Back to overview

CompTIA CySA+ CS03

All questions without description (e.g. Question #1) are from the premium version of Exam Topics. I always choosed the community answer if possible for them. The rest is from the specific documents, written in the header of each question.

Subject
No category / Others
Language of creation
English
342 flashcards No ratings yet 0 views
Add to my sets

Sign in to add this set to your collection. You will return here afterwards.

Cards in this set

Card 161

Question

Question #160

An analyst is becoming overwhelmed with the number of events that need to be investigated for a timeline. Which of the following should the analyst focus on in order to move the incident forward?

Answer

  • C. Mean time to detect
  • A. Impact
  • D. Isolation
  • B. Vulnerability score

Card 162

Question

Question #161

To minimize the impact of a security incident, a cybersecurity analyst has configured audit settings in the organization’s cloud services. Which of the following security controls has the analyst configured?

Answer

  • A. Preventive
  • B. Corrective
  • C. Directive
  • D. Detective

Card 163

Question

Question #162

A web developer reports the following error that appeared on a development server when testing a new application:



Which of the following tools can be used to identify the application’s point of failure?

Answer

  • C. Immunity debugger
  • D. Burp Suite
  • B. Angry IP scanner
  • A. OpenVAS

Card 164

Question

Question #163

Which of the following describes a contract that is used to define the various levels of maintenance to be provided by an external business vendor in a secure environment?

Answer

  • C. BIA
  • D. SLA
  • A. MOU
  • B. NDA

Card 165

Question

 

Question #164

A security team is concerned about recent Layer 4 DDoS attacks against the company website. Which of the following controls would best mitigate the attacks?

Answer

  • D. Implement a load balancer
  • A. Block the attacks using firewall rules
  • B. Deploy an IPS in the perimeter network
  • C. Roll out a CDN

Card 166

Question

 

Question #165

An analyst is reviewing system logs while threat hunting:



Which of the following hosts should be investigated first?

Answer

  • A. PC1
  • B. PC2
  • E. PC5
  • D. PC4
  • C. PC3

Card 167

Question

Question #166

An organization needs to bring in data collection and aggregation from various endpoints. Which of the following is the best tool to deploy to help analysts gather this data?

Answer

  • A. DLP
  • C. EDR
  • B. NAC
  • D. NIDS

Card 168

Question

 

Question #167

A regulated organization experienced a security breach that exposed a list of customer names with corresponding PII data. Which of the following is the best reason for developing the organization's communication plans?

Answer

  • B. To ensure incidents are immediately reported to a regulatory agency
  • A. For the organization's public relations department to have a standard notification
  • C. To automate the notification to customers who were impacted by the breach
  • D. To have approval from executive leadership on when communication should occur

Card 169

Question

Question #168

Following an incident, a security analyst needs to create a script for downloading the configuration of all assets from the cloud tenancy. Which of the following authentication methods should the analyst use?

Answer

  • A. MFA
  • C. PAM
  • D. Key pair
  • B. User and password

Card 170

Question

 

Question #169

A penetration tester is conducting a test on an organization's software development website. The penetration tester sends the following request to the web interface:



Which of the following exploits is most likely being attempted?

Answer

  • B. Local file inclusion
  • C. Cross-site scripting
  • A. SQL injection
  • D. Directory traversal

Card 171

Question

 

Question #170

Two employees in the finance department installed a freeware application that contained embedded malware. The network is robustly segmented based on areas of responsibility. These computers had critical sensitive information stored locally that needs to be recovered. The department manager advised all department employees to turn off their computers until the security team could be contacted about the issue. Which of the following is the first step the incident response staff members should take when they arrive?

Answer

  • A. Turn on all systems, scan for infection, and back up data to a USB storage device.
  • D. Log on to the impacted systems with an administrator account that has privileges to perform backups.
  • C. Explain that malware cannot truly be removed and then reimage the devices.
  • B. Identify and remove the software installed on the impacted systems in the department.
  • E. Segment the entire department from the network and review each computer offline.

Card 172

Question

 

Question #171

A manufacturer has hired a third-party consultant to assess the security of an OT network that includes both fragile and legacy equipment. Which of the following must be considered to ensure the consultant does no harm to operations?

Answer

  • A. Employing Nmap Scripting Engine scanning techniques
  • B. Preserving the state of PLC ladder logic prior to scanning
  • C. Using passive instead of active vulnerability scans
  • D. Running scans during off-peak manufacturing hours

Card 173

Question

 

Question #172

A team of analysts is developing a new internal system that correlates information from a variety of sources, analyzes that information, and then triggers notifications according to company policy. Which of the following technologies was deployed?

Answer

  • A. SIEM
  • B. SOAR
  • D. CERT
  • C. IPS

Card 174

Question

Question #173

Which of following would best mitigate the effects of a new ransomware attack that was not properly stopped by the company antivirus?

Answer

  • A. Install a firewall.
  • B. Implement vulnerability management.
  • C. Deploy sandboxing.
  • D. Update the application blocklist.

Card 175

Question

Question #174

A Chief Information Security Officer wants to implement security by design, starting with the implementation of a security scanning method to identify vulnerabilities, including SQL injection, RFI, XSS, etc. Which of the following would most likely meet the requirement?

Answer

  • C. Dynamic application security testing
  • B. Known environment testing
  • A. Reverse engineering
  • D. Code debugging

Card 176

Question

Question #175

A security analyst scans a host and generates the following output:



Which of the following best describes the output?

Answer

  • D. The host is vulnerable to web-based exploits.
  • B. The host is running a vulnerable mail server.
  • C. The host is allowing unsecured FTP connections.
  • A. The host is unresponsive to the ICMP request.

Card 177

Question

Question #176

The security team at a company, which was a recent target of ransomware, compiled a list of hosts that were identified as impacted and in scope for this incident. Based on the following host list:



Which of the following systems was most pivotal to the threat actor in its distribution of the encryption binary via Group Policy?

Answer

  • B. WK10-Sales07
  • A. SQL01
  • C. WK7-Plant01
  • D. DCEast01
  • E. HQAdmin9

Card 178

Question

Question #177

After a security assessment was done by a third-party consulting firm, the cybersecurity program recommended integrating DLP and CASE to reduce analyst alert fatigue. Which of the following is the best possible outcome that this effort hopes to achieve?

Answer

  • C. False positive rates drop to 20%.
  • B. Phishing alerts drop by 20%.
  • D. The MTTR decreases by 20%.
  • A. SIEM ingestion logs are reduced by 20%.

Card 179

Question

Question #178

Which of the following threat actors is most likely to target a company due to its questionable environmental policies?

Answer

  • B. Organized crime
  • D. Lone wolf
  • C. Nation-state
  • A. Hacktivist

Card 180

Question

Question #179

A cybersecurity analyst is recording the following details:

• ID
• Name
• Description
• Classification of information
• Responsible party

In which of the following documents is the analyst recording this information?

Answer

  • B. Change control documentation
  • D. Incident response plan
  • C. Incident response playbook
  • A. Risk register

How to use this set

Read the preview and check whether the content and answers suit your learning goal. You can add the public set to your sets to study it. Your account shows the available actions.

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please reload the page.