Back to overview

CompTIA CySA+ CS03

All questions without description (e.g. Question #1) are from the premium version of Exam Topics. I always choosed the community answer if possible for them. The rest is from the specific documents, written in the header of each question.

Subject
No category / Others
Language of creation
English
342 flashcards No ratings yet 0 views
Add to my sets

Sign in to add this set to your collection. You will return here afterwards.

Cards in this set

Card 141

Question

Question #140

An organization enabled a SIEM rule to send an alert to a security analyst distribution list when ten failed logins occur within one minute. However, the control was unable to detect an attack with nine failed logins. Which of the following best represents what occurred?

Answer

  • C. False negative
  • D. True positive
  • B. True negative
  • A. False positive

Card 142

Question

Question #141

A cybersecurity analyst is tasked with scanning a web application to understand where the scan will go and whether there are URIs that should be denied access prior to more in-depth scanning. Which of following best fits the type of scanning activity requested?

Answer

  • A. Uncredentialed scan
  • B. Discovery scan
  • C. Vulnerability scan
  • D. Credentialed scan

Card 143

Question

Question #142

Which of the following best describes the process of requiring remediation of a known threat within a given time frame?

Answer

  • A. SLA
  • D. Organizational governance
  • C. Best-effort patching
  • B. MOU

Card 144

Question

Question #143

Which of the following risk management principles is accomplished by purchasing cyber insurance?

Answer

  • C. Mitigate
  • B. Avoid
  • D. Transfer
  • A. Accept

Card 145

Question

Question #144

A recent audit of the vulnerability management program outlined the finding for increased awareness of secure coding practices. Which of the following would be best to address the finding?

Answer

  • A. Establish quarterly SDLC training on the top vulnerabilities for developers
  • B. Conduct a yearly inspection of the code repositories and provide the report to management.
  • D. Deploy more vulnerability scanners for increased coverage
  • C. Hire an external penetration test of the network

Card 146

Question

Question #145

An organization has deployed a cloud-based storage system for shared data that is in phase two of the data life cycle. Which of the following controls should the security team ensure are addressed? (Choose two.)

Answer

  • D. Encryption
  • C. Data loss prevention
  • B. Data destruction
  • A. Data classification
  • F. Access controls
  • E. Backups

Card 147

Question

Question #146

An analyst is conducting routine vulnerability assessments on the company infrastructure. When performing these scans, a business-critical server crashes, and the cause is traced back to the vulnerability scanner. Which of the following is the cause of this issue?

Answer

  • B. The scanner is running in active mode.
  • C. The scanner is segmented improperly
  • A. The scanner is running without an agent installed.
  • D. The scanner is configured with a scanning window

Card 148

Question

Question #147

An organization's threat intelligence team notes a recent trend in adversary privilege escalation procedures. Multiple threat groups have been observed utilizing native Windows tools to bypass system controls and execute commands with privileged credentials. Which of the following controls would be most effective to reduce the rate of success of such attempts?

Answer

  • B. Implement MFA requirements for all internal resources
  • A. Set user account control protection to the most restrictive level on all devices
  • C. Harden systems by disabling or removing unnecessary services
  • D. Implement controls to block execution of untrusted applications

Card 149

Question

Question #148

A new zero-day vulnerability was released. A security analyst is prioritizing which systems should receive deployment of compensating controls deployment first. The systems have been grouped into the categories shown below:


Which of the following groups should be prioritized for compensating controls?

Answer

  • A. Group A
  • D. Group D
  • B. Group B
  • C. Group C

Card 150

Question

Question #149

A Chief Information Security Officer wants to map all the attack vectors that the company faces each day. Which of the following recommendations should the company align their security controls around?

Answer

  • A. OSSTMM
  • B. Diamond Model of Intrusion Analysis
  • D. MITRE ATT&CK
  • C. OWASP

Card 151

Question

Question #150

Which of the following actions would an analyst most likely perform after an incident has been investigated?

Answer

  • A. Risk assessment
  • B. Root cause analysis
  • D. Tabletop exercise
  • C. Incident response plan

Card 152

Question

Question #151

After completing a review of network activity, the threat hunting team discovers a device on the network that sends an outbound email via a mail client to a non-company email address daily at 10:00 p.m. Which of the following is potentially occurring?

Answer

  • A. Irregular peer-to-peer communication
  • B. Rogue device on the network
  • C. Abnormal OS process behavior
  • D. Data exfiltration

Card 153

Question

Question #152

A vulnerability scanner generates the following output:



The company has an SLA for patching that requires time frames to be met for high-risk vulnerabilities. Which of the following should the analyst prioritize first for remediation?

Answer

  • B. Cisco Webex
  • C. Redis Server
  • A. Oracle JDK
  • D. SSL Self-signed Certificate

Card 154

Question

Question #153

A web application team notifies a SOC analyst that there are thousands of HTTP/404 events on the public-facing web server. Which of the following is the next step for the analyst to take?

Answer

  • B. Escalate the event to an incident and notify the SOC manager of the activity
  • C. Notify the incident response team that there is a DDoS attack occurring
  • A. Instruct the firewall engineer that a rule needs to be added to block this external server
  • D. Identify the IP/hostname for the requests and look at the related activity

Card 155

Question

Question #154

Which of the following best describes the reporting metric that should be utilized when measuring the degree to which a system application, or user base is affected by an uptime availability outage?

Answer

  • C. Impact
  • D. Scope
  • A. Timeline
  • B. Evidence

Card 156

Question

Question #155

A security analyst needs to provide evidence of regular vulnerability scanning on the company's network for an auditing process. Which of the following is an example of a tool that can produce such evidence?

Answer

  • B. Burp Suite
  • A. OpenVAS
  • C. Nmap
  • D. Wireshark

Card 157

Question

Question #156

A security analyst performs a vulnerability scan. Based on the metrics from the scan results, the analyst must prioritize which hosts to patch. The analyst runs the tool and receives the following output:



Which of the following hosts should be patched first, based on the metrics?

Answer

  • B. host02
  • C. host03
  • A. host01
  • D. host04

Card 158

Question

Question #157

An organization receives a legal hold request from an attorney. The request pertains to emails related to a disputed vendor contract. Which of the following is the best step for the security team to take to ensure compliance with the request?

Answer

  • A. Publicly disclose the request to other vendors
  • C. Establish a chain of custody starting with the attorney's request
  • B. Notify the departments involved to preserve potentially relevant information
  • D. Back up the mailboxes on the server and provide the attorney with a copy

Card 159

Question

Question #158

A company has the following security requirements:

• No public IPs
• All data secured at rest
• No insecure ports/protocols

After a cloud scan is completed a security analyst receives reports that several misconfigurations are putting the company at risk. Given the following cloud scanner output:



Which of the following should the analyst recommend be updated first to meet the security requirements and reduce risks?

Answer

  • B. VM_DEV_DB
  • A. VM_PRD_DB
  • D. VM_PRD_Web01
  • C. VM_DEV_Web02

Card 160

Question

Question #159

Which of the following best describes the actions taken by an organization after the resolution of an incident that addresses issues and reflects on the growth opportunities for future incidents?

Answer

  • C. Root cause analysis
  • A. Lessons learned
  • D. Regulatory compliance
  • B. Scrum review

How to use this set

Read the preview and check whether the content and answers suit your learning goal. You can add the public set to your sets to study it. Your account shows the available actions.

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please reload the page.