Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the CompTIA CompTIA CySA+ CS0-003 Questions and answers with CertsForce

Viewing page 3 out of 15 pages
Viewing questions 21-30 out of questions
Questions # 21:

A DevOps analyst implements a webhook to trigger code vulnerability scanning for submissions to the repository. Which of the following is the primary benefit of this enhancement?

Options:

A.

To increase coverage by making the process occur automatically with uploads


B.

To create a single pane of glass dashboard for the vulnerability management process


C.

To include a threat feed component into the software development life cycle


D.

To employ data enrichment for new code commits to enhance project documentation


Expert Solution
Questions # 22:

A security analyst has found a moderate-risk item in an organization ' s point-of-sale application. The organization is currently in a change freeze window and has decided that the risk is not high enough to correct at this time. Which of the following inhibitors to remediation does this scenario illustrate?

Options:

A.

Service-level agreement


B.

Business process interruption


C.

Degrading functionality


D.

Proprietary system


Expert Solution
Questions # 23:

Which of the following tools provides logs that show user access to prohibited cloud storage, identifying whether a file was downloaded to a personal device?

Options:

A.

SASE


B.

CASB


C.

EDR


D.

SDN


Expert Solution
Questions # 24:

A vulnerability analyst received a list of system vulnerabilities and needs to evaluate the relevant impact of the exploits on the business. Given the constraints of the current sprint, only three can be remediated. Which of the following represents the least impactful risk, given the CVSS3.1 base scores?

Options:

A.

AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L - Base Score 6.0


B.

AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L - Base Score 7.2


C.

AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H - Base Score 6.4


D.

AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L - Base Score 6.5


Expert Solution
Questions # 25:

A security analyst is reviewing events that occurred during a possible compromise. The analyst obtains the following log:

Question # 25

Which of the following is most likely occurring, based on the events in the log?

Options:

A.

An adversary is attempting to find the shortest path of compromise.


B.

An adversary is performing a vulnerability scan.


C.

An adversary is escalating privileges.


D.

An adversary is performing a password stuffing attack..


Expert Solution
Questions # 26:

A security analyst needs to prioritize vulnerabilities for patching. Given the following vulnerability and system information:

Question # 26

Which of the following systems should the analyst patch first?

Options:

A.

System 1


B.

System 2


C.

System 3


D.

System 4


E.

System 5


F.

System 6


Expert Solution
Questions # 27:

Which of the following phases of the Cyber Kill Chain involves the adversary attempting to establish communication with a successfully exploited target?

Options:

A.

Command and control


B.

Actions on objectives


C.

Exploitation


D.

Delivery


Expert Solution
Questions # 28:

An IT professional is reviewing the output from the top command in Linux. In this company, only IT and security staff are allowed to have elevated privileges. Both departments have confirmed they are not working on anything that requires elevated privileges. Based on the output below:

PID

USER

VIRT

RES

SHR

%CPU

%MEM

TIME+

COMMAND

34834

person

4980644

224288

111076

5.3

14.44

1:41.44

cinnamon

34218

person

51052

30920

23828

4.7

0.2

0:26.54

Xorg

2264

root

449628

143500

26372

14.0

3.1

0:12.38

bash

35963

xrdp

711940

42356

10560

2.0

0.2

0:06.81

xrdp

Which of the following PIDs is most likely to contribute to data exfiltration?

Options:

A.

2264


B.

34218


C.

34834


D.

35963


Expert Solution
Questions # 29:

A security administrator has found indications of dictionary attacks against the company ' s external-facing portal. Which of the following should be implemented to best mitigate the password attacks?

Options:

A.

Multifactor authentication


B.

Password complexity


C.

Web application firewall


D.

Lockout policy


Expert Solution
Questions # 30:

A SIEM alert is triggered based on execution of a suspicious one-liner on two workstations in the organization ' s environment. An analyst views the details of these events below:

Question # 30

Which of the following statements best describes the intent of the attacker, based on this one-liner?

Options:

A.

Attacker is escalating privileges via JavaScript.


B.

Attacker is utilizing custom malware to download an additional script.


C.

Attacker is executing PowerShell script " AccessToken.psr.


D.

Attacker is attempting to install persistence mechanisms on the target machine.


Expert Solution
Viewing page 3 out of 15 pages
Viewing questions 21-30 out of questions