Back to overview

CompTIA CySA+ CS03

All questions without description (e.g. Question #1) are from the premium version of Exam Topics. I always choosed the community answer if possible for them. The rest is from the specific documents, written in the header of each question.

Subject
No category / Others
Language of creation
English
342 flashcards No ratings yet 0 views
Add to my sets

Sign in to add this set to your collection. You will return here afterwards.

Cards in this set

Card 81

Question

Question #80

Which of the following best describes the goal of a tabletop exercise?

Answer

  • A. To test possible incident scenarios and how to react properly
  • B. To perform attack exercises to check response effectiveness
  • D. To check the effectiveness of the business continuity plan
  • C. To understand existing threat actors and how to replicate their techniques

Card 82

Question

Question #81

A virtual web server in a server pool was infected with malware after an analyst used the internet to research a system issue. After the server was rebuilt and added back into the server pool, users reported issues with the website, indicating the site could not be trusted. Which of the following is the most likely cause of the server issue?

Answer

  • B. The server was supporting weak TLS protocols for client connections.
  • A. The server was configured to use SSL to securely transmit data.
  • C. The malware infected all the web servers in the pool.
  • D. The digital certificate on the web server was self-signed.

Card 83

Question

A zero-day command injection vulnerability was published. A security administrator is analyzing the following logs for evidence of adversaries attempting to exploit the vulnerability:



Which of the following log entries provides evidence of the attempted exploit?

Answer

  • A. Log entry 1
  • D. Log entry 4
  • C. Log entry 3
  • B. Log entry 2

Card 84

Question

 

Question #83

A security analyst needs to ensure that systems across the organization are protected based on the sensitivity of the content each system hosts. The analyst is working with the respective system owners to help determine the best methodology that seeks to promote confidentiality, availability, and integrity of the data being hosted. Which of the following should the security analyst perform first to categorize and prioritize the respective systems?

Answer

  • A. Interview the users who access these systems.
  • B. Scan the systems to see which vulnerabilities currently exist.
  • C. Configure alerts for vendor-specific zero-day exploits.
  • D. Determine the asset value of each system.

Card 85

Question

Question #84

A security analyst is reviewing the following alert that was triggered by FIM on a critical system:



Which of the following best describes the suspicious activity that is occurring?

Answer

  • B. A network drive was added to allow exfiltration of data.
  • C. A new program has been set to execute on system start.
  • D. The host firewall on 192.168.1.10 was disabled.
  • A. A fake antivirus program was installed by the user.

Card 86

Question

Question #85

Which of the following best describes the document that defines the expectation to network customers that patching will only occur between 2:00 a.m. and 4:00 a.m.?

Answer

  • A. SLA
  • B. LOI
  • C. MOU
  • D. KPI

Card 87

Question

Question #86

A cybersecurity analyst is reviewing SIEM logs and observes consistent requests originating from an internal host to a blocklisted external server. Which of the following best describes the activity that is taking place?

Answer

  • A. Data exfiltration
  • C. Scanning
  • B. Rogue device
  • D. Beaconing

Card 88

Question

Question #87

An incident response team is working with law enforcement to investigate an active web server compromise. The decision has been made to keep the server running and to implement compensating controls for a period of time. The web service must be accessible from the internet via the reverse proxy and must connect to a database server. Which of the following compensating controls will help contain the adversary while meeting the other requirements? (Choose two).

Answer

  • D. Use microsegmentation to restrict connectivity to/from the web and database servers.
  • F. Move the database from the database server to the web server.
  • C. Stop the httpd service on the web server so that the adversary can not use web exploits.
  • E. Comment out the HTTP account in the /etc/passwd file of the web server.
  • A. Drop the tables on the database server to prevent data exfiltration.
  • B. Deploy EDR on the web server and the database server to reduce the adversary’s capabilities.

Card 89

Question

Question #88

An incident response team member is triaging a Linux server. The output is shown below:



Which of the following is the adversary most likely trying to do?

Answer

  • A. Create a backdoor root account named zsh.
  • C. Send a beacon to a command-and-control server.
  • D. Perform a denial-of-service attack on the web server.
  • B. Execute commands through an unsecured service account.

Card 90

Question

Question #89

A SOC analyst identifies the following content while examining the output of a debugger command over a client-server application:

getConnection(database01,"alpha" ,"AxTv.127GdCx94GTd");

Which of the following is the most likely vulnerability in this system?

Answer

  • A. Lack of input validation
  • C. Hard-coded credential
  • B. SQL injection
  • D. Buffer overflow

Card 91

Question

Question #90

A technician is analyzing output from a popular network mapping tool for a PCI audit:



Which of the following best describes the output?

Answer

  • D. The Secure Shell port on this host is closed.
  • A. The host is not up or responding.
  • B. The host is running excessive cipher suites.
  • C. The host is allowing insecure cipher suites.

Card 92

Question

Question #91

A managed security service provider is having difficulty retaining talent due to an increasing workload caused by a client doubling the number of devices connected to the network. Which of the following would best aid in decreasing the workload without increasing staff?

Answer

  • A. SIEM
  • B. XDR
  • D. EDR
  • C. SOAR

Card 93

Question

Question #92

An employee is suspected of misusing a company-issued laptop. The employee has been suspended pending an investigation by human resources. Which of the following is the best step to preserve evidence?

Answer

  • D. Make a forensic image of the device and create a SHA-1 hash.
  • A. Disable the user’s network account and access to web resources.
  • C. Place a legal hold on the device and the user’s network share.
  • B. Make a copy of the files as a backup on the server.

Card 94

Question

Question #93

An analyst receives threat intelligence regarding potential attacks from an actor with seemingly unlimited time and resources. Which of the following best describes the threat actor attributed to the malicious activity?

Answer

  • B. Ransomware group
  • C. Nation-state
  • A. Insider threat
  • D. Organized crime

Card 95

Question

Question #94

A systems analyst is limiting user access to system configuration keys and values in a Windows environment. Which of the following describes where the analyst can find these configuration items?

Answer

  • A. config.ini
  • D. Registry
  • B. ntds.dit
  • C. Master boot record

Card 96

Question

Question #95

While reviewing web server logs, a security analyst found the following line:

< IMG SRC='vbscript:msgbox("test")' >

Which of the following malicious activities was attempted?

Answer

  • A. Command injection
  • C. Server-side request forgery
  • D. Cross-site scripting
  • B. XML injection

Card 97

Question

Question #96

A security analyst at a company called ACME Commercial notices there is outbound traffic to a host IP that resolves to https://office365password.acme.co. The site’s standard VPN logon page is www.acme.com/logon. Which of the following is most likely true?

Answer

  • C. A new VPN gateway has been deployed.
  • D. A social engineering attack is underway.
  • A. This is a normal password change URL.
  • B. The security operations center is performing a routine password audit.

Card 98

Question

Question #97

A security analyst is performing vulnerability scans on the network. The analyst installs a scanner appliance, configures the subnets to scan, and begins the scan of the network. Which of the following would be missing from a scan performed with this configuration?

Answer

  • B. Registry key values
  • A. Operating system version
  • D. IP address
  • C. Open ports

Card 99

Question

Question #98

A security analyst discovers an LFI vulnerability that can be exploited to extract credentials from the underlying host. Which of the following patterns can the security analyst use to search the web server logs for evidence of exploitation of that particular vulnerability?

Answer

  • D. cat /proc/self/
  • C. ; printenv
  • A. /etc/shadow
  • B. curl localhost

Card 100

Question

Question #99

A company is in the process of implementing a vulnerability management program. Which of the following scanning methods should be implemented to minimize the risk of OT/ICS devices malfunctioning due to the vulnerability identification process?

Answer

  • D. Credentialed scanning
  • C. Agent-based scanning
  • A. Non-credentialed scanning
  • B. Passive scanning

How to use this set

Read the preview and check whether the content and answers suit your learning goal. You can add the public set to your sets to study it. Your account shows the available actions.

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please reload the page.