Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the CompTIA CompTIA CySA+ CS0-003 Questions and answers with CertsForce

Viewing page 3 out of 15 pages
Viewing questions 21-30 out of questions
Questions # 21:

A security analyst has just received an incident ticket regarding a ransomware attack. Which of the following would most likely help an analyst properly triage the ticket?

Options:

A.

Incident response plan


B.

Lessons learned


C.

Playbook


D.

Tabletop exercise


Expert Solution
Questions # 22:

An incident response analyst is investigating the root cause of a recent malware outbreak. Initial binary analysis indicates that this malware disables host security services and performs cleanup routines on it infected hosts, including deletion of initial dropper and removal of event log entries and prefetch files from the host. Which of the following data sources would most likely reveal evidence of the root cause?

(Select two).

Options:

A.

Creation time of dropper


B.

Registry artifacts


C.

EDR data


D.

Prefetch files


E.

File system metadata


F.

Sysmon event log


Expert Solution
Questions # 23:

During a routine review of DNS logs, a security analyst observes that Host X has been making frequent DNS requests to domains with random alphanumeric strings, such as ajd8ekthj.xyz. IPS anomaly rules are blocking these domains. This behavior started shortly after a new software installation on the host. Which of the following should the analyst do first to determine whether Host X has been compromised?

Options:

A.

Allow the domains because the DNS requests are part of a misconfigured software update.


B.

Check the software installation logs for errors and reinstall the software.


C.

Block all outbound connections from the host to prevent further DNS queries.


D.

Use threat intelligence to check if the queried domains are associated with legitimate sites.


Expert Solution
Questions # 24:

A user is flagged for consistently consuming a high volume of network bandwidth over the past week. During the investigation, the security analyst finds traffic to the following websites:

Date/Time

URL

Destination Port

Bytes In

Bytes Out

12/24/2023 14:00:25

youtube.com

80

450000

4587

12/25/2023 14:09:30

translate.google.com

80

2985

3104

12/25/2023 14:10:00

tiktok.com

443

675000

105

12/25/2023 16:00:45

netflix.com

443

525900

295

12/26/2023 16:30:45

grnail.com

443

1250

525984

12/31/2023 17:30:25

office.com

443

350000

450

12/31/2023 17:35:00

youtube.com

443

300

350000

Which of the following data flows should the analyst investigate first?

Options:

A.

netflix.com


B.

youtube.com


C.

tiktok.com


D.

grnail.com


E.

translate.google.com


F.

office.com


Expert Solution
Questions # 25:

A Chief Information Security Officer (CISO) has determined through lessons learned and an associated after-action report that staff members who use legacy applications do not adequately understand how to differentiate between non-malicious emails and phishing emails. Which of the following should the CISO include in an action plan to remediate this issue?

Options:

A.

Awareness training and education


B.

Replacement of legacy applications


C.

Organizational governance


D.

Multifactor authentication on all systems


Expert Solution
Questions # 26:

A security analyst is tasked with prioritizing vulnerabilities for remediation. The relevant company security policies are shown below:

Security Policy 1006: Vulnerability Management

1. The Company shall use the CVSSv3.1 Base Score Metrics (Exploitability and Impact) to prioritize the remediation of security vulnerabilities.

2. In situations where a choice must be made between confidentiality and availability, the Company shall prioritize confidentiality of data over availability of systems and data.

3. The Company shall prioritize patching of publicly available systems and services over patching of internally available system.

According to the security policy, which of the following vulnerabilities should be the highest priority to patch?

A)

Question # 26

B)

Question # 26

C)

Question # 26

D)

Question # 26

Options:

A.

Option A


B.

Option B


C.

Option C


D.

Option D


Expert Solution
Questions # 27:

Which of the following is the appropriate phase in the incident response process to perform a vulnerability scan to determine the effectiveness of corrective actions?

Options:

A.

Lessons learned


B.

Reporting


C.

Recovery


D.

Root cause analysis


Expert Solution
Questions # 28:

While reviewing web server logs, a security analyst discovers the following suspicious line:

Question # 28

Which of the following is being attempted?

Options:

A.

Remote file inclusion


B.

Command injection


C.

Server-side request forgery


D.

Reverse shell


Expert Solution
Questions # 29:

The analyst reviews the following endpoint log entry:

Question # 29

Which of the following has occurred?

Options:

A.

Registry change


B.

Rename computer


C.

New account introduced


D.

Privilege escalation


Expert Solution
Questions # 30:

An analyst is reviewing processes running on a Windows host. The analyst reviews the following information:

Question # 30

Which of the following processes should the analyst review first?

Options:

A.

533


B.

740


C.

768


D.

1100


Expert Solution
Viewing page 3 out of 15 pages
Viewing questions 21-30 out of questions