Get ready to pass the CS0-002 Exam right now using our CompTIA CySA+ Exam Package [Q175-Q193]

Share

 Get ready to pass the CS0-002 Exam right now using our CompTIA CySA+  Exam Package

A fully updated 2022 CS0-002 Exam Dumps exam guide from training expert ActualCollection

NEW QUESTION 175
A threat intelligence analyst who works for a technology firm received this report from a vendor.
"There has been an intellectual property theft campaign executed
against organizations in the technology industry. Indicators for this
activity are unique to each intrusion. The information that appears to
be targeted is R&D data. The data exfiltration appears to occur over
months via uniform TTPs. Please execute a defensive operation regarding this attack vector." Which of the following combinations suggests how the threat should MOST likely be classified and the type of analysis that would be MOST helpful in protecting against this activity?

  • A. Polymorphic malware and secure code analysis
  • B. APT and behavioral analysis
  • C. Ransomware and encryption
  • D. Insider threat and indicator analysis

Answer: B

 

NEW QUESTION 176
During a routine log review, a security analyst has found the following commands that cannot be identified from the Bash history log on the root user.

Which of the following commands should the analyst investigate FIRST?

  • A. Line 5
  • B. Line 6
  • C. Line 1
  • D. Line 2
  • E. Line 3
  • F. Line 4

Answer: D

 

NEW QUESTION 177
During routine monitoring, a security analyst discovers several suspicious websites that are communicating with a local host. The analyst queries for IP 192.168.50.2 for a 24-hour period:

To further investigate, the analyst should request PCAP for SRC 192.168.50.2 and.

  • A. DST 175.35.20.5.
  • B. DST 172.10.3.5.
  • C. DST 172.10.45.5.
  • D. DST 138.10.25.5.
  • E. DST 138.10.2.5.

Answer: E

 

NEW QUESTION 178
A threat intelligence analyst who works for an oil and gas company has received the following email from a superior:
"We will be connecting our IT network with our ICS. Our IT security has historically been top of the line, and this convergence will make the ICS easier to manage and troubleshoot. Can you please perform a risk/vulnerability assessment on this decision?" Which of the following is MOST accurate regarding ICS in this scenario?

  • A. Integrating increases the attack surface
  • B. Convergence decreases attack vectors
  • C. IT networks cannot be connected to ICS infrastructure
  • D. Combined networks decrease efficiency

Answer: A

 

NEW QUESTION 179
A company has been a victim of multiple volumetric DoS attacks. Packet analysis of the offending traffic shows the following:

Which of the following mitigation techniques is MOST effective against the above attack?

  • A. The company should implement the following ACL at their gateway firewall:DENY IP HOST
    192.168.1.1 170.43.30.0/24.
  • B. The company should implement a network-based sinkhole to drop all traffic coming from
    192.168.1.1 at their gateway router.
  • C. The company should contact the upstream ISP and ask that RFC1918 traffic be dropped.
  • D. The company should enable the DoS resource starvation protection feature of the gateway NIPS.

Answer: C

 

NEW QUESTION 180
An analyst is reviewing a list of vulnerabilities, which were reported from a recent vulnerability scan of a Linux server.
Which of the following is MOST likely to be a false positive?

  • A. Apache HTTP Server Byte Range DoS
  • B. OpenSSH/OpenSSL Package Random Number Generator Weakness
  • C. HTTP TRACE / TRACK Methods Allowed (002-1208)
  • D. GDI+ Remote Code Execution Vulnerability (MS08-052)
  • E. SSL Certificate Expiry

Answer: E

 

NEW QUESTION 181
A security analyst received a SIEM alert regarding high levels of memory consumption for a critical system.
After several attempts to remediate the issue, the system went down. A root cause analysis revealed a bad actor forced the application to not reclaim memory. This caused the system to be depleted of resources.
Which of the following BEST describes this attack?

  • A. Denial of service
  • B. Injection attack
  • C. Memory corruption
  • D. Array attack

Answer: C

 

NEW QUESTION 182
Which of the following technologies can be used to house the entropy keys for disk encryption on desktops and laptops?

  • A. HSM
  • B. Bus encryption
  • C. TPM
  • D. Self-encrypting drive

Answer: D

 

NEW QUESTION 183
A security analyst at a technology solutions firm has uncovered the same vulnerabilities on a vulnerability scan for a long period of time. The vulnerabilities are on systems that are dedicated to the firm's largest client.
Which of the following is MOST likely inhibiting the remediation efforts?

  • A. Patches for the vulnerabilities have not been fully tested by the software vendor
  • B. The parties have an MOU between them that could prevent shutting down the systems
  • C. There is a potential disruption of the vendor-client relationship
  • D. There is an SLA with the client that allows very little downtime

Answer: D

 

NEW QUESTION 184
A security analyst is investigating a compromised Linux server.
The analyst issues the ps command and receives the following output.

Which of the following commands should the administrator run NEXT to further analyze the compromised system?

  • A. /bin/la -1 /proc/1301/exe
  • B. rpm -V openash-server
  • C. strace /proc/1301
  • D. kill -9 1301

Answer: C

 

NEW QUESTION 185
A security analyst for a large financial institution is creating a threat model for a specific threat actor that is likely targeting an organization's financial assets.
Which of the following is the BEST example of the level of sophistication this threat actor is using?

  • A. Custom malware attributed to the threat actor from prior attacks
  • B. Social media accounts attributed to the threat actor
  • C. Network assets used in previous attacks attributed to the threat actor
  • D. Email addresses and phone numbers tied to the threat actor
  • E. IP addresses used by the threat actor for command and control

Answer: A

 

NEW QUESTION 186
An organization recently had its strategy posted to a social media website. The document posted to the website is an exact copy of a document stored on only one server in the organization. A security analyst sees the following output from a command-line entry on the server suspected of the problem:

Which of the following would be the BEST course of action?

  • A. Monitor all the established TCP connections for data exfiltration
  • B. Figure out which of the Firefox processes is the malware
  • C. Remove the malware associated with PID 773
  • D. Investigate the malware associated with PID 123
  • E. Block all TCP connections at the firewall

Answer: C

 

NEW QUESTION 187
The help desk informed a security analyst of a trend that is beginning to develop regarding a suspicious email that has been reported by multiple users. The analyst has determined the email includes an attachment named invoice.zip that contains the following files:
Locky.js
xerty.ini
xerty.lib
Further analysis indicates that when the .zip file is opened, it is installing a new version of ransomware on the devices. Which of the following should be done FIRST to prevent data on the company NAS from being encrypted by infected devices?

  • A. Set permissions on file shares to read-only.
  • B. Email employees instructing them not to open the invoice attachment.
  • C. Add the URL included in the .js file to the company's web proxy filter.
  • D. Disable access to the company VPN.

Answer: B

 

NEW QUESTION 188
Hotspot Question
A security analyst performs various types of vulnerability scans. You must review the vulnerability scan results to determine the type of scan that was executed and determine if a false positive occurred for each device.
Instructions:
Select the drop option for whether the results were generated from a credentialed scan, non- credentialed scan, or a compliance scan.
For ONLY the credentialed and non-credentialed scans, evaluate the results for false positives and check the findings that display false positives.
NOTE: If you would like to uncheck an option that is currently selected, click on the option a second time. Lastly, based on the vulnerability scan results, identify the type of Server by dragging the Server to the results.
The Linux Web Server, File-Print Server and Directory Server are draggable. If at any time you would like to bring back the initial state of the simulation, please select the Reset button. When you have completed the simulation, please select the Done button to submit. Once the simulation is submitted, please select the Next button to continue.

Answer:

Explanation:

 

NEW QUESTION 189
A security audit revealed that port 389 has been used instead of 636 when connecting to LDAP for the authentication of users.
The remediation recommended by the audit was to switch the port to 636 wherever technically possible.
Which of the following is the BEST response?

  • A. Change all devices and servers that support it to 636, as encrypted services run by default on
    636.
  • B. Correct the audit. This finding is accurate, but the correct remediation is to update encryption keys on each of the servers to match port 636.
  • C. Correct the audit. This finding is a well-known false positive; the services that typically run on 389 and 636 are identical.
  • D. Change all devices and servers that support it to 636, as 389 is a reserved port that requires root access and can expose the server to privilege escalation attacks.

Answer: A

 

NEW QUESTION 190
To prioritize the morning's work, an analyst is reviewing security alerts that have not yet been investigated. Which of the following assets should be investigated FIRST?

  • A. The workstation of a developer who is installing software on a web server
  • B. The laptop of the vice president that is on the corporate LAN
  • C. An accounting supervisor's laptop that is connected to the VPN
  • D. A new test web server that is in the process of initial installation

Answer: B

 

NEW QUESTION 191
An analyst is examining a system that is suspected of being involved in an intrusion.
The analyst uses the command `cat/etc/passwd' and receives the following partial output:

Based on the above output, which of the following should the analyst investigate further?

  • A. User `daemon' should not have a home directory of /usr/sbin
  • B. User `news' should not have a default shell of /bin/bash
  • C. User `root' should not have a home directory of /root
  • D. User `mail' should not have a default shell of /usr/sbin/nologin

Answer: B

 

NEW QUESTION 192
For machine learning to be applied effectively toward security analysis automation, it requires .

  • A. relevant training data.
  • B. a threat feed API.
  • C. a multicore, multiprocessor system.
  • D. anomalous traffic signatures.

Answer: A

 

NEW QUESTION 193
......

Master 2022 Latest The Questions CompTIA CySA+ and Pass CS0-002  Real Exam!: https://www.actualcollection.com/CS0-002-exam-questions.html

Practice To CS0-002 - ActualCollection Remarkable Practice On your CompTIA Cybersecurity Analyst (CySA+) Certification Exam Exam: https://drive.google.com/open?id=1xlmbR9cntf62fr69wRP8AlDTT2zNw7zv