Back to overview

CompTIA CySA+ CS03

All questions without description (e.g. Question #1) are from the premium version of Exam Topics. I always choosed the community answer if possible for them. The rest is from the specific documents, written in the header of each question.

Subject
No category / Others
Language of creation
English
342 flashcards No ratings yet 0 views
Add to my sets

Sign in to add this set to your collection. You will return here afterwards.

Cards in this set

Card 61

Question

Question #61

A user downloads software that contains malware onto a computer that eventually infects numerous other systems. Which of the following has the user become?

Answer

  • D. Script kiddie
  • A. Hacktivist
  • B. Advanced persistent threat
  • C. Insider threat

Card 62

Question

Question #62

An organization has activated the CSIRT. A security analyst believes a single virtual server was compromised and immediately isolated from the network. Which of the following should the CSIRT conduct next?

Answer

  • B. Restore the affected server to remove any malware
  • A. Take a snapshot of the compromised server and verify its integrity
  • C. Contact the appropriate government agency to investigate
  • D. Research the malware strain to perform attribution

Card 63

Question

Question #63

During an incident, an analyst needs to acquire evidence for later investigation. Which of the following must be collected first in a computer system, related to its volatility level?

Answer

  • B. Backup data
  • C. Temporary files
  • D. Running processes
  • A. Disk contents

Card 64

Question

Question #64

A security analyst is trying to identify possible network addresses from different source networks belonging to the same company and region. Which of the following shell script functions could help achieve the goal?

Answer

  • C. function y() { dig $(dig -x $1 | grep PTR | tail -n 1 | awk -F ”.in-addr” ’{print $1}’).origin.asn.cymru.com TXT +short }
  • A. function w() { a=$(ping -c 1 $1 | awk-F ”/” ’END{print $1}’) && echo “$1 | $a” }
  • B. function x() { b=traceroute -m 40 $1 | awk ’END{print $1}’) && echo “$1 | $b” }
  • D. function z() { c=$(geoiplookup$1) && echo “$1 | $c” }

Card 65

Question

Question #65

A security analyst is writing a shell script to identify IP addresses from the same country. Which of the following functions would help the analyst achieve the objective?

Answer

  • A. function w() { info=$(ping -c 1 $1 | awk -F “/” ‘END{print $1}’) && echo “$1 | $info” }
  • B. function x() { info=$(geoiplookup $1) && echo “$1 | $info” }
  • D. function z() { info=$(traceroute -m 40 $1 | awk ‘END{print $1}’) && echo “$1 | $info” }
  • C. function y() { info=$(dig -x $1 | grep PTR | tail -n 1 ) && echo “$1 | $info” }

Card 66

Question

Question #66

A security analyst obtained the following table of results from a recent vulnerability assessment that was conducted against a single web server in the environment:

Which of the following should be completed first to remediate the findings?

Answer

  • C. Purchase an appropriate certificate from a trusted root CA
  • A. Ask the web development team to update the page contents
  • B. Add the IP address allow listing for control panel access
  • D. Perform proper sanitization on all fields

Card 67

Question

Question #67

While reviewing web server logs, an analyst notices several entries with the same time stamps, but all contain odd characters in the request line. Which of the following steps should be taken next?

Answer

  • A. Shut the network down immediately and call the next person in the chain of command.
  • B. Determine what attack the odd characters are indicative of.
  • C. Utilize the correct attack framework and determine what the incident response will consist of.
  • D. Notify the local law enforcement for incident response.

Card 68

Question

Question #67

While reviewing web server logs, an analyst notices several entries with the same time stamps, but all contain odd characters in the request line. Which of the following steps should be taken next?

Answer

  • A. Shut the network down immediately and call the next person in the chain of command.
  • B. Determine what attack the odd characters are indicative of.
  • D. Notify the local law enforcement for incident response.
  • C. Utilize the correct attack framework and determine what the incident response will consist of.

Card 69

Question

Question #68

A security team conducts a lessons-learned meeting after struggling to determine who should conduct the next steps following a security event. Which of the following should the team create to address this issue?

Answer

  • A. Service-level agreement
  • D. Memorandum of understanding
  • B. Change management plan
  • C. Incident response plan

Card 70

Question

Question #69

A cybersecurity analyst notices unusual network scanning activity coming from a country that the company does not do business with. Which of the following is the best mitigation technique?

Answer

  • B. Block the IP range of the scans at the network firewall.
  • C. Perform a historical trend analysis and look for similar scanning activity.
  • A. Geoblock the offending source country.
  • D. Block the specific IP address of the scans at the network firewall.

Card 71

Question

Question #70

An analyst has received an IPS event notification from the SIEM stating an IP address, which is known to be malicious, has attempted to exploit a zero-day vulnerability on several web servers. The exploit contained the following snippet:
 

/wp-json/trx_addons/V2/get/sc_layout?sc=wp_insert_user&role=administrator

Which of the following controls would work best to mitigate the attack represented by this snippet?

Answer

  • D. Set the directory V2 to read only for all users.
  • A. Limit user creation to administrators only.
  • C. Set the directory trx_addons to read only for all users.
  • B. Limit layout creation to administrators only.

Card 72

Question

Question #71

A penetration tester submitted data to a form in a web application, which enabled the penetration tester to retrieve user credentials. Which of the following should be recommended for remediation of this application vulnerability?

Answer

  • C. Performing input validation before allowing submission
  • B. Hashing user passwords on the web application
  • D. Segmenting the network between the users and the web server
  • A. Implementing multifactor authentication on the server OS

Card 73

Question

Question #72

A cybersecurity team lead is developing metrics to present in the weekly executive briefs. Executives are interested in knowing how long it takes to stop the spread of malware that enters the network. Which of the following metrics should the team lead include in the briefs?

Answer

  • B. Mean time to detect
  • A. Mean time between failures
  • C. Mean time to remediate
  • D. Mean time to contain

Card 74

Question

Question #73

An employee accessed a website that caused a device to become infected with invasive malware. The incident response analyst has:

• created the initial evidence log.
• disabled the wireless adapter on the device.
• interviewed the employee, who was unable to identify the website that was accessed.
• reviewed the web proxy traffic logs.

Which of the following should the analyst do to remediate the infected device?

Answer

  • D. Delete the user profile and restore data from backup.
  • B. Install an additional malware scanner that will send email alerts to the analyst.
  • A. Update the system firmware and reimage the hardware.
  • C. Configure the system to use a proxy server for Internet access.

Card 75

Question

Question #74

A cloud team received an alert that unauthorized resources were being auto-provisioned. After investigating, the team suspects that cryptomining is occurring. Which of the following indicators would most likely lead the team to this conclusion?

Answer

  • D. Unusual traffic spikes
  • C. Unauthorized changes
  • B. Bandwidth consumption
  • A. High GPU utilization

Card 76

Question

Question #75

A company’s security team is updating a section of the reporting policy that pertains to inappropriate use of resources (e.g., an employee who installs cryptominers on workstations in the office). Besides the security team, which of the following groups should the issue be escalated to first in order to comply with industry best practices?

Answer

  • A. Help desk
  • B. Law enforcement
  • D. Board member
  • C. Legal department

Card 77

Question

Question #76

Given the following CVSS string:

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which of the following attributes correctly describes this vulnerability?

Answer

  • A. A user is required to exploit this vulnerability.
  • C. The vulnerability does not affect confidentiality.
  • B. The vulnerability is network based.
  • D. The complexity to exploit the vulnerability is high.

Card 78

Question

 

Question #77

A cryptocurrency service company is primarily concerned with ensuring the accuracy of the data on one of its systems. A security analyst has been tasked with prioritizing vulnerabilities for remediation for the system. The analyst will use the following CVSSv3.1 impact metrics for prioritization:



Which of the following vulnerabilities should be prioritized for remediation?

Answer

  • B. 2
  • A. 1
  • D. 4
  • C. 3

Card 79

Question

Question #78

Patches for two highly exploited vulnerabilities were released on the same Friday afternoon. Information about the systems and vulnerabilities is shown in the tables below:





Which of the following should the security analyst prioritize for remediation?

Answer

  • A. rogers
  • D. manning
  • B. brady
  • C. brees

Card 80

Question

Question #79

A security analyst must preserve a system hard drive that was involved in a litigation request. Which of the following is the best method to ensure the data on the device is not modified?

Answer

  • A. Generate a hash value and make a backup image.
  • B. Encrypt the device to ensure confidentiality of the data.
  • C. Protect the device with a complex password.
  • D. Perform a memory scan dump to collect residual data

How to use this set

Read the preview and check whether the content and answers suit your learning goal. You can add the public set to your sets to study it. Your account shows the available actions.

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please reload the page.