[Oct 14, 2023] Free CompTIA CySA+ CS0-002 Official Cert Guide PDF Download
CompTIA CS0-002 Official Cert Guide PDF
NEW QUESTION # 96
A security analyst performs a weekly vulnerability scan on a network that has 240 devices and receives a report with 2.450 pages. Which of the following would most likely decrease the number of false positives?
- A. Penetration testing
- B. A known-environment assessment
- C. Manual validation
- D. Credentialed scanning
Answer: D
Explanation:
Credentialed scanning is a method of vulnerability scanning that uses valid user credentials to access the target systems and perform a more thorough and accurate assessment of their security posture. Credentialed scanning can help to reduce the number of false positives by allowing the scanner to access more information and resources on the systems, such as configuration files, registry keys, installed software, patches, and permissions .
NEW QUESTION # 97
A security analyst is investigating a compromised Linux server. The analyst issues the ps command and receives the following output.
Which of the following commands should the administrator run NEXT to further analyze the compromised system?
- A. /bin/la -1 /proc/1301/exe
- B. kill -9 1301
- C. strace /proc/1301
- D. rpm -V openash-server
Answer: C
NEW QUESTION # 98
Which of the following should be found within an organization's acceptable use policy?
- A. Administrator accounts must be audited monthly, and inactive accounts should be removed.
- B. Consequences of violating the policy could include discipline up to and including termination.
- C. Passwords must be eight characters in length and contain at least one special character.
- D. Customer data must be handled properly, stored on company servers, and encrypted when possible
Answer: B
NEW QUESTION # 99
A vulnerability scan returned the following results for a web server that hosts multiple wiki sites:
Apache-HTTPD-cve-2014-023: Apache HTTPD: mod_cgid denial of service CVE-2014- Due to a flaw found in mog_cgid, a server using mod_cgid to host CGI scripts could be vulnerable to a DoS attack caused by a remote attacker who is exploiting a weakness in non-standard input, causing processes to hang indefinitely.
The security analyst has confirmed the server hosts standard CGI scripts for the wiki sites, does not have mod_cgid installed, is running Apache 2.2.22, and is not behind a WAF. The server is located in the DMZ, and the purpose of the server is to allow customers to add entries into a publicly accessible database.
Which of the following would be the MOST efficient way to address this finding?
- A. Upgrade to the newest version of Apache.
- B. Place the server behind a WAF to prevent DoS attacks from occurring.
- C. Document the finding as a false positive.
- D. Disable the HTTP service and use only HTTPS to access the server.
Answer: C
NEW QUESTION # 100
A security analyst needs to provide a copy of a hard drive for forensic analysis. Which of the following would allow the analyst to perform the task?
A)
B)
C)
D)
- A. Option C
- B. Option D
- C. Option A
- D. Option B
Answer: A
Explanation:
Option C shows a device that can perform a forensic copy of a hard drive. A forensic copy, also known as a forensic image or a bit-stream image, is an exact, unaltered digital copy of a piece of digital evidence. A forensic copy captures everything on the hard drive, including active and latent data, and preserves the integrity of the original evidence. A forensic copy can be used for forensic analysis without risking any changes to the original drive1. Option C shows a device that can connect to two hard drives and create a forensic copy from one drive to another using a write-blocker. A write-blocker is a tool that prevents any data from being written to the destination drive, ensuring that only a read-only copy is made2.
NEW QUESTION # 101
Hotspot Question
Malware is suspected on a server in the environment. The analyst is provided with the output of commands from servers in the environment and needs to review all output files in order to determine which process running on one of the servers may be malware. Servers 1, 2 and 4 are clickable. Select the Server which hosts the malware, and select the process which hosts this malware.
Instructions:
If any time you would like to bring back the initial state of the simulation, please select the Reset button. When you have completed the simulation, please select the Done button to submit. Once the simulation is submitted, please select the Next button to continue.



Answer:
Explanation:
NEW QUESTION # 102
A security analyst is concerned the number of security incidents being reported has suddenly gone down. Daily business interactions have not changed, and no following should the analyst review FIRST?
- A. The firewall ACL
- B. Privileged accounts
- C. The IDS rule set
- D. The DNS configuration
Answer: C
NEW QUESTION # 103
An organization has the following risk mitigation policy:
Risks with a probability of 95% or greater will be addressed before all others regardless of the impact.
All other prioritization will be based on risk value.
The organization has identified the following risks:
Which of the following is the order of priority for risk mitigation from highest to lowest?
- A. D, A, C, B
- B. A, B, C, D
- C. A, B, D, C
- D. D, A, B, C
Answer: A
Explanation:
According to the risk mitigation policy, risks with a probability of 95% or greater will be addressed first, regardless of the impact. Therefore, risk D is the highest priority, as it has a probability of 95% and an impact of $100,000. The next priority is risk A, which has a probability of 90% and an impact of $200,000. The remaining risks will be prioritized based on their risk value, which is calculated by multiplying the probability and the impact. Risk C has a risk value of $40,000 (80% x $50,000), while risk B has a risk value of $30,000 (60% x $50,000). Therefore, risk C is higher priority than risk B.
NEW QUESTION # 104
A security analyst performs various types of vulnerability scans. Review the vulnerability scan results to determine the type of scan that was executed and if a false positive occurred for each device.
Instructions:
Select the Results Generated drop-down option to determine if the results were generated from a credentialed scan, non-credentialed scan, or a compliance scan.
For ONLY the credentialed and non-credentialed scans, evaluate the results for false positives and check the findings that display false positives. NOTE: If you would like to uncheck an option that is currently selected, click on the option a second time.
Lastly, based on the vulnerability scan results, identify the type of Server by dragging the Server to the results.
The Linux Web Server, File-Print Server and Directory Server are draggable.
If at any time you would like to bring back the initial state of the simulation, please select the Reset All button. When you have completed the simulation, please select the Done button to submit. Once the simulation is submitted, please select the Next button to continue.

Answer:
Explanation:
NEW QUESTION # 105
Due to a nse m cyberattackers seeking PHI, a healthcare company that collects highly sensitive data from millions of customers is deploying a solution that will ensure the customers' data is protected by the organization internally and externally Which of the following countermeasures can BEST prevent the loss of customers' sensitive data?
- A. Add more security resources to the environment
- B. Implement multifactor authentication
- C. Implement a nsk management process
- D. Implement privileged access management
Answer: D
NEW QUESTION # 106
A security analyst is reviewing a firewall usage report that contains traffic generated over the last 30 minutes in order to locate unusual traffic patterns:
Which of the following source IP addresses does the analyst need to investigate further?
- A. 10.18.76.179
- B. 192.168.48.147
- C. 10.50.180.49
- D. 192.168.100.5
Answer: B
NEW QUESTION # 107
An organizational policy requires one person to input accounts payable and another to do accounts receivable. A separate control requires one person to write a check and another person to sign all checks greater than $5,000 and to get an additional signature for checks greater than $10,000. Which of the following controls has the organization implemented?
- A. Non-repudiaton
- B. Segregation of duties
- C. Job rotation
- D. Dual control
Answer: B
Explanation:
Segregation of duties is a security control that requires multiple people to be involved with completing a task. This helps prevent fraud, as it ensures that no one individual has the ability to commit fraud or make mistakes without other people being aware of it
NEW QUESTION # 108
Company A is m the process of merging with Company B As part of the merger, connectivity between the ERP systems must be established so portent financial information can be shared between the two entitles.
Which of the following will establish a more automated approach to secure data transfers between the two entities?
- A. Create static NATs on each entity's firewalls that map lo the ERP systems and use native ERP authentication to allow access.
- B. Set up a VPN between Company A and Company B. granting access only lo the ERPs within the connection
- C. Set up an FTP server that both companies can access and export the required financial data to a folder.
- D. Set up a PKI between Company A and Company B and Intermediate shared certificates between the two entities
Answer: B
NEW QUESTION # 109
Which of the following is a technology used to provide Internet access to internal associates without exposing the Internet directly to the associates?
- A. Web proxy
- B. Intrusion prevention system
- C. Fuzzer
- D. Vulnerability scanner
Answer: A
NEW QUESTION # 110
Because some clients have reported unauthorized activity on their accounts, a security analyst is reviewing network packet captures from the company's API server. A portion of a capture file is shown below:
POST /services/v1_0/Public/Members.svc/soap <s:Envelope+xmlns:s="http:// schemas.s/soap/envelope/"><s:Body><GetIPLocation+xmlns="http://tempuri.org/">
<request+xmlns:a="http://schemas.somesite.org"+xmlns:i="http://www.w3.org/2001/ XMLSchema-instance"></s:Body></s:Envelope> 192.168.1.22 - - api.somesite.com 200
0 1006 1001 0 192.168.1.22
POST /services/v1_0/Public/Members.svc/soap <<a:Password>Password123</
a:Password><a:ResetPasswordToken+i:nil="true"/>
<a:ShouldImpersonatedAuthenticationBePopulated+i:nil="true"/
><a:Username>[email protected]</a:Username></request></Login></s:Body></ s:Envelope> 192.168.5.66 - - api.somesite.com 200 0 11558 1712 2024 192.168.4.89 POST /services/v1_0/Public/Members.svc/soap <s:Envelope+xmlns:s="http:// schemas.xmlsoap.org/soap/envelope/"><s:Body><GetIPLocation+xmlns="http:// tempuri.org/"> <a:IPAddress>516.7.446.605</a:IPAddress><a:ZipCode+i:nil="true"/
></request></GetIPLocation></s:Body></s:Envelope> 192.168.1.22 - -
api.somesite.com 200 0 1003 1011 307 192.168.1.22
POST /services/v1_0/Public/Members.svc/soap <s:Envelope+xmlns:s="http:// schemas.xmlsoap.org/soap/envelope/"><s:Body><IsLoggedIn+xmlns="http:// tempuri.org/"> <request+xmlns:a="http://schemas.datacontract.org/2004/07/ somesite.web+xmlns:i="http://www.w3.org/2001/XMLSchema- instance"><a:Authentication>
<a:ApiToken>kmL4krg2CwwWBan5BReGv5Djb7syxXTNKcWFuSjd</
a:ApiToken><a:ImpersonateUserId>0</a:ImpersonateUserId><a:LocationId>161222</ a:LocationId> <a:NetworkId>4</a:NetworkId><a:ProviderId>''1=1</ a:ProviderId><a:UserId>13026046</a:UserId></a:Authentication></request></ IsLoggedIn></s:Body></s:Envelope> 192.168.5.66 - - api.somesite.com 200 0 1378
1209 48 192.168.4.89
Which of the following MOST likely explains how the clients' accounts were compromised?
- A. The clients' authentication tokens were impersonated and replayed.
- B. The clients' usernames and passwords were transmitted in cleartext.
- C. A SQL injection attack was carried out on the server.
- D. An XSS scripting attack was carried out on the server.
Answer: A
NEW QUESTION # 111
You are a penetration tester who is reviewing the system hardening guidelines for a company. Hardening guidelines indicate the following.
There must be one primary server or service per device.
Only default port should be used
Non- secure protocols should be disabled.
The corporate internet presence should be placed in a protected subnet
Instructions :
Using the available tools, discover devices on the corporate network and the services running on these devices.
You must determine
ip address of each device
The primary server or service each device
The protocols that should be disabled based on the hardening guidelines

Answer:
Explanation:

NEW QUESTION # 112
An incident response team is responding to a breach of multiple systems that contain Pll and PHI Disclosure of the incident to external entities should be based on:
- A. the public relations policy.
- B. the communication plan.
- C. the responder's discretion.
- D. the senior management team's guidance.
Answer: B
Explanation:
The communication plan is an important part of incident response, as it outlines how and when information about the incident should be shared with external entities.
A communication plan is a set of procedures and protocols that define how an organization should communicate with external entities during times of emergency or security incident. The plan typically outlines how and when information about the incident should be shared, and ensures that any relevant stakeholders are informed of the incident in a timely manner. It also serves as a guide for determining what information to share with outside parties. Here is a link to an article from CompTIA's website about the importance of a communication plan for incident response for your reference: https://www.comptia.org/content/incident-response-communication-plan
NEW QUESTION # 113
An analyst needs to provide recommendations for the AUP Which of the following is the BEST recommendation to protect the company's intellectual property?
- A. Company assets must be stored in a locked cabinet when not in use.
- B. Company assets should never leave the company's property.
- C. Company assets must not be utilized for personal use or gain.
- D. AII Internet access must be via a proxy server.
Answer: D
NEW QUESTION # 114
A security analyst recently observed evidence of an attack against a company's web server. The analyst investigated the issue but was unable to find an exploit that adequately explained the observations.
Which of the following is the MOST likely cause of this issue?
- A. The security analyst needs more training on threat hunting and research.
- B. The security analyst needs updated forensic analysis tools.
- C. The security analyst has encountered a polymorphic piece of malware.
- D. The security analyst has potentially found a zero-day vulnerability that has been exploited.
Answer: D
Explanation:
If an analyst observes evidence of an attack but cannot find an exploit that adequately explains the observations, it may indicate the presence of a zero-day vulnerability, which is an unknown vulnerability that attackers can exploit to gain unauthorized access to systems. In such cases, traditional security tools may not be able to detect or prevent the attack. Therefore, the analyst should investigate further to identify and mitigate the vulnerability to prevent further exploitation.
NEW QUESTION # 115
While preparing of an audit of information security controls in the environment an analyst outlines a framework control that has the following requirements:
* All sensitive data must be classified
* All sensitive data must be purged on a quarterly basis
* Certificates of disposal must remain on file for at least three years This framework control is MOST likely classified as:
- A. prescriptive
- B. preventive
- C. risk-based
- D. corrective
Answer: A
Explanation:
Explanation
prescrcriptiveitive. now look at definition of prescriptive. The definition of prescriptive is the imposition of rules, or something that has become established because it has been going on a long time and has become customary. A handbook dictating the rules for proper behavior is an example of something that would be described as a prescriptive handbookules are being implimented.
Preventative controls describe any security measure that's designed to stop unwanted or unauthorized activity from occurring. Examples include physical controls such as fences, locks, and alarm systems; technical controls such as antivirus software, firewalls, and IPSs; and administrative controls like separation of duties, data classification, and auditing. https://www.f5.com/labs/articles/education/what-are-security-controls
NEW QUESTION # 116
While reviewing three months of logs, a security analyst notices probes from random company laptops going to SCADA equipment at the company's manufacturing location. Some of the probes are getting responses from the equipment even though firewall rules are in place, which should block this type of unauthorized activity. Which of the following should the analyst recommend to keep this activity from originating from company laptops?
- A. Require connections to the SCADA network to go through a forwarding proxy.
- B. Install security software and a host-based firewall on the SCADA equipment.
- C. Implement a group policy on company systems to block access to SCADA networks.
- D. Update the firewall rules to block SCADA network access from those laptop IP addresses.
Answer: C
NEW QUESTION # 117
Several accounting department users are reporting unusual Internet traffic in the browsing history of their workstations after returning to work and logging in. The building security team informs the IT security team that the cleaning staff was caught using the systems after the accounting department users left for the day. Which of the following steps should the IT security team take to help prevent this from happening again? (Choose two.)
- A. Set up a camera to monitor the workstations for unauthorized use.
- B. Configure a policy for workstation account timeout at three minutes.
- C. Configure NAC to set time-based restrictions on the accounting group to normal business hours.
- D. Configure mandatory access controls to allow only accounting department users to access the workstations.
- E. Install a web monitor application to track Internet usage after hours.
Answer: B,C
NEW QUESTION # 118
......
Free CS0-002 Exam Dumps to Improve Exam Score: https://www.exams4collection.com/CS0-002-latest-braindumps.html
Exam CS0-002: New Brain Dump Professional - Exams4Collection: https://drive.google.com/open?id=1ngzZG09tgzcSwHVQB6a28QVtNj0-q5hQ
