Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the CompTIA CompTIA CySA+ CS0-003 Questions and answers with CertsForce

Viewing page 1 out of 15 pages
Viewing questions 1-10 out of questions
Questions # 1:

A security analyst is investigating an unusually high volume of requests received on a web server. Based on the following command and output:

access_log - [21/May/2024 13:19:06] " GET /newyddion HTTP/1.1 " 404 -

access_log - [21/May/2024 13:19:06] " GET /1970 HTTP/1.1 " 404 -

access_log - [21/May/2024 13:19:06] " GET /dopey HTTP/1.1 " 404 -

...

Which of the following best describes the activity that the analyst will confirm?

Options:

A.

SQL injection


B.

Directory brute force


C.

Remote command execution


D.

Cross-site scripting


Expert Solution
Questions # 2:

A disgruntled open-source developer has decided to sabotage a code repository with a logic bomb that will act as a wiper. Which of the following parts of the Cyber Kill Chain does this act exhibit?

Options:

A.

Reconnaissance


B.

Weaponization


C.

Exploitation


D.

Installation


Expert Solution
Questions # 3:

A Chief Information Security Officer has requested a dashboard to share critical vulnerability management goals with company leadership.

Which of the following would be the best to include in the dashboard?

Options:

A.

KPI


B.

MOU


C.

SLO


D.

SLA


Expert Solution
Questions # 4:

An analyst wants to track how quickly vulnerabilities are identified. Which of the following would be the best metric?

Options:

A.

KPI


B.

MTTD


C.

SLO


D.

Alert volume


Expert Solution
Questions # 5:

Which of the following should be configured in a WAF to mitigate an RCE attack?

Options:

A.

Rate control in deny mode


B.

Rule to detect and block OS commands


C.

Parameterized queries


D.

Stored procedure in the database


Expert Solution
Questions # 6:

A company is launching a new application in its internal network, where internal customers can communicate with the service desk. The security team needs to ensure the application will be able to handle unexpected strings with anomalous formats without crashing. Which of the following processes is the most applicable for testing the application to find how it would behave in such a situation?

Options:

A.

Fuzzing


B.

Coding review


C.

Debugging


D.

Static analysis


Expert Solution
Questions # 7:

Which of the following characteristics ensures the security of an automated information system is the most effective and economical?

Options:

A.

Originally designed to provide necessary security


B.

Subjected to intense security testing


C.

Customized to meet specific security threats


D.

Optimized prior to the addition of security


Expert Solution
Questions # 8:

An incident response analyst notices multiple emails traversing the network that target only the administrators of the company. The email contains a concealed URL that leads to an unknown website in another country. Which of the following best describes what is happening? (Choose two.)

Options:

A.

Beaconinq


B.

Domain Name System hijacking


C.

Social engineering attack


D.

On-path attack


E.

Obfuscated links


F.

Address Resolution Protocol poisoning


Expert Solution
Questions # 9:

A cybersecurity analyst is tasked with scanning a web application to understand where the scan will go and whether there are URIs that should be denied access prior to more in-depth scanning. Which of following best fits the type of scanning activity requested?

Options:

A.

Uncredentialed scan


B.

Discqyery scan


C.

Vulnerability scan


D.

Credentialed scan


Expert Solution
Questions # 10:

A team of analysts is developing a new internal system that correlates information from a variety of sources analyzes that information, and then triggers notifications according to company policy Which of the following technologies was deployed?

Options:

A.

SIEM


B.

SOAR


C.

IPS


D.

CERT


Expert Solution
Viewing page 1 out of 15 pages
Viewing questions 1-10 out of questions