Pass CompTIA CySA+ CS0-002 exam [Nov 03, 2021] Updated 299 Questions
CompTIA CS0-002 Actual Questions and 100% Cover Real Exam Questions
You can read the CompTIA CS0-002 Exam certified salary
The Average Salary of an CompTIA Certified Professional in
- Europe - 63578 EURO
- United State - 74952 USD
- India - 5624454 INR
- England - 57463 POUND
For more information visit:
CompTIA CS0-002 Exam Reference
NEW QUESTION 19
A database administrator contacts a security administrator to request firewall changes for a connection to a new internal application.
The security administrator notices that the new application uses a port typically monopolized by a virus.
The security administrator denies the request and suggests a new port or service be used to complete the application's task.
Which of the following is the security administrator practicing in this example?
- A. Explicit deny
- B. Implicit deny
- C. Access control lists
- D. Port security
Answer: C
NEW QUESTION 20
A security analyst reviews SIEM logs and detects a well-known malicious executable running in a Windows machine The up-to-date antivirus cannot detect the malicious executable Which of the following is the MOST likely cause of this issue?
- A. The malware is being executed with administrative privileges.
- B. The malware detects and prevents its own execution in a virtual environment.
- C. The malware is fileless and exists only in physical memory.
- D. The antivirus does not have the mltware's signature.
Answer: C
NEW QUESTION 21
A cybersecurity analyst needs to rearchitect the network using a firewall and a VPN server to achieve the highest level of security To BEST complete this task, the analyst should place the:
- A. VPN on the firewall
- B. VPN server behind the firewall
- C. firewall behind the VPN server
- D. VPN server parallel to the firewall
Answer: D
NEW QUESTION 22
A security analyst is reviewing packet captures from a system that was compromised. The system was already isolated from the network, but it did have network access for a few hours after being compromised. When viewing the capture in a packet analyzer, the analyst sees the following:
Which of the following can the analyst conclude?
- A. The system is scanning ajgidwle.com for PII.
- B. Data is being exfiltrated over DNS.
- C. Malware is attempting to beacon to 128.50.100.3.
- D. The system is running a DoS attack against ajgidwle.com.
Answer: B
NEW QUESTION 23
Using a heuristic system to detect an anomaly in a computer's baseline, a system administrator was able to detect an attack even though the company signature based IDS and antivirus did not detect it. Further analysis revealed that the attacker had downloaded an executable file onto the company PC from the USB port, and executed it to trigger a privilege escalation flaw. Which of the following attacks has MOST likely occurred?
- A. XML injection
- B. Directory traversal
- C. Zero-day
- D. Cookie stealing
Answer: C
NEW QUESTION 24
A security analyst is investigating malicious traffic from an internal system that attempted to download proxy avoidance software as identified from the firewall logs but the destination IP is blocked and not captured. Which of the following should the analyst do?
- A. Shut down the computer
- B. Capture live data using Wireshark
- C. Take a snapshot
- D. Determine if DNS logging is enabled.
- E. Review the network logs.
Answer: B
NEW QUESTION 25
A company's marketing emails are either being found in a spam folder or not being delivered at all. The security analyst investigates the issue and discovers the emails in question are being sent on behalf of the company by a third party in1marketingpartners.com Below is the exiting SPP word:
Which of the following updates to the SPF record will work BEST to prevent the emails from being marked as spam or blocked?
A)
B)
C)
D)
- A. Option D
- B. Option A
- C. Option C
- D. Option B
Answer: D
NEW QUESTION 26
While analyzing logs from a WAF, a cybersecurity analyst finds the following:
Which of the following BEST describes what the analyst has found?
- A. This is an encrypted GET HTTP request
- B. This is an encrypted packet
- C. A packet is being used to bypass the WAF
- D. This is an encoded WAF bypass
Answer: D
NEW QUESTION 27
A security analyst positively identified the threat, vulnerability, and remediation. The analyst is ready to implement the corrective control. Which of the following would be the MOST inhibiting to applying the fix?
- A. Resetting all administrator passwords.
- B. Business process interruption.
- C. Full desktop backups.
- D. Requiring a firewall reboot.
Answer: C
NEW QUESTION 28
Portions of a legacy application are being refactored to discontinue the use of dynamic SQL Which of the following would be BEST to implement in the legacy application?
- A. Input validation
- B. Parameterized queries
- C. Multifactor authentication
- D. Web-application firewall
- E. SQL injection
Answer: E
NEW QUESTION 29
A security administrator determines several months after the first instance that a local privileged user has been routinely logging into a server interactively as "root" and browsing the Internet. The administrator determines this by performing an annual review of the security logs on that server.
For which of the following security architecture areas should the administrator recommend review and modification? (Select TWO).
- A. Encryption
- B. Password complexity
- C. Software assurance
- D. Network isolation and separation
- E. Log aggregation and analysis
- F. Acceptable use policies
Answer: E,F
NEW QUESTION 30
An organization has two environments: development and production. Development is where applications are developed with unit testing. The development environment has many configuration differences from the production environment. All applications are hosted on virtual machines. Vulnerability scans are performed against all systems before and after any application or configuration changes to any environment. Lately, vulnerability remediation activity has caused production applications to crash and behave unpredictably. Which of the following changes should be made to the current vulnerability management process?
- A. Refine testing in the development environment to include fuzzing and user acceptance testing so applications are more stable before they migrate to production
- B. Create a second production environment by cloning the virtual machines, and if any stability problems occur, migrate users to the alternate production environment
- C. Refine testing in the production environment to include more exhaustive application stability testing while continuing to maintain the robust vulnerability remediation activities
- D. Create a third environment between development and production that mirrors production and tests all changes before deployment to the users
Answer: D
NEW QUESTION 31
A security analyst discovered a specific series of IP addresses that are targeting an organization. None of the attacks have been successful. Which of the following should the security analyst perform NEXT?
- A. Determine the attack vector and total attack surface.
- B. Conduct threat research on the IP addresses
- C. Begin blocking all IP addresses within that subnet.
- D. Begin a kill chain analysis to determine the impact.
Answer: B
NEW QUESTION 32
A software assurance lab is performing a dynamic assessment on an application by automatically generating and inputting different, random data sets to attempt to cause an error/failure condition.
Which of the following software assessment capabilities is the lab performing AND during which phase of the SDLC should this occur? (Select two.)
- A. Prototyping phase
- B. Behavior modeling
- C. Planning phase
- D. Fuzzing
- E. Requirements phase
- F. Static code analysis
Answer: A,D
NEW QUESTION 33
A monthly job to install approved vendor software updates and hot fixes recently stopped working. The security team performed a vulnerability scan, which identified several hosts as having some critical OS vulnerabilities, as referenced in the common vulnerabilities and exposures (CVE) database.
Which of the following should the security team do NEXT to resolve the critical findings in the most effective manner? (Choose two.)
- A. Resolve the monthly job issues and test them before applying them to the production network.
- B. Manually patch the computers on the network, as recommended on the CVE website.
- C. Remove the servers reported to have high and medium vulnerabilities.
- D. Tag the computers with critical findings as a business risk acceptance.
- E. Patch the required hosts with the correct updates and hot fixes, and rescan them for vulnerabilities.
- F. Harden the hosts on the network, as recommended by the NIST framework.
Answer: D,F
NEW QUESTION 34
During an investigation, an incident responder intends to recover multiple pieces of digital media.
Before removing the media, the responder should initiate:
- A. secure communications.
- B. malware scans.
- C. decryption tools.
- D. chain of custody forms.
Answer: D
NEW QUESTION 35
A company requests a security assessment of its network. Permission is given, but no details are provided. It is discovered that the company has a web presence, and the company's IP address is 70.182.11.4. Which of the following Nmap commands would reveal common open ports and their versions?
- A. nmap - oV
- B. nmap -vO
- C. nmap -sv
Answer: C
NEW QUESTION 36
......
CompTIA CS0-002 Real 2021 Braindumps Mock Exam Dumps: https://www.suretorrent.com/CS0-002-exam-guide-torrent.html
CS0-002 Free Exam Questions & Answers PDF Updated on Nov-2021: https://drive.google.com/open?id=1dkcIvQ3Ydmx7lh9fXp2Y-Zijh48R0Zz9