CompTIA Server+ SK0-005 Practice Question

Your organization's SIEM generates a high-priority alert: a Windows Server 2022 file server that stores customer PII suddenly begins transferring several gigabytes of data to an unknown external IP address over TCP port 22. When you remotely log in, you discover an unauthorized OpenSSH service running under a domain service account and notice that the server's sshd_config file was modified within the last hour. According to widely accepted breach-response procedures for production servers, which immediate action should the administrator take to contain the incident while still preserving evidence for later forensic analysis?

  • Delete the compromised service account from Active Directory and force a domain-wide password reset.

  • Power the server down and restore the most recent full-system backup image.

  • Isolate the host by disconnecting its network interfaces (physically unplug the cable or detach the NIC from the virtual switch).

  • Install the latest OpenSSH security patches and restart the service to close the vulnerability.

CompTIA Server+ SK0-005
Security and Disaster Recovery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

SAVE $47
$390.00 $343.00
SAVE $53
CompTIA Server+ Voucher with Retake
v5 / SK0-005
Includes Retake
$439.00 $386.00
Bash, the Crucial Exams Chat Bot
AI Bot