Back to overview

CompTIA CySA+ CS03

All questions without description (e.g. Question #1) are from the premium version of Exam Topics. I always choosed the community answer if possible for them. The rest is from the specific documents, written in the header of each question.

Subject
No category / Others
Language of creation
English
342 flashcards No ratings yet 0 views
Add to my sets

Sign in to add this set to your collection. You will return here afterwards.

Cards in this set

Card 181

Question

 

Question #180

A SOC manager is establishing a reporting process to manage vulnerabilities. Which of the following would be the best solution to identify potential loss incurred by an issue?

Answer

  • C. Mitigation
  • A. Trends
  • B. Risk score
  • D. Prioritization

Card 182

Question

Question #181

While configuring a SIEM for an organization, a security analyst is having difficulty correlating incidents across different systems. Which of the following should be checked first?

Answer

  • C. Behavioral correlation settings
  • B. NTP configuration on each system
  • A. If appropriate logging levels are set
  • D. Data normalization rules

Card 183

Question

 

Question #182

During a scan of a web server in the perimeter network, a vulnerability was identified that could be exploited over port 3389. The web server is protected by a WAF. Which of the following best represents the change to overall risk associated with this vulnerability?

Answer

  • C. The risk would decrease because a web application firewall is in place
  • D. The risk would increase because the host is external facing
  • B. The risk would decrease because RDP is blocked by the firewall
  • A. The risk would not change because network firewalls are in use

Card 184

Question

 

Question #183

Several vulnerability scan reports have indicated runtime errors as the code is executing. The dashboard that lists the errors has a command-line interface for developers to check for vulnerabilities. Which of the following will enable a developer to correct this issue? (Choose two.)

Answer

  • A. Performing dynamic application security testing
  • C. Fuzzing the application
  • E. Implementing a coding standard
  • F. Implementing IDS
  • D. Debugging the code
  • B. Reviewing the code

Card 185

Question

 

Question #184

A security analyst is trying to validate the results of a web application scan with Burp Suite. The security analyst performs the following:



Which of the following vulnerabilities is the security analyst trying to validate?

Answer

  • A. SQL injection
  • B. LFI
  • C. XSS
  • D. CSRF

Card 186

Question

 

Question #185

A cybersecurity team has witnessed numerous vulnerability events recently that have affected operating systems. The team decides to implement host-based IPS, firewalls and two-factor authentication. Which of the following does this most likely describe?

Answer

  • D. Secure access service edge
  • B. Hybrid network architecture
  • A. System hardening
  • C. Continuous authorization

Card 187

Question

 

Question #186

A security analyst needs to secure digital evidence related to an incident. The security analyst must ensure that the accuracy of the data cannot be repudiated. Which of the following should be implemented?

Answer

  • C. Integrity validation
  • D. Legal hold
  • B. Evidence collection
  • A. Offline storage

Card 188

Question

 

Question #187

An analyst investigated a website and produced the following:



Which of the following syntaxes did the analyst use to discover the application versions on this vulnerable website?

Answer

  • A. nmap -sS -T4 -F insecure.org
  • B. nmap -C insecure.org
  • D. nmap -A insecure.org
  • C. nmap -sV -T4 -F insecure.org

Card 189

Question

 

Question #188

A cybersecurity analyst is doing triage in a SIEM and notices that the time stamps between the firewall and the host under investigation are off by 43 minutes. Which of the following is the most likely scenario occurring with the time stamps?

Answer

  • C. The firewall is using UTC time
  • A. The NTP server is not configured on the host
  • B. The cybersecurity analyst is looking at the wrong information
  • D. The host with the logs is offline

Card 190

Question

Question #189

A payroll department employee was the target of a phishing attack in which an attacker impersonated a department director and requested that direct deposit information be updated to a new account. Afterward, a deposit was made into the unauthorized account. Which of the following is one of the first actions the incident response team should take when they receive notification of the attack?

Answer

  • C. Contact human resources and recommend the termination of the employee
  • A. Scan the employee's computer with virus and malware tools
  • B. Review the actions taken by the employee and the email related to the event
  • D. Assign security awareness training to the employee involved in the incident

Card 191

Question

 

Question #190

A security analyst has found the following suspicious DNS traffic while analyzing a packet capture:

• DNS traffic while a tunneling session is active.
• The mean time between queries is less than one second.
• The average query length exceeds 100 characters.

Which of the following attacks most likely occurred?

Answer

  • A. DNS exfiltration
  • C. DNS zone transfer
  • D. DNS poisoning
  • B. DNS spoofing

Card 192

Question

 

Question #191

A small company does not have enough staff to effectively segregate duties to prevent error and fraud in payroll management. The Chief Information Security Officer (CISO) decides to maintain and review logs and audit trails to mitigate risk. Which of the following did the CISO implement?

Answer

  • C. Operational controls
  • B. Compensating controls
  • A. Corrective controls
  • D. Administrative controls

Card 193

Question

 

Question #192

During the log analysis phase, the following suspicious command is detected:


Which of the following is being attempted?

 

Answer

  • A. Buffer overflow
  • C. ICMP tunneling
  • B. RCE
  • D. Smurf attack

Card 194

Question

 

Question #193

An email hosting provider added a new data center with new public IP addresses. Which of the following most likely needs to be updated to ensure emails from the new data center do not get blocked by spam filters?

Answer

  • C. SMTP
  • B. SPF
  • D. DMARC
  • A. DKIM

Card 195

Question

 

Question #194

A laptop that is company owned and managed is suspected to have malware. The company implemented centralized security logging. Which of the following log sources will confirm the malware infection?

Answer

  • D. MFA logs
  • A. XDR logs
  • B. Firewall legs
  • C. IDS logs

Card 196

Question

 

Question #195

Which of the following best describes the goal of a disaster recovery exercise as preparation for possible incidents?

Answer

  • D. To perform tests against implemented security controls
  • A. To provide metrics and test continuity controls
  • C. To provide recommendations for handling vulnerabilities
  • B. To verify the roles of the incident response team

Card 197

Question

 

Question #196

A security analyst has prepared a vulnerability scan that contains all of the company’s functional subnets. During the initial scan users reported that network printers began to print pages that contained unreadable text and icons. Which of the following should the analyst do to ensure this behavior does not occur during subsequent vulnerability scans?

Answer

  • C. Create a tailored scan for the printer subnet
  • A. Perform non-credentialed scans
  • B. Ignore embedded web server ports
  • D. Increase the threshold length of the scan timeout

Card 198

Question

 

Question #197

A Chief Information Security Officer has outlined several requirements for a new vulnerability scanning project:

• Must use minimal network bandwidth
• Must use minimal host resources
• Must provide accurate, near real-time updates
• Must not have any stored credentials in configuration on the scanner

Which of the following vulnerability scanning methods should be used to best meet these requirements?

Answer

  • C. Active
  • B. Agent
  • A. Internal
  • D. Uncredentialed

Card 199

Question

 

Question #198

An employee is no longer able to log in to an account after updating a browser. The employee usually has several tabs open in the browser. Which of the following attacks was most likely performed?

Answer

  • D. XSS
  • C. CSRF
  • A. RFI
  • B. LFI

Card 200

Question

 

Question #199

Which of the following does "federation" most likely refer to within the context of identity and access management?

Answer

  • B. An authentication mechanism that allows a user to utilize one set of credentials to access multiple domains
  • C. Utilizing a combination of what you know who you are, and what you have to grant authentication to a user
  • A. Facilitating groups of users in a similar function or profile to system access that requires elevated or conditional access
  • D. Correlating one's identity with the attributes and associated applications the user has access to

How to use this set

Read the preview and check whether the content and answers suit your learning goal. You can add the public set to your sets to study it. Your account shows the available actions.

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please reload the page.