Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the CompTIA CompTIA CySA+ CS0-003 Questions and answers with CertsForce

Viewing page 4 out of 15 pages
Viewing questions 31-40 out of questions
Questions # 31:

An analyst is investigating a phishing incident and has retrieved the following as part of the investigation:

cmd.exe /c c:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -EncodedCommand < VERY LONG STRING >

Which of the following should the analyst use to gather more information about the purpose of this command?

Options:

A.

Echo the command payload content into ' base64 -d ' .


B.

Execute the command from a Windows VM.


C.

Use a command console with administrator privileges to execute the code.


D.

Run the command as an unprivileged user from the analyst workstation.


Expert Solution
Questions # 32:

You are a cybersecurity analyst tasked with interpreting scan data from Company As servers You must verify the requirements are being met for all of the servers and recommend changes if you find they are not

The company ' s hardening guidelines indicate the following

• TLS 1 2 is the only version of TLS

running.

• Apache 2.4.18 or greater should be used.

• Only default ports should be used.

INSTRUCTIONS

using the supplied data. record the status of compliance With the company’s guidelines for each server.

The question contains two parts: make sure you complete Part 1 and Part 2. Make recommendations for Issues based ONLY on the hardening guidelines provided.

Part 1:

AppServ1:

Question # 32

AppServ2:

Question # 32

AppServ3:

Question # 32

AppServ4:

Question # 32

Question # 32

Part 2:

Question # 32

Question # 32


Expert Solution
Questions # 33:

A company has a primary control in place to restrict access to a sensitive database. However, the company discovered an authentication vulnerability that could bypass this control. Which of the following is the best compensating control?

Options:

A.

Running regular penetration tests to identify and address new vulnerabilities


B.

Conducting regular security awareness training of employees to prevent social engineering attacks


C.

Deploying an additional layer of access controls to verify authorized individuals


D.

Implementing intrusion detection software to alert security teams of unauthorized access attempts


Expert Solution
Questions # 34:

A security analyst discovers an ongoing ransomware attack while investigating a phishing email. The analyst downloads a copy of the file from the email and isolates the affected workstation from the network. Which of the following activities should the analyst perform next?

Options:

A.

Wipe the computer and reinstall software


B.

Shut down the email server and quarantine it from the network.


C.

Acquire a bit-level image of the affected workstation.


D.

Search for other mail users who have received the same file.


Expert Solution
Questions # 35:

Which of the following is the best reason to implement an MOU?

Options:

A.

To create a business process for configuration management


B.

To allow internal departments to understand security responsibilities


C.

To allow an expectation process to be defined for legacy systems


D.

To ensure that all metrics on service levels are properly reported


Expert Solution
Questions # 36:

A systems administrator receives several reports about emails containing phishing links. The hosting domain is always different, but the URL follows a specific pattern of characters. Which of the following is the best way for the administrator to find more messages that were not reported?

Options:

A.

Search email logs for a regular expression


B.

Open a support ticket with the email hosting provider


C.

Send a memo to all staff asking them to report suspicious emails


D.

Query firewall logs for any traffic with a suspicious website


Expert Solution
Questions # 37:

Which of the following best describes the document that defines the expectation to network customers that patching will only occur between 2:00 a.m. and 4:00 a.m.?

Options:

A.

SLA


B.

LOI


C.

MOU


D.

KPI


Expert Solution
Questions # 38:

Which of the following best explains the importance of utilizing an incident response playbook?

Options:

A.

It prioritizes the business-critical assets for data recovery.


B.

It establishes actions to execute when inputs trigger an event.


C.

It documents the organization asset management and configuration.


D.

It defines how many disaster recovery sites should be staged.


Expert Solution
Questions # 39:

A Chief Information Security Officer (CISO) is concerned that a specific threat actor who is known to target the company ' s business type may be able to breach the network and remain inside of it for an extended period of time.

Which of the following techniques should be performed to meet the CISO ' s goals?

Options:

A.

Vulnerability scanning


B.

Adversary emulation


C.

Passive discovery


D.

Bug bounty


Expert Solution
Questions # 40:

A development team is preparing to roll out a beta version of a web application and wants to quickly test for vulnerabilities, including SQL injection, path traversal, and cross-site scripting. Which of the following tools would the security team most likely recommend to perform this test?

Options:

A.

Has heat


B.

OpenVAS


C.

OWASP ZAP


D.

Nmap


Expert Solution
Viewing page 4 out of 15 pages
Viewing questions 31-40 out of questions