl PCc2

22/tcp open 3389/tcp open 80/tcp open 80/tcp open
80/tcp open 53/udp open 443/tcp open 443/tcp open
443/tcp open 1433/tcp open

Firewall ACL

10 permit tcp from:any to:serverl:www
15 permit udp from:lan-net to:any:dns
16 permit udp from:any to:server2:dns
20 permit tcp from:any to serverl:ssl
25 permit tcp from:lan-net to:any:www
26 permit tcp from:lan-net to:any:ssl
27 permit tcp from:any to pce2:mssql
30 permit tcp from:any to serverl:ssh
100 deny ip any any

Which of the following should the analyst reconfigure to BEST reduce organizational risk while maintaining current functionality?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D. E.

E.