New ActualCollection CS0-002 Exam Questions| Real CS0-002 Dumps Updated on Dec 07, 2021
CS0-002 Braindumps – CS0-002 Questions to Get Better Grades
CompTIA CS0-002 is a prerequisite exam for the CompTIA Cybersecurity Analyst (CySA+) certification. This certificate is designed to validate the skills and knowledge of the professionals looking to demonstrate their ability to apply behavioral analytics to devices and networks to detect, combat, and prevent cybersecurity threats via consistent security monitoring.
CompTIA CS0-002 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
| Topic 8 |
|
| Topic 9 |
|
NEW QUESTION 124
A network attack that is exploiting a vulnerability in the SNMP is detected.
Which of the following should the cybersecurity analyst do FIRST?
- A. Escalate the incident to senior management for guidance.
- B. Apply the required patches to remediate the vulnerability.
- C. Temporarily block the attacking IP address.
Section: (none)
Explanation - D. Disable all privileged user accounts on the network.
Answer: B
NEW QUESTION 125
A company's Chief Information Security Officer (CISO) is concerned about the integrity of some highly confidential files. Any changes to these files must be tied back to a specific authorized user's activity session.
Which of the following is the BEST technique to address the CISO's concerns?
- A. Place a legal hold on the files. Require authorized users to abide by a strict time context access policy.
Monitor the files for unauthorized changes. - B. Configure DLP to reject all changes to the files without pre-authorization. Monitor the files for unauthorized changes.
- C. Regularly use SHA-256 to hash the directory containing the sensitive information. Monitor the files for unauthorized changes.
- D. Use Wireshark to scan all traffic to and from the directory. Monitor the files for unauthorized changes.
Answer: A
NEW QUESTION 126
During routine monitoring, a security analyst discovers several suspicious websites that are communicating with a local host. The analyst queries for IP 192.168.50.2 for a 24-hour period:
To further investigate, the analyst should request PCAP for SRC 192.168.50.2 and.
- A. DST 138.10.2.5.
- B. DST 175.35.20.5.
- C. DST 172.10.45.5.
- D. DST 172.10.3.5.
- E. DST 138.10.25.5.
Answer: A
NEW QUESTION 127
A security analyst is reviewing packet captures for a specific server that is suspected of containing malware and discovers the following packets:
Which of the following traffic patterns or data would be MOST concerning to the security analyst?
- A. Ports used for HTTP traffic from 202.53.245.78
- B. Anonymous access granted by 103.34.243.12
- C. Port used for SMTP traffic from 73.252.34.101
- D. Unencrypted password sent from 103.34.243.12
Answer: B
NEW QUESTION 128
A development team signed a contract that requires access to an on-premises physical server. Access must be restricted to authorized users only and cannot be connected to the Internet.
Which of the following solutions would meet this requirement?
- A. Establish a hosted SSO.
- B. Air gap the server.
- C. Implement a CASB.
- D. Virtualize the server.
Answer: A
NEW QUESTION 129
A security analyst has been asked to remediate a server vulnerability.
Once the analyst has located a patch for the vulnerability, which of the following should happen NEXT?
- A. Implement continuous monitoring.
- B. Rescan to ensure the vulnerability still exists.
- C. Begin the incident response process.
- D. Start the change control process.
Answer: D
NEW QUESTION 130
An organization has had problems with security teams remediating vulnerabilities that are either false positives or are not applicable to the organization's servers. Management has put emphasis on security teams conducting detailed analysis and investigation before conducting any remediation.
The output from a recent Apache web server scan is shown below:
The team performs some investigation and finds this statement from Apache on 07/02/2008:
"Fixed in Apache HTTP server 2.2.6, 2.0.61, and 1.3.39"
Which of the following conditions would require the team to perform remediation on this finding?
- A. The organization is running version 2.2.6 and has ExtendedStatus enabled
- B. The organization is running version 1.3.39 and is using a public-server-status page
- C. The organization is running version 2.0.5 and has ExtendedStatus enabled
- D. The organization is running version 2.0.59 is not using a public-server-status page
Answer: C
NEW QUESTION 131
An organization has not had an incident for several month. The Chief information Security Officer (CISO) wants to move to proactive stance for security investigations. Which of the following would BEST meet that goal?
- A. Advanced antivirus
- B. Active response
- C. Information-sharing community
- D. Threat hunting
- E. Root-cause analysis
Answer: D
NEW QUESTION 132
Ransomware is identified on a company's network that affects both Windows and MAC hosts.
The command and control channel for encryption for this variant uses TCP ports from 11000 to
65000. The channel goes to good1. Iholdbadkeys.com, which resolves to IP address 72.172.16.2.
Which of the following is the MOST effective way to prevent any newly infected systems from actually encrypting the data on connected network drives while causing the least disruption to normal Internet traffic?
- A. Block all outbound TCP connections to IP host address 172.172.16.2 at the border gateway.
- B. Block all outbound traffic on TCP ports 11000 to 65000 at the border gateway.
- C. Block all outbound traffic to web host good1 iholdbadkeys.com at the border gateway.
- D. Block all outbound traffic on TCP ports 11000 to 65000 to IP host address 172.172.16.2 at the border gateway.
Answer: C
NEW QUESTION 133
While a threat intelligence analyst was researching an indicator of compromise on a search engine, the web proxy generated an alert regarding the same indicator.
The threat intelligence analyst states that related sites were not visited but were searched for in a search engine.
Which of the following MOST likely happened in this situation?
- A. The analyst accidently clicked a link related to the indicator.
- B. The alert in unrelated to the analyst's search.
- C. The analyst has prefetch enabled on the browser in use.
- D. The analyst is not using the standard approved browser.
Answer: C
NEW QUESTION 134
A cybersecurity analyst is investigating a potential incident affecting multiple systems on a company's internal network. Although there is a negligible impact to performance, the following symptom present on each of the affected systems:
* Existence of a new and unexpected svchost exe process
* Persistent, outbound TCP/IP connections to an unknown external host with routine keep-alives transferred
* DNS query logs showing successful name resolution for an Internet-resident dynamic DNS domain If this situation remains unresolved, which of the following will MOST likely occur?
- A. The affected hosts may participate in a coordinated DDoS attack upon command
- B. The adversary may attempt to perform a man-in-the-middle attack.
- C. An adversary may leverage the affected hosts to reconfigure the company's router ACLs.
- D. Key files on the affected hosts may become encrypted and require ransom payment for unlock.
Answer: D
NEW QUESTION 135
A security analyst is reviewing the following log entries to identify anomalous activity:
Which of the following attack types is occurring?
- A. Buffer overflow
- B. SQL injection
- C. Cross-site scripting
- D. Directory traversal
Answer: D
NEW QUESTION 136
A staff member reported that a laptop has degraded performance. The security analyst has investigated the issue and discovered that CPU utilization, memory utilization, and outbound network traffic are consuming the laptop resources. Which of the following is the BEST course of actions to resolve the problem?
- A. Increase laptop memory.
- B. Disable scheduled tasks.
- C. Identify and remove malicious processes.
- D. Suspend virus scan.
- E. Ensure the laptop OS is properly patched.
Answer: C
NEW QUESTION 137
Review the following results:
Which of the following has occurred?
- A. 172.29.0.109 is infected with a Trojan.
- B. 123.120.110.212 is infected with a Trojan.
- C. This is normal network traffic.
- D. 172.29.0.109 is infected with a worm.
Answer: C
NEW QUESTION 138
The software development team pushed a new web application into production for the accounting department. Shortly after the application was published, the head of the accounting department informed IT operations that the application was not performing as intended. Which of the following SDLC best practices was missed?
- A. Peer code reviews
- B. Static code analysis
- C. Fuzzing
- D. User acceptance testing
- E. Regression testing
Answer: D
NEW QUESTION 139
After reviewing the following packet, a cybersecurity analyst has discovered an unauthorized service is running on a company's computer.
Which of the following ACLs, if implemented, will prevent further access ONLY to the unauthorized service and will not impact other services?
- A. DENY IP HOST192.168.1.10 HOST 10.38.219.20 EQ 3389
- B. DENY IP HOST 10.38.219.20 ANY EQ 25
- C. DENY TCP ANY HOST 192.168.1.10 EQ 25
- D. DENY TCP ANY HOST 10.38.219.20 EQ 3389
Answer: D
NEW QUESTION 140
......
CS0-002 Exam Dumps - Try Best CS0-002 Exam Questions: https://www.actualcollection.com/CS0-002-exam-questions.html
Get New CS0-002 Certification – Valid Exam Dumps Questions: https://drive.google.com/open?id=1aRT3EcKa1F9tDZ9jGKxNKOTomZA4Itla