Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the CompTIA CompTIA CySA+ CS0-003 Questions and answers with CertsForce

Viewing page 2 out of 15 pages
Viewing questions 11-20 out of questions
Questions # 11:

After an incident, a security analyst needs to perform a forensic analysis to report complete information to a company stakeholder. Which of the following is most likely the goal of the forensic analysis in this case?

Options:

A.

Provide a full picture of the existing risks.


B.

Notify law enforcement of the incident.


C.

Further contain the incident.


D.

Determine root cause information.


Expert Solution
Questions # 12:

Which of the following is a commonly used four-component framework to communicate threat actor behavior?

Options:

A.

STRIDE


B.

Diamond Model of Intrusion Analysis


C.

Cyber Kill Chain


D.

MITRE ATT & CK


Expert Solution
Questions # 13:

A security analyst has found a moderate-risk item in an organization ' s point-of-sale application. The organization is currently in a change freeze window and has decided that the risk is not high enough to correct at this time. Which of the following inhibitors to remediation does this scenario illustrate?

Options:

A.

Service-level agreement


B.

Business process interruption


C.

Degrading functionality


D.

Proprietary system


Expert Solution
Questions # 14:

A threat intelligence analyst is updating a document according to the MITRE ATT & CK framework. The analyst detects the following behavior from a malicious actor: “The malicious actor will attempt to achieve unauthorized access to the vulnerable system.” In which of the following phases should the analyst include the detection?

Options:

A.

Procedures


B.

Techniques


C.

Tactics


D.

Subtechniques


Expert Solution
Questions # 15:

An organization wants to establish a disaster recovery plan for critical applications that are hosted on premises. Which of the following is the first step to prepare for supporting this new requirement?

Options:

A.

Choose a vendor to utilize for the disaster recovery location.


B.

Establish prioritization of continuity from data and business owners.


C.

Negotiate vendor agreements to support disaster recovery capabilities.


D.

Advise the leadership team that a geographical area for recovery must be defined.


Expert Solution
Questions # 16:

Several vulnerability scan reports have indicated runtime errors as the code is executing. The dashboard that lists the errors has a command-line interface for developers to check for vulnerabilities. Which of the following will enable a developer to correct this issue? (Select two).

Options:

A.

Performing dynamic application security testing


B.

Reviewing the code


C.

Fuzzing the application


D.

Debugging the code


E.

Implementing a coding standard


F.

Implementing IDS


Expert Solution
Questions # 17:

Which of the following best describes the reporting metric that should be utilized when measuring the degree to which a system, application, or user base is affected by an uptime availability outage?

Options:

A.

Timeline


B.

Evidence


C.

Impact


D.

Scope


Expert Solution
Questions # 18:

A vulnerability manager analyzes suspicious data after scanning a database. Which of the following should the manager do to prioritize the remediation tasks?

Options:

A.

Conduct further analysis and send the findings report to the incident response team.


B.

Perform an assessment in the command line and determine if there are true or false positives.


C.

Identify the impact level and create a ticket that includes the time frame for fixing the issue.


D.

Apply compensating controls and advise an analyst to document the problem in a risk register.


Expert Solution
Questions # 19:

A security analyst is reviewing the findings of the latest vulnerability report for a company ' s web application. The web application accepts files for a Bash script to be processed if the files match a given hash. The analyst is able to submit files to the system due to a hash collision. Which of the following should the analyst suggest to mitigate the vulnerability with the fewest changes to the current script and infrastructure?

Options:

A.

Deploy a WAF to the front of the application.


B.

Replace the current MD5 with SHA-256.


C.

Deploy an antivirus application on the hosting system.


D.

Replace the MD5 with digital signatures.


Expert Solution
Questions # 20:

An analyst is evaluating a vulnerability management dashboard. The analyst sees that a previously remediated vulnerability has reappeared on a database server. Which of the following is the most likely cause?

Options:

A.

The finding is a false positive and should be ignored.


B.

A rollback had been executed on the instance.


C.

The vulnerability scanner was configured without credentials.


D.

The vulnerability management software needs to be updated.


Expert Solution
Viewing page 2 out of 15 pages
Viewing questions 11-20 out of questions