200-201 Question 375
Select 3As a cybersecurity analyst, you are tasked with server profiling to identify potential risks in your organization's infrastructure. Which of the following elements are typically used for server profiling?
- A
Operating system and version
- B
Open ports and running services
- C
Physical location of the server
- D
Installed patches and updates
- E
User activity logs
- F
CPU performance benchmarks
Show answer and explanation
Correct answers: A, B, D
Explanation
Server profiling involves gathering information about the operating system, open ports, running services, and patch status to assess vulnerabilities and security posture. These elements provide a comprehensive understanding of the server's configuration and risk exposure, aiding in proactive defense measures.
- A. Correct.
Operating system and version are critical for server profiling as they help determine vulnerabilities and compatibility with security tools.
- B. Correct.
Open ports and running services provide insight into the potential attack surface of the server, making this a key element of server profiling.
- C. Incorrect.
While knowing the physical location of the server could be useful for asset management, it is not directly relevant to server profiling from a cybersecurity perspective.
- D. Correct.
Installed patches and updates are vital to identify whether the server is up-to-date and protected against known vulnerabilities.
- E. Incorrect.
User activity logs are more relevant for monitoring and auditing, not for server profiling itself.
- F. Incorrect.
While CPU performance benchmarks might be useful for hardware assessment, they do not contribute to the cybersecurity-focused process of server profiling.