Q: 3
[Attacks and Exploits]
Which of the following activities should be performed to prevent uploaded web shells from being
exploited by others?
Options
Discussion
Makes sense to pick A here. Removing any persistence mechanisms stops others from exploiting the web shell. I've seen similar on other practice tests, so pretty confident that's what they're after in this question. Disagree?
Option A is the way to actually prevent further abuse. Removing persistence mechanisms like web shells will stop attackers from getting back in. Preserving artifacts (C) is about evidence, not prevention. Pretty sure the test wants A here, but open for discussion.
Guessing C, saw this in some practice questions and preserving artifacts was suggested for evidence before you touch anything. Not fully sure since prevention is in the question, but C could be justified for forensics.
I don’t think it’s C, has to be A. C is for evidence but the question wants prevention. Anyone disagree?
Probably A. To stop more exploitation, you want to remove persistence like web shells. C just helps with evidence after, not prevention.
C/D? C is for preserving artifacts which could help in investigations, but to actually stop the exploit it's A. D feels like a trap if you think permanent removal is needed, but question just asked about prevention.
A , because removing persistence is what actually stops others from exploiting the web shell again. D might look tempting if the goal was full destruction or secure wipe, but that's not needed just to prevent further exploitation. C is more about evidence, not prevention. Seen similar wording on practice tests before-always about eradicating the threat first. Anyone see it differently?
These CompTIA questions always twist the words. The real way to stop more web shell abuse is A, yank out persistence so attackers can't hop right back in. Preservation (C) is evidence stuff, not prevention imo.
I see why some folks pick C for evidence, but since the question is about prevention, I'd go with A here.
C , saw a similar question and picked preserve artifacts since you want evidence before messing with anything. Not 100% since prevention might lean A, but C still feels valid if you wanna keep the trail for forensics. Open to counterpoints.
Be respectful. No spam.