Mitigating Server Virus Infection and Vulnerability
IDS alerts indicate abnormal traffic patterns are coming from a specific server in a data center that hosts sensitive data. Upon further investigation, the server administrator notices this server has been infected with a virus due to an exploit of a known vulnerability from its database software. Which of the following should the administrator perform after removing the virus to mitigate this issue from reoccurring and to maintain high availability? (Choose three.)
Community Votes
100% of anonymous learners picked answer ACD. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the ability to select multiple remediation steps that address root cause (patching), future detection (scanning), and access control (firewall) while maintaining availability.
This question addresses incident response and vulnerability management following a server compromise. The community consensus strongly favors patching the specific exploit, scanning for other weaknesses, and implementing host-based network controls.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The correct combination of actions involves addressing the immediate root cause, ensuring system integrity, and preventing lateral movement or reinfection. Patching the specific vulnerability (C) is the most critical step to stop the initial attack vector. Running a vulnerability scanner (A) ensures no other similar flaws exist on the server. Enabling a host firewall (D) provides an additional layer of defense by restricting unnecessary traffic, which is crucial for high availability in a data center environment.Why the Other Options Are Wrong
Repartitioning the hard drive (B) does not mitigate security vulnerabilities and is unrelated to virus removal. Reformatting the OS (E) is a drastic measure that destroys all data and applications, requiring extensive restoration from backups, which negatively impacts high availability and is unnecessary if the virus is removed and patches are applied.Community Comment Notes
Several users argue for ACF, suggesting antivirus updates are needed. However, option A (Vulnerability Scanner) covers identifying the flaw, and C (Patch) fixes it. While AV is important, the question asks for mitigation of the issue (the exploited vulnerability). D (Host Firewall) is often preferred over just AV in exam contexts for network-level mitigation. Note that the suggested answer 'AC' might be incomplete in some keys, but ACD is the most robust technical solution for 'high availability' and 'mitigation'.Exam Strategy
When asked for 'three' actions involving mitigation and availability, prioritize fixing the root cause (Patch), verifying system health (Scan/AV), and adding defensive layers (Firewall/WAF). Avoid destructive options like reformatting unless total compromise is stated.
Related Analysis
Practice All SK0-005 Questions
Access 135 questions with complete answers and detailed explanations.
View Full SK0-005 Practice Test →