Mitigating Server Virus Infection and Vulnerability

Security Operations

IDS alerts indicate abnormal traffic patterns are coming from a specific server in a data center that hosts sensitive data. Upon further investigation, the server administrator notices this server has been infected with a virus due to an exploit of a known vulnerability from its database software. Which of the following should the administrator perform after removing the virus to mitigate this issue from reoccurring and to maintain high availability? (Choose three.)

  1. Run a vulnerability scanner on the server. Source Reference Answer
  2. Repartition the hard drive that houses the database.
  3. Patch the vulnerability. Source Reference Answer
  4. Enable a host firewall.
  5. Reformat the OS on the server.

Community Votes

ACD
100%

100% of anonymous learners picked answer ACD. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the ability to select multiple remediation steps that address root cause (patching), future detection (scanning), and access control (firewall) while maintaining availability.

This question addresses incident response and vulnerability management following a server compromise. The community consensus strongly favors patching the specific exploit, scanning for other weaknesses, and implementing host-based network controls.

Community Discussion (3 comments)

cj207800 👍 1 Selected: AC
the given answer is correct
[Removed] 👍 3 Selected: AC
The server was infected, so you definitively need to update the AV. Answer is ACF
surfuganda 👍 1 Selected: ACD
A. Run a vulnerability scanner on the server. This action will help identify any existing vulnerabilities, including but not limited to the one that was exploited. It's an essential step for ensuring that all potential security weaknesses are identified and can be addressed. C. Patch the vulnerability. Once the specific vulnerability that was exploited is identified, patching it is critical to prevent future exploits of the same weakness. Regularly updating and patching the system and its software components is a fundamental security practice. D. Enable a host firewall. A host-based firewall can provide an additional layer of security by controlling incoming and outgoing network traffic based on an applied rule set. It can help mitigate the risk of future infections by blocking unauthorized access attempts and limiting the spread of any potential intrusion.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The correct combination of actions involves addressing the immediate root cause, ensuring system integrity, and preventing lateral movement or reinfection. Patching the specific vulnerability (C) is the most critical step to stop the initial attack vector. Running a vulnerability scanner (A) ensures no other similar flaws exist on the server. Enabling a host firewall (D) provides an additional layer of defense by restricting unnecessary traffic, which is crucial for high availability in a data center environment.

Why the Other Options Are Wrong

Repartitioning the hard drive (B) does not mitigate security vulnerabilities and is unrelated to virus removal. Reformatting the OS (E) is a drastic measure that destroys all data and applications, requiring extensive restoration from backups, which negatively impacts high availability and is unnecessary if the virus is removed and patches are applied.

Community Comment Notes

Several users argue for ACF, suggesting antivirus updates are needed. However, option A (Vulnerability Scanner) covers identifying the flaw, and C (Patch) fixes it. While AV is important, the question asks for mitigation of the issue (the exploited vulnerability). D (Host Firewall) is often preferred over just AV in exam contexts for network-level mitigation. Note that the suggested answer 'AC' might be incomplete in some keys, but ACD is the most robust technical solution for 'high availability' and 'mitigation'.

Exam Strategy

When asked for 'three' actions involving mitigation and availability, prioritize fixing the root cause (Patch), verifying system health (Scan/AV), and adding defensive layers (Firewall/WAF). Avoid destructive options like reformatting unless total compromise is stated.

Related Analysis

Practice All SK0-005 Questions

Access 135 questions with complete answers and detailed explanations.

View Full SK0-005 Practice Test →

← Back to SK0-005 Study Guide