CompTIA CySA+ (CS0-002) — Question 291
While conducting a network infrastructure review, a security analyst discovers a laptop that is plugged into a core switch and hidden behind a desk. The analyst sees the following on the laptop's screen:
[*] [NBT-NS] Poisoned answer sent to 192.169.23.115 for name FILE-SHARE-A (service: File Server)
[*] [LLMNR] Poisoned answer sent to 192.168.23.115 for name FILE-SHARE-A
[*] [LLMNR] Poisoned answer sent to 192.168.23.115 for name FILE-SHARE-A
[SMBv2] NTLMv2-SSP Client : 192.168.23.115
[SMBv2] NTLMv2-SSP Username : CORP\jsmith
[SMBv2] NTLMv2-SSP Hash : F5DBF769CFEA7...
[*] [NBT-NS] Poisoned answer sent to 192.169.23.24 for name FILE-SHARE-A (service: File Server)
[*] [LLMNR] Poisoned answer sent to 192.168.23.24 for name FILE-SHARE-A
[*] [LLMNR] Poisoned answer sent to 192.168.23.24 for name FILE-SHARE-A
[SMBv2] NTLMv2-SSP Client : 192.168.23.24
[SMBv2] NTLMv2-SSP Username : CORP\progers
[SMBv2] NTLMv2-SSP Hash : 6D093BE2FDD70A...
Which of the following is the BEST action for the security analyst to take?
Answer options
- A. Force all users in the domain to change their passwords at the next login.
- B. Disconnect the laptop and ask the users jsmith and progers to log out.
- C. Take the FILE-SHARE-A server offline and scan it for viruses.
- D. Initiate a scan of devices on the network to find password-cracking tools.
Correct answer: B
Explanation
The best action is to disconnect the laptop and ask the users to log out because it prevents further potential compromise of credentials and mitigates immediate risk. Forcing all users to change their passwords may not address the immediate threat, while taking the server offline or scanning for tools does not directly address the security incident at hand.