Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the CompTIA CompTIA CySA+ CS0-003 Questions and answers with CertsForce

Viewing page 2 out of 15 pages
Viewing questions 11-20 out of questions
Questions # 11:

During security scanning, a security analyst regularly finds the same vulnerabilities in a critical application. Which of the following recommendations would best mitigate this problem if applied along the SDLC phase?

Options:

A.

Conduct regular red team exercises over the application in production


B.

Ensure that all implemented coding libraries are regularly checked


C.

Use application security scanning as part of the pipeline for the CI/CDflow


D.

Implement proper input validation for any data entry form


Expert Solution
Questions # 12:

After conducting a cybersecurity risk assessment for a new software request, a Chief Information Security Officer (CISO) decided the risk score would be too high. The CISO refused the software request. Which of the following risk management principles did the CISO select?

Options:

A.

Avoid


B.

Transfer


C.

Accept


D.

Mitigate


Expert Solution
Questions # 13:

Which of the following describes the importance of an organization understanding SLOs when outsourcing incident response to a third party?

Options:

A.

To track the performance of specific KPIs


B.

To understand the hidden costs of an SLA


C.

To ensure that an objective risk score can be calculated


D.

To quantify the risk appetite in an MOU


Expert Solution
Questions # 14:

A recent penetration test discovered that several employees were enticed to assist attackers by visiting specific websites and running downloaded files when prompted by phone calls. Which of the following would best address this issue?

Options:

A.

Increasing training and awareness for all staff


B.

Ensuring that malicious websites cannot be visited


C.

Blocking all scripts downloaded from the internet


D.

Disabling all staff members ' ability to run downloaded applications


Expert Solution
Questions # 15:

A security analyst needs to develop a solution to protect a high-value asset from an exploit like a recent zero-day attack. Which of the following best describes this risk management strategy?

Options:

A.

Avoid


B.

Transfer


C.

Accept


D.

Mitigate


Expert Solution
Questions # 16:

An incident response team is working with law enforcement to investigate an active web server compromise. The decision has been made to keep the server running and to implement compensating controls for a period of time. The web service must be accessible from the internet via the reverse proxy and must connect to a database server. Which of the following compensating controls will help contain the adversary while meeting the other requirements? (Select two).

Options:

A.

Drop the tables on the database server to prevent data exfiltration.


B.

Deploy EDR on the web server and the database server to reduce the adversaries capabilities.


C.

Stop the httpd service on the web server so that the adversary can not use web exploits


D.

use micro segmentation to restrict connectivity to/from the web and database servers.


E.

Comment out the HTTP account in the / etc/passwd file of the web server


F.

Move the database from the database server to the web server.


Expert Solution
Questions # 17:

A company ' s internet-facing web application has been compromised several times due to identified design flaws. The company would like to minimize the risk of these incidents from reoccurring and has provided the developers with better security training. However, the company cannot allocate any more internal resources to the issue. Which of the following are the best options to help identify flaws within the system? (Select two).

Options:

A.

Deploying a WAF


B.

Performing a forensic analysis


C.

Contracting a penetration test


D.

Holding a tabletop exercise


E.

Creating a bug bounty program


F.

Implementing threat modeling


Expert Solution
Questions # 18:

After reviewing the final report for a penetration test, a cybersecurity analyst prioritizes the remediation for input validation vulnerabilities. Which of the following attacks is the analyst seeking to prevent?

Options:

A.

DNS poisoning


B.

Pharming


C.

Phishing


D.

Cross-site scripting


Expert Solution
Questions # 19:

Joe, a leading sales person at an organization, has announced on social media that he is leaving his current role to start a new company that will compete with his current employer. Joe is soliciting his current employer ' s customers. However, Joe has not resigned or discussed this with his current supervisor yet. Which of the following would be the best action for the incident response team to recommend?

Options:

A.

Isolate Joe ' s PC from the network


B.

Reimage the PC based on standard operating procedures


C.

Initiate a remote wipe of Joe ' s PC using mobile device management


D.

Perform no action until HR or legal counsel advises on next steps


Expert Solution
Questions # 20:

Which of the following best explains the importance of the implementation of a secure software development life cycle in a company with an internal development team?

Options:

A.

Increases the product price by using the implementation as a piece of marketing


B.

Decreases the risks of the software usage and complies with regulatory requirements


C.

Improves the agile process and decreases the amount of tests before the final deployment


D.

Transfers the responsibility for security flaws to the vulnerability management team


Expert Solution
Viewing page 2 out of 15 pages
Viewing questions 11-20 out of questions