Pass the CompTIA CompTIA CySA+ CS0-003 Questions and answers with CertsForce

Viewing page 11 out of 13 pages
Viewing questions 101-110 out of questions
Questions # 101:

Due to an incident involving company devices, an incident responder needs to take a mobile phone to the lab for further investigation. Which of the following tools should be used to maintain the integrity of the mobile phone while it is transported? (Select two).

Options:

A.

Signal-shielded bag


B.

Tamper-evident seal


C.

Thumb drive


D.

Crime scene tape


E.

Write blocker


F.

Drive duplicator


Expert Solution
Questions # 102:

A report contains IoC and TTP information for a zero-day exploit that leverages vulnerabilities in a specific version of a web application. Which of the following actions should a SOC analyst take first after receiving the report?

Options:

A.

Implement a vulnerability scan to determine whether the environment is at risk.


B.

Block the IP addresses and domains from the report in the web proxy and firewalls.


C.

Verify whether the information is relevant to the organization.


D.

Analyze the web application logs to identify any suspicious or malicious activity.


Expert Solution
Questions # 103:

A company that has a geographically diverse workforce and dynamic IPs wants to implement a vulnerability scanning method with reduced network traffic. Which of the following would best meet this requirement?

Options:

A.

External


B.

Agent-based


C.

Non-credentialed


D.

Credentialed


Expert Solution
Questions # 104:

A security analyst detects an email server that had been compromised in the internal network. Users have been reporting strange messages in their email inboxes and unusual network traffic. Which of the following incident response steps should be performed next?

Options:

A.

Preparation


B.

Validation


C.

Containment


D.

Eradication


Expert Solution
Questions # 105:

A security analyst would like to integrate two different SaaS-based security tools so that one tool can notify the other in the event a threat is detected. Which of the following should the analyst utilize to best accomplish this goal?

Options:

A.

SMB share


B.

API endpoint


C.

SMTP notification


D.

SNMP trap


Expert Solution
Questions # 106:

Which of the following can be used to learn more about TTPs used by cybercriminals?

Options:

A.

ZenMAP


B.

MITRE ATT&CK


C.

National Institute of Standards and Technology


D.

theHarvester


Expert Solution
Questions # 107:

A security analyst reviews the following Arachni scan results for a web application that stores PII data:

Question # 107

Which of the following should be remediated first?

Options:

A.

SQL injection


B.

RFI


C.

XSS


D.

Code injection


Expert Solution
Questions # 108:

The Chief Information Security Officer wants the same level of security to be present whether a remote worker logs in at home or at a coffee shop. Which of the following should be recommended as a starting point?

Options:

A.

Non-persistent virtual desktop infrastructures


B.

Passwordless authentication


C.

Standard-issue laptops


D.

Serverless workloads


Expert Solution
Questions # 109:

An analyst is reviewing a dashboard from the company’s SIEM and finds that an IP address known to be malicious can be tracked to numerous high-priority events in the last two hours. The dashboard indicates that these events relate to TTPs. Which of the following is the analyst most likely using?

Options:

A.

MITRE ATT&CK


B.

OSSTMM


C.

Diamond Model of Intrusion Analysis


D.

OWASP


Expert Solution
Questions # 110:

After a security assessment was done by a third-party consulting firm, the cybersecurity program recommended integrating DLP and CASB to reduce analyst alert fatigue. Which of the following is the best possible outcome that this effort hopes to achieve?

Options:

A.

SIEM ingestion logs are reduced by 20%.


B.

Phishing alerts drop by 20%.


C.

False positive rates drop to 20%.


D.

The MTTR decreases by 20%.


Expert Solution
Viewing page 11 out of 13 pages
Viewing questions 101-110 out of questions