SK0-005 — Frequently Asked Questions
Community-vetted answers to 15 common questions about this exam.
The most critical next step is to apply the latest security patches and updates to the operating system and all applications. This addresses the vulnerability that the virus likely exploited to gain access in the first place, preventing reinfection or compromise through the same vector.
Link Aggregation Control Protocol (LACP), also known as IEEE 802.3ad, is the technology that allows for the aggregation of multiple physical network links into a single logical link. This increases the total available bandwidth and provides redundancy, as traffic can be distributed across all active adapters.
Redundancy means having a backup component (the second power supply) ready to take over if the primary one fails. Fault tolerance goes a step further, ensuring there is no interruption in service during the failure. Dual power supplies on different sources provide redundancy, as the server will continue to operate if one source fails, but there might be a brief, often imperceptible, switch-over time.
The administrator should modify the logrotate configuration file, typically located at /etc/logrotate.conf or in the /etc/logrotate.d/ directory. Within the relevant configuration block for the audit logs, they would adjust parameters like daily, weekly, monthly, or size to change the rotation frequency.
While multiple policies help, enforcing account lockout after a specified number of failed login attempts is often the highest priority. This directly stops an automated brute-force attack in its tracks by temporarily or permanently disabling the account, preventing the attacker from trying an infinite number of password combinations.
The recommended first step is to use remote management tools, such as the Integrated Lights-Out (iLO), iDRAC, or IPMI interface, to check the server's health status. These tools can report fan speeds, temperatures, and system logs, which can help diagnose if a fan is failing or if the high speed (and noise) is a normal response to high temperatures.
The most important procedure is to follow Lockout/Tagout (LOTO) protocols. This involves de-energizing the equipment and physically locking the power source with a lock and tag that only the authorized technician can remove. This ensures the equipment cannot be accidentally powered on during maintenance, protecting the technician from harm.
Web servers benefit the most from load balancers. A load balancer distributes incoming network traffic across a group of web servers, ensuring no single server becomes overwhelmed. This improves application responsiveness, increases availability through redundancy, and allows for easy scalability by adding more servers to the pool.
A minimum of five disks is required. A RAID 1 array needs a minimum of two disks. A RAID 5 array needs a minimum of three disks. Since these are separate arrays, the total minimum number of disks is the sum of their individual minimums (2 + 3 = 5).
The most secure procedure is to perform a cryptographic erase or use a secure wipe utility that overwrites all data on the drives multiple times according to a recognized standard (like DoD 5220.22-M). For the highest level of security, especially with sensitive data, physically destroying the hard drives is the only guaranteed method.
Disk quotas are a management tool used to limit the amount of storage space a user or group can consume, preventing any single user from filling up the disk. Data deduplication is an optimization technique that eliminates duplicate copies of data to reduce the total amount of storage used, thereby increasing the overall efficiency and capacity of the storage system.
A tabletop exercise or a parallel test would be the most cost-effective strategy. A tabletop exercise involves key personnel discussing the recovery steps in a conference room setting, which is very low-cost. A parallel test involves running the DR systems alongside the production systems to verify they work without cutting over, which is more involved but less disruptive and costly than a full interruption test.
The most likely cause is a misconfigured firewall on the server or a network device between the server and the remote client. The firewall is probably blocking the specific ports required for remote access protocols like RDP (3389) or SSH (22), while still allowing local network traffic.
This concept is often related to adaptive authentication or risk-based authentication. The system builds a profile of the user's typical behavior (e.g., location, device, time of access). If a future login attempt matches this profile, it may be prioritized or granted with fewer authentication challenges, whereas an anomalous attempt would trigger stricter verification.
The primary benefit of a TPM is to provide hardware-based security functions. It can securely store cryptographic keys, passwords, and certificates. It is crucial for features like full-disk encryption (e.g., BitLocker), secure boot (ensuring the system boots with trusted software), and platform integrity verification, protecting against offline attacks and boot-level malware.
Ready to practice?
Access 135 SK0-005 questions with instant feedback and detailed explanations.
View SK0-005 Practice Questions →← Back to CompTIA Server+ SK0-005 Tricky Questions & Common Mistakes