Pass CompTIA CS0-002 PDF Dumps | Recently Updated 371 Questions
Updated Test Engine to Practice CS0-002 Dumps & Practice Exam
CompTIA CS0-002 exam is a rigorous exam that requires candidates to have a thorough understanding of cybersecurity concepts and practices. CS0-002 exam consists of 85 multiple-choice and performance-based questions that must be completed within 165 minutes. Candidates must score a minimum of 750 out of 900 to pass the exam and earn the CompTIA CySA+ certification. CompTIA Cybersecurity Analyst (CySA+) Certification Exam certification is valid for three years and can be renewed through CompTIA's Continuing Education (CE) program.
NEW QUESTION # 81
Which of the following attack techniques has the GREATEST likelihood of quick success against Modbus assets?
- A. Buffer overflow
- B. Unauthenticated commands
- C. Remote code execution
- D. Certificate spoofing
Answer: B
Explanation:
Modbus is a communication protocol that is widely used in industrial control systems (ICS). Modbus does not have any built-in security features, such as authentication or encryption, which makes it vulnerable to various attacks. One of the most common and effective attack techniques against Modbus assets is to send unauthenticated commands to manipulate or disrupt the operation of the devices. Remote code execution, buffer overflow, and certificate spoofing are other attack techniques, but they have less likelihood of quick success against Modbus assets. Reference: https://www.sciencedirect.com/science/article/pii/S2405959517300045
NEW QUESTION # 82
In an effort to be proactive, an analyst has run an assessment against a sample workstation before auditors visit next month. The scan results are as follows:
Based on the output of the scan, which of the following is the BEST answer?
- A. Failed compliance check
- B. Successful sensitivity level check
- C. Failed credentialed scan
- D. Failed asset inventory
Answer: C
NEW QUESTION # 83
Which of the following is an advantage of continuous monitoring as a way to help protect an enterprise?
- A. Continuous monitoring uses automation to identify threats and alerts in real time
- B. Continuous monitoring leverages open-source tools, thereby reducing cost to the organization.
- C. Continuous monitoring blocks malicious activity by connecting to real-lime threat feeds.
- D. Continuous monitoring responds to active Intrusions without requiring human assistance.
Answer: A
Explanation:
Continuous monitoring uses automation to identify threats and alerts in real time. This is an advantage of continuous monitoring as a way to help protect an enterprise because it enables faster detection and response to security incidents, reduces the risk of human error, and improves the overall security posture and compliance of the organization.
NEW QUESTION # 84
A security analyst receives an alert that highly sensitive information has left the company's network Upon investigation, the analyst discovers an outside IP range has had connections from three servers more than 100 times m the past month.
The affected servers are virtual machines.
Which of the following is the BEST course of action?
- A. Disconnect the affected servers from the network, use the virtual machine console to access the systems, determine which information has left the network, find the security weakness, and remediate
- B. Determine if any other servers have been affected, snapshot any servers found, determine the vector that was used to allow the data exfiltration. fix any vulnerabilities, remediate, and report.
- C. Shut down the servers as soon as possible, move them to a clean environment, restart, run a vulnerability scanner to find weaknesses determine the root cause, remediate, and report
- D. Report the data exfiltration to management take the affected servers offline, conduct an antivirus scan, remediate all threats found, and return the servers to service.
Answer: C
NEW QUESTION # 85
A security analyst is reviewing WAF alerts and sees the following request:
Which of the following BEST describes the attack?
- A. Denial of service
- B. SQL injection
- C. LDAP injection
- D. Command injection
Answer: B
Explanation:
The attack is a SQL injection attack. SQL injection is a type of attack that exploits a security vulnerability in an application's software that allows user input to be executed as SQL commands by the underlying database3. SQL injection can enable an attacker to perform various malicious actions on the database, such as reading, modifying, deleting or creating data; executing commands; or bypassing authentication. The request shows that the attacker has entered a malicious SQL statement in the username parameter that attempts to drop (delete) all tables in the database.
NEW QUESTION # 86
A team of security analysts has been alerted to potential malware activity. The initial examination indicates one of the affected workstations is beaconing on TCP port 80 to five IP addresses and attempting to spread across the network over port 445.
Which of the following should be the team's NEXT step during the detection phase of this response process?
- A. Depending on system criticality, remove each affected device from the network by disabling wired and wireless connections.
- B. Engage the engineering team to block SMB traffic internally and outbound HTTP traffic to the five IP addresses.
- C. Escalate the incident to management, who will then engage the network infrastructure team to keep them informed.
- D. Identify potentially affected systems by creating a correlation search in the SIEM based on the network traffic.
Answer: D
NEW QUESTION # 87
Which of the following commands would a security analyst use to make a copy of an image for forensics use?
- A. dd
- B. wget
- C. rm
- D. touch
Answer: A
NEW QUESTION # 88
A security analyst is investigating a malware infection that occurred on a Windows system. The system was not connected to a network and had no wireless capability Company policy prohibits using portable media or mobile storage The security analyst is trying to determine which user caused the malware to get onto the system Which of the following registry keys would MOST likely have this information?
A)
B)
C)
D)
- A. Option B
- B. Option C
- C. Option A
- D. Option D
Answer: B
NEW QUESTION # 89
A security analyst is responding to an incident on a web server on the company network that is making a large number of outbound requests over DNS Which of the following is the FIRST step the analyst should take to evaluate this potential indicator of compromise'?
- A. Shut down the system to prevent further degradation of the company network
- B. Reimage the machine to remove the threat completely and get back to a normal running state.
- C. Start a network capture on the system to look into the DNS requests to validate command and control traffic.
- D. Run an anti-malware scan on the system to detect and eradicate the current threat
- E. Isolate the system on the network to ensure it cannot access other systems while evaluation is underway.
Answer: E
NEW QUESTION # 90
An organization has a strict policy that if elevated permissions are needed, users should always run commands under their own account, with temporary administrator privileges if necessary. A security analyst is reviewing syslog entries and sees the following:
Which of the following entries should cause the analyst the MOST concern?
- A. <100>2 2020-01-10T20:36:36.0010z financeserver su 201 32001 = BOM ' sudo vi users.txt success
- B. <100> 2020-01-10T19:33:48.002z webserver sudo 201 32001 = BOM ' su vi httpd.conf' success
- C. <100> 2020-01-10T19:33:48.002z webserver sudo 201 32001 = BOM ' su vi syslog.conf failed for jos
- D. <100> 2020-01-10T19:34..002z financeserver su 201 32001 = BOM ' su vi success
- E. <100>2 2020-01-10T19:33:41.002z webserver su 201 32001 = BOM ' su vi httpd.conf' failed for joe
Answer: E
NEW QUESTION # 91
A security analyst has observed several incidents within an organization that are affecting one specific piece of hardware on the network. Further investigation reveals the equipment vendor previously released a patch.
Which of the following is the MOST appropriate threat classification for these incidents?
- A. Zero day
- B. Advanced persistent threat
- C. Unknown threat
- D. Known threat
Answer: C
NEW QUESTION # 92
A company's change management team has asked a security analyst to review a potential change to the email server before it is released into production. The analyst reviews the following change request:
Which of the following is the MOST likely reason for the change?
- A. To reject email from email addresses that are not digitally signed.
- B. To accept email to the company's domain.
- C. To reject email from servers that are not listed in the SPF record
- D. To reject email from users who are not authenticated to the network.
Answer: C
NEW QUESTION # 93
After running a packet analyzer on the network, a security analyst has noticed the following output:
Which of the following is occurring?
- A. A ping sweep
- B. A network map
- C. A service discovery
- D. A port scan
Answer: D
NEW QUESTION # 94
A company notices unknown devices connecting to the internal network and would like to implement a solution to block all non-corporate managed machines. Which of the following solutions would be best to accomplish this goal?
- A. RADIUS with challenge/response
- B. NAC with 802.1X implementation
- C. Extensible Authentication Protocol
- D. WPA2 for W1F1 networks
Answer: B
Explanation:
This solution is the best to accomplish the goal of blocking all non-corporate managed machines from connecting to the internal network. NAC stands for network access control, which is a method of enforcing policies and rules on network devices based on their identity, role, location, and other attributes. 802.1X is a standard for port-based network access control, which authenticates devices before granting them access to a network port or wireless access point.
NEW QUESTION # 95
A security analyst gathered forensics from a recent intrusion in preparation for legal proceedings. The analyst used EnCase to gather the digital forensics, cloned the hard drive, and took the hard drive home for further analysis. Which of the following did the security analyst violate?
- A. Cloning procedures
- B. Virtualization
- C. Hashing procedures
- D. Chain of custody
Answer: D
NEW QUESTION # 96
A security analyst is performing a Diamond Model analysis of an incident the company had last quarter. A potential benefit of this activity is that it can identify:
- A. which analysts require more training.
- B. the time spent by analysts on each of the incidents.
- C. detection and prevention capabilities to improve.
- D. which systems were exploited more frequently.
- E. possible evidence that is missing during forensic analysis.
Answer: C
Explanation:
A Diamond Model analysis of an incident is a framework that identifies the four essential features of an attack: adversary, capability, infrastructure, and victim1 By analyzing these features and their relationships, a security analyst can gain insights into the attack's objectives, methods, sources, and targets. A potential benefit of this activity is that it can identify detection and prevention capabilities to improve, such as gaps in security controls, indicators of compromise, or mitigation strategies2
NEW QUESTION # 97
A company is building a new fabrication plant and designing its production lines based on the products it manufactures and the networks to support them. The security engineer has the following requirements:
* Each production line must be secured using a single posture.
* Each production line must only communicate with the other lines in a least privilege method.
* Access to each production line from the rest of the network must be strictly controlled.
To best provide the protection that meets these requirements, each product line should be:
- A. logically segmented and firewalled to control inbound and outbound connectivity.
- B. logically segmented and then air gapped to specifically limit traffic.
- C. air gapped but connected to one another by data diodes.
- D. air gapped and firewalled to manage connectivity.
Answer: A
Explanation:
Logical segmentation is a technique that divides a network into smaller, isolated segments based on logical criteria, such as function, role, or application. Logical segmentation can be implemented using various technologies, such as VLANs, subnets, virtual firewalls, or software-defined networking (SDN). Logical segmentation can enhance the security of a network by reducing the attack surface, limiting the lateral movement of threats, enforcing the principle of least privilege, and facilitating the monitoring and auditing of network traffic12.
Firewall is a device or software that filters and controls the incoming and outgoing network traffic based on predefined rules or policies. Firewall can be deployed at the network perimeter or within the network to create internal zones or segments. Firewall can protect a network from unauthorized access, malicious attacks, or data exfiltration by allowing or blocking traffic based on the source, destination, port, protocol, or application3 .
To best provide the protection that meets the requirements of the security engineer, each product line should be logically segmented and firewalled to control inbound and outbound connectivity. This way, each product line can be secured using a single posture that is consistent and manageable. Each product line can also communicate with the other lines in a least privilege method by allowing only the necessary traffic and blocking the rest. Access to each product line from the rest of the network can be strictly controlled by applying firewall rules that restrict or limit the traffic based on the business needs.
NEW QUESTION # 98
An employee in the billing department accidentally sent a spreadsheet containing payment card data to a recipient outside the organization.
The employee intended to send the spreadsheet to an internal staff member with a similar name and was unaware of the mistake until the recipient replied to the message.
In addition to retraining the employee, which of the following would prevent this from happening in the future?
- A. Remove all external recipients from the employee's address book
- B. Set the outgoing mail filter to strip spreadsheet attachments from all messages.
- C. Configure the outgoing mail filter to allow attachments only to addresses on the whitelist
- D. Implement outgoing filter rules to quarantine messages that contain card data
Answer: C
NEW QUESTION # 99
In web application scanning, static analysis refers to scanning:
- A. an application that is installed on a system that is assigned a static IP.
- B. the compiled code of the application to detect possible issues.
- C. an application that is installed and active on a system.
- D. the system for vulnerabilities before installing the application.
Answer: B
Explanation:
This type of analysis is performed before the application is installed and active on a system, and it involves examining the code without actually executing it in order to identify potential vulnerabilities or security risks.
As per CYSA+ 002 Study Guide: Static analysis is conducted by reviewing the code for an application. Static analysis does not run the program; instead, it focuses on understanding how the program is written and what the code is intended to do.
Static analysis refers to scanning the source code or the compiled code of an application without executing it, to identify potential vulnerabilities, errors, or bugs. Static analysis can help improve the quality and security of the code before it is deployed or run4
NEW QUESTION # 100
A security incident has been created after noticing unusual behavior from a Windows domain controller. The server administrator has discovered that a user logged in to the server with elevated permissions, but the user's account does not follow the standard corporate naming scheme. There are also several other accounts in the administrators group that do not follow this naming scheme. Which of the following is the possible cause for this behavior and the BEST remediation step?
- A. The naming scheme allows for too many variations, and the account naming convention should be updates to enforce organizational policies.
- B. The server administrator created user accounts cloning the wrong user ID, and the accounts should be removed from administrators and placed in an employee group.
- C. The server has been compromised and should be removed from the network and cleaned before reintroducing it to the network.
- D. The Windows Active Directory domain controller has not completed synchronization, and should force the domain controller to sync.
Answer: A
NEW QUESTION # 101
A company's marketing emails are either being found in a spam folder or not being delivered at all. The security analyst investigates the issue and discovers the emails in question are being sent on behalf of the company by a third party in1marketingpartners.com Below is the exiting SPP word:
Which of the following updates to the SPF record will work BEST to prevent the emails from being marked as spam or blocked?
A)
B)
C)
D)
- A. Option B
- B. Option A
- C. Option C
- D. Option D
Answer: A
NEW QUESTION # 102
A web-based front end for a business intelligence application uses pass-through authentication to authenticate users. The application then uses a service account to perform queries and look up data in a database. A security analyst discovers employees are accessing data sets they have not been authorized to use. Which of the following will fix the cause of the issue?
- A. Change the security model to force the users to access the database as themselves
- B. Configure database security logging using syslog or a SIEM
- C. Enforce unique session IDs so users do not get a reused session ID
- D. Parameterize queries to prevent unauthorized SQL queries against the database
Answer: A
NEW QUESTION # 103
......
What are the prerequisites for CompTIA CS0-002 Exam
Suggested:
- Minimum 4 years of practical experience in information security or related experience.
- Network +, Security + or equivalent knowledge.
CompTIA CS0-002 Dumps Cover Real Exam Questions: https://www.examcollectionpass.com/CompTIA/CS0-002-practice-exam-dumps.html
Dumps Collection CS0-002 Test Engine Dumps Training With 371 Questions: https://drive.google.com/open?id=1Byt11cV6z2iemLfK__LVd2r_5nlLudEi