Back to overview

CompTIA CySA+ CS03

All questions without description (e.g. Question #1) are from the premium version of Exam Topics. I always choosed the community answer if possible for them. The rest is from the specific documents, written in the header of each question.

Subject
No category / Others
Language of creation
English
342 flashcards No ratings yet 0 views
Add to my sets

Sign in to add this set to your collection. You will return here afterwards.

Cards in this set

Card 121

Question

Question #120

An organization was compromised, and the usernames and passwords of all employees were leaked online. Which of the following best describes the remediation that could reduce the impact of this situation?

Answer

  • D. Password encryption
  • A. Multifactor authentication
  • C. System hardening
  • B. Password changes

Card 122

Question

Question #121

A company is deploying new vulnerability scanning software to assess its systems. The current network is highly segmented, and the networking team wants to minimize the number of unique firewall rules. Which of the following scanning techniques would be most efficient to achieve the objective?

Answer

  • B. Deploy a central scanner and perform non-credentialed scans
  • C. Deploy a cloud-based scanner and perform a network scan
  • A. Deploy agents on all systems to perform the scans
  • D. Deploy a scanner sensor on every segment and perform credentialed scans

Card 123

Question

Question #122

An organization's email account was compromised by a bad actor. Given the following information:



Which of the following is the length of time the team took to detect the threat?

Answer

  • A. Data masking
  • B. Hashing
  • D. Encoding
  • C. Watermarking

Card 124

Question

Question #123

A security administrator needs to import PII data records from the production environment to the test environment for testing purposes. Which of the following would best protect data confidentiality?

Answer

  • A. Data masking
  • C. Watermarking
  • B. Hashing
  • D. Encoding

Card 125

Question

Question #124

The email system administrator for an organization configured DKIM signing for all email legitimately sent by the organization. Which of the following would most likely indicate an email is malicious if the company's domain name is used as both the sender and the recipient?

Answer

  • B. The sending IP address is the hosting provider
  • A. The message fails a DMARC check
  • C. The signature does not meet corporate standards
  • D. The sender and reply address are different

Card 126

Question

Question #125

During an incident involving phishing, a security analyst needs to find the source of the malicious email. Which of the following techniques would provide the analyst with this information?

Answer

  • C. SSL inspection
  • A. Header analysis
  • B. Packet capture
  • D. Reverse engineering

Card 127

Question

Question #126

An analyst wants to ensure that users only leverage web-based software that has been pre-approved by the organization. Which of the following should be deployed?

Answer

  • A. Blocklisting
  • B. Allowlisting
  • C. Graylisting
  • D. Webhooks

Card 128

Question

Question #127

During a cybersecurity incident, one of the web servers at the perimeter network was affected by ransomware. Which of the following actions should be performed immediately?

Answer

  • D. Update the OS to latest version.
  • C. Quarantine the server.
  • A. Shut down the server.
  • B. Reimage the server.

Card 129

Question

Question #128

An organization recently changed its BC and DR plans. Which of the following would best allow for the incident response team to test the changes without any impact to the business?

Answer

  • C. Migrate active workloads from the primary data center to the secondary location.
  • B. Simulate an incident by shutting down power to the primary data center.
  • D. Compare the current plan to lessons learned from previous incidents.
  • A. Perform a tabletop drill based on previously identified incident scenarios.

Card 130

Question

Question #129

Security analysts review logs on multiple servers on a daily basis. Which of the following implementations will give the best central visibility into the events occurring throughout the corporate environment without logging in to the servers individually?

Answer

  • D. Automate the emailing of logs to the analysts.
  • A. Deploy a database to aggregate the logging
  • B. Configure the servers to forward logs to a SIEM
  • C. Share the log directory on each server to allow local access.

Card 131

Question

Question #130

Following a recent security incident, the Chief Information Security Officer is concerned with improving visibility and reporting of malicious actors in the environment. The goal is to reduce the time to prevent lateral movement and potential data exfiltration. Which of the following techniques will best achieve the improvement?

Answer

  • D. Service-level agreement uptime
  • B. Mean time to respond
  • A. Mean time to detect
  • C. Mean time to remediate

Card 132

Question

Question #131

After identifying a threat, a company has decided to implement a patch management program to remediate vulnerabilities. Which of the following risk management principles is the company exercising?

Answer

  • C. Mitigate
  • A. Transfer
  • D. Avoid
  • B. Accept

Card 133

Question

Question #132

A security analyst discovers an ongoing ransomware attack while investigating a phishing email. The analyst downloads a copy of the file from the email and isolates the affected workstation from the network. Which of the following activities should the analyst perform next?

Answer

  • A. Wipe the computer and reinstall software
  • B. Shut down the email server and quarantine it from the network
  • D. Search for other mail users who have received the same file
  • C. Acquire a bit-level image of the affected workstation

Card 134

Question

Question #133

The security analyst received the monthly vulnerability report. The following findings were included in the report:

• Five of the systems only required a reboot to finalize the patch application
• Two of the servers are running outdated operating systems and cannot be patched

The analyst determines that the only way to ensure these servers cannot be compromised is to isolate them. Which of the following approaches will best minimize the risk of the outdated servers being compromised?

Answer

  • B. Due diligence
  • A. Compensating controls
  • C. Maintenance windows
  • D. Passive discovery

Card 135

Question

Question #134

The vulnerability analyst reviews threat intelligence regarding emerging vulnerabilities affecting workstations that are used within the company:



Which of the following vulnerabilities should the analyst be most concerned about, knowing that end users frequently click on malicious links sent via email?

Answer

  • A. Vulnerability A
  • C. Vulnerability C
  • D. Vulnerability D
  • B. Vulnerability B

Card 136

Question

Question #135

An incident response analyst is taking over an investigation from another analyst. The investigation has been going on for the past few days. Which of the following steps is most important during the transition between the two analysts?

Answer

  • A. Identify and discuss the lessons learned with the prior analyst.
  • C. Review the steps that the previous analyst followed.
  • D. Validate the root cause from the prior analyst.
  • B. Accept all findings and continue to investigate the next item target.

Card 137

Question

Question #136

A company recently removed administrator rights from all of its end user workstations. An analyst uses CVSSv3.1 exploitability metrics to prioritize the vulnerabilities for the workstations and produces the following information:



Which of the following vulnerabilities should be prioritized for remediation?

Answer

  • A. nessie.explosion
  • D. great.skills
  • C. sweet.bike
  • B. vote.4p

Card 138

Question

Question #137

A recent penetration test discovered that several employees were enticed to assist attackers by visiting specific websites and running downloaded files when prompted by phone calls. Which of the following would best address this issue?

Answer

  • D. Disabling all staff members’ ability to run downloaded applications
  • A. Increasing training and awareness for all staff
  • B. Ensuring that malicious websites cannot be visited
  • C. Blocking all scripts downloaded from the internet

Card 139

Question

Question #138

A security analyst at a company is reviewing an alert from the file integrity monitoring indicating a mismatch in the login. html file hash. After comparing the code with the previous version of the page source code, the analyst found the following code snippet added:



Which of the following best describes the activity the analyst has observed?

Answer

  • B. Exfiltration
  • A. Obfuscated links
  • C. Unauthorized changes
  • D. Beaconing

Card 140

Question

Question #139

A security administrator has been notified by the IT operations department that some vulnerability reports contain an incomplete list of findings. Which of the following methods should be used to resolve this issue?

Answer

  • D. Network scan
  • C. Differential scan
  • B. External scan
  • A. Credentialed scar

How to use this set

Read the preview and check whether the content and answers suit your learning goal. You can add the public set to your sets to study it. Your account shows the available actions.

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please reload the page.