Back to overview

CompTIA CySA+ CS03

All questions without description (e.g. Question #1) are from the premium version of Exam Topics. I always choosed the community answer if possible for them. The rest is from the specific documents, written in the header of each question.

Subject
No category / Others
Language of creation
English
342 flashcards No ratings yet 0 views
Add to my sets

Sign in to add this set to your collection. You will return here afterwards.

Cards in this set

Card 301

Question

CompTIA-CS0-003 ,27.01.24-unlocked.pdf

Question #115

During an internal code review, software called "ACE" was discovered to have a vulnerability that allows the execution of arbitrary code. The vulnerability is in a legacy, third-party vendor resource that is used by the ACE software. ACE is used worldwide and is essential for many businesses in this industry. Developers informed the Chief Information Security Officer that removal of the vulnerability will take time.

Which of the following is the first action to take?
 

Answer

  • A. Look for potential loCs in the company.
  • C. Remove the affected vendor resource from the ACE software.
  • D. Develop a compensating control until the issue can be fixed permanently.
  • B. Inform customers of the vulnerability.

Card 302

Question

CompTIA-CS0-003 ,27.01.24-unlocked.pdf

Question #116

During an incident, a security analyst discovers a large amount of Pll has been emailed externally from an employee to a public email address. The analyst finds that the external email is the employee's personal email.

Which of the following should the analyst recommend be done first?
 

Answer

  • A. Place a legal hold on the employee's mailbox.
  • D. Configure a deny rule on the firewall.
  • C. Disable the public email access with CASB.
  • B. Enable filtering on the web proxy.

Card 303

Question

CompTIA-CS0-003 ,27.01.24-unlocked.pdf

Question #118

A company has a primary control in place to restrict access to a sensitive database. However, the company discovered an authentication vulnerability that could bypass this control. Which of the following is the best compensating control?
 

Answer

  • A. Running regular penetration tests to identify and address new vulnerabilities
  • B. Conducting regular security awareness training of employees to prevent social engineering attacks
  • C. Deploying an additional layer of access controls to verify authorized individuals
  • D. Implementing intrusion detection software to alert security teams of unauthorized access attempts

Card 304

Question

CompTIA-CS0-003 ,27.01.24-unlocked.pdf

Question #129

An organization is conducting a pilot deployment of an e-commerce application. The application's source code is not available. Which of the following strategies should an analyst recommend to evaluate the security of the software?
 

Answer

  • C. Dynamic testing
  • A. Static testing
  • B. Vulnerability testing
  • D. Penetration testing

Card 305

Question

CompTIA-CS0-003 ,27.01.24-unlocked.pdf

Question #138

The Chief Executive Officer (CEO) has notified that a confidential trade secret has been compromised. Which of the following communication plans should the CEO initiate?
 

Answer

  • A. Alert department managers to speak privately with affected staff.
  • B. Schedule a press release to inform other service provider customers of the compromise.
  • C. Disclose to all affected parties in the Chief Operating Officer for discussion and resolution.
  • D. Verify legal notification requirements of PII and SPII in the legal and human resource departments.

Card 306

Question

CompTIA-CS0-003 ,27.01.24-unlocked.pdf

Question #141

A security analyst recently used Arachni to perform a vulnerability assessment of a newly developed web application. The analyst is concerned about the following output:
 

[+] XSS: In form input 'txtSearch' with action https://localhost/search.aspx
[-] XSS: Analyzing response #1...
[-] XSS: Analyzing response #2...
[-] XSS: Analyzing response #3...
[+] XSS: Response is tainted. Looking for proof of the vulnerability.

Which of the following is the most likely reason for this vulnerability?

 

Answer

  • D. The developer did not set proper cross-site request forgery protections.
  • A. The developer set input validation protection on the specific field of search.aspx.
  • B. The developer did not set proper cross-site scripting protections in the header.
  • C. The developer did not implement default protections in the web application build.

Card 307

Question

CompTIA-CS0-003 ,27.01.24-unlocked.pdf

Question #144

A security analyst noticed the following entry on a web server log:

Warning:

fopen (http://127.0.0.1:16) : failed to open stream:
Connection refused in /hj/var/www/showimage.php on line 7


Which of the following malicious activities was most likely attempted?

 

Answer

  • B. CSRF
  • A. XSS
  • C. SSRF
  • D. RCE

Card 308

Question

CompTIA-CS0-003 ,27.01.24-unlocked.pdf

Question #156

Which of the following statements best describes the MITRE ATT&CK framework?

 

Answer

  • A. It provides a comprehensive method to test the security of applications.
  • E. It breaks down intrusions into a clearly defined sequence of phases.
  • C. It helps identify and stop enemy activity by highlighting the areas where an attacker functions.
  • B. It provides threat intelligence sharing and development of action and mitigation strategies.
  • D. It tracks and understands threats and is an open-source project that evolves.

Card 309

Question

CompTIA-CS0-003 ,27.01.24-unlocked.pdf

Question #157

A security analyst detects an email server that had been compromised in the internal network. Users have been reporting strange messages in their email inboxes and unusual network traffic. Which of the following incident response steps should be performed next?
 

Answer

  • A. Preparation
  • D. Eradiction
  • B. Validation
  • C. Containment

Card 310

Question

CompTIA-CS0-003 ,27.01.24-unlocked.pdf

Question #164

Exploit code for a recently disclosed critical software vulnerability was publicly available (or download for several days before being removed. Which of the following CVSS v.3.1 temporal metrics was most impacted by this exposure?
 

Answer

  • C. Report confidence
  • D. Availability
  • B. Exploit code maturity
  • A. Remediation Level

Card 311

Question

CompTIA-CS0-003 ,27.01.24-unlocked.pdf

Question #165

An organization discovered a data breach that resulted in Pll being released to the public. During the lessons earned review, the panel identified discrepancies regarding who was responsible for external reporting, as well as the timing requirements. Which of the following actions would best address the reporting issue?
 

Answer

  • C. Defining which security incidents require external notifications and incident reporting in addition to internal stakeholders
  • A. Creating a playbook denoting specific SLAs and containment actions per incident type
  • B. Researching federal laws, regulatory compliance requirements, and organizational policies to document specific reporting SLAs
  • D. Designating specific roles and responsibilities within the security team and stakeholders to streamline tasks

Card 312

Question

CompTIA-CS0-003 ,27.01.24-unlocked.pdf

Question #169

An analyst reviews a recent government alert on new zero-day threats and finds the following CVE metrics for the most critical of the vulnerabilities:
 

CVSS: 3.1/AV:N/AC: L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:W/RC:R

Which of the following represents the exploit code maturity of this critical vulnerability?

Answer

  • B. S:C
  • A. E:U
  • C. RC:R
  • D. AV:N
  • E. AC:L

Card 313

Question

CompTIA-CS0-003 ,27.01.24-unlocked.pdf

Question #171

An organization has tracked several incidents that are listed in the following table:


Which of the following is the organization's MTTD?
 

Answer

  • D. 180
  • C. 160
  • B. 150
  • A. 140

Card 314

Question

CompTIA-CS0-003 ,27.01.24-unlocked.pdf

Question #172

A security analyst would like to integrate two different SaaS-based security tools so that one tool can notify the other in the event a threat is detected. Which of the following should the analyst utilize to best accomplish this goal?
 

Answer

  • B. API endpoint
  • D. SNMP trap
  • A. SMB share
  • C. SMTP notification

Card 315

Question

CompTIA-CS0-003 ,27.01.24-unlocked.pdf

Question #176

AXSS vulnerability was reported on one of the non-sensitive/non-mission-critical public websites of a company. The security department confirmed the finding and needs to provide a recommendation to the application owner.

Which of the following recommendations will best prevent this vulnerability from being exploited? (Select two).



 

Answer

  • A. Implement an IPS in front of the web server.
  • B. Enable MFA on the website.
  • E. Configure TLS v1.3 on the website.
  • F. Fix the vulnerability using a virtual patch at the WAF.
  • D. Implement a compensating control in the source code.
  • C. Take the website offline until it is patched.

Card 316

Question

CompTIA-CS0-003 ,27.01.24-unlocked.pdf

Question #177

An attacker has just gained access to the syslog server on a LAN. Reviewing the syslog entries has allowed the attacker to prioritize possible next targets. Which of the following is this an example of?
 

Answer

  • C. Service port identification
  • A. Passive network foot printing
  • D. Application versioning
  • B. OS fingerprinting

Card 317

Question

CompTIA-CS0-003 ,27.01.24-unlocked.pdf

Question #178

A security analyst is working on a server patch management policy that will allow the infrastructure team to be informed more quickly about new patches. Which of the following would most likely be required by the infrastructure team so that vulnerabilities can be remediated quickly? (Select two).
 

Answer

  • A. Hostname
  • B. Missing KPI
  • F. npm identifier
  • E. loCs
  • D. POC availability
  • C. CVE details

Card 318

Question

CompTIA-CS0-003 ,27.01.24-unlocked.pdf

Question #179

Which of the following would likely be used to update a dashboard that integrates…..

 

Answer

  • B. Extensible Markup Language
  • A. Webhooks
  • C. Threat feed combination
  • D. JavaScript Object Notation

Card 319

Question

CompTIA-CS0-003 ,27.01.24-unlocked.pdf

Question #180

A security analyst is reviewing events that occurred during a possible compromise. The analyst obtains the following log:
 

Which of the following is most likely occurring, based on the events in the log?

 

Answer

  • A. An adversary is attempting to find the shortest path of compromise.
  • B. An adversary is performing a vulnerability scan.
  • D. An adversary is performing a password stuffing attack.
  • C. An adversary is escalating privileges.

Card 320

Question

CompTIA-CS0-003 ,27.01.24-unlocked.pdf

Question #182

A security analyst has prepared a vulnerability scan that contains all of the company's functional subnets. During the initial scan, users reported that network printers began to print pages that contained unreadable text and icons.

Which of the following should the analyst do to ensure this behavior does not oocur during subsequent vulnerability scans?



 

Answer

  • A. Perform non-credentialed scans.
  • D. Increase the threshold length of the scan timeout.
  • C. Create a tailored scan for the printer subnet.
  • B. Ignore embedded web server ports.

How to use this set

Read the preview and check whether the content and answers suit your learning goal. You can add the public set to your sets to study it. Your account shows the available actions.

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please reload the page.