Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the CompTIA CompTIA CySA+ CS0-003 Questions and answers with CertsForce

Viewing page 4 out of 15 pages
Viewing questions 31-40 out of questions
Questions # 31:

A security analyst has prepared a vulnerability scan that contains all of the company ' s functional subnets. During the initial scan, users reported that network printers began to print pages that contained unreadable text and icons.

Which of the following should the analyst do to ensure this behavior does not oocur during subsequent vulnerability scans?

Options:

A.

Perform non-credentialed scans.


B.

Ignore embedded web server ports.


C.

Create a tailored scan for the printer subnet.


D.

Increase the threshold length of the scan timeout.


Expert Solution
Questions # 32:

An employee downloads a freeware program to change the desktop to the classic look of legacy Windows. Shortly after the employee installs the program, a high volume of random DNS queries begin

to originate from the system. An investigation on the system reveals the following:

Add-MpPreference -ExclusionPath ' %Program Filest\ksysconfig '

Which of the following is possibly occurring?

Options:

A.

Persistence


B.

Privilege escalation


C.

Credential harvesting


D.

Defense evasion


Expert Solution
Questions # 33:

A security analyst performs forensic analysis of a user’s computer. The analyst immediately orders the user to leave the computer powered on and not interact with it until further notice. Which of the following best describes the reason for the analyst’s orders?

Options:

A.

To prevent loss of sensitive data due to misuse


B.

To preserve artifacts related to the incident


C.

To validate that the security tools are installed and up to date


D.

To ensure there is a legal hold on the computer


Expert Solution
Questions # 34:

Which of the following best describes the importance of implementing TAXII as part of a threat intelligence program?

Options:

A.

It provides a structured way to gain information about insider threats.


B.

It proactively facilitates real-time information sharing between the public and private sectors.


C.

It exchanges messages in the most cost-effective way and requires little maintenance once implemented.


D.

It is a semi-automated solution to gather threat intellbgence about competitors in the same sector.


Expert Solution
Questions # 35:

An attacker has just gained access to the syslog server on a LAN. Reviewing the syslog entries has allowed the attacker to prioritize possible next targets. Which of the following is this an example of?

Options:

A.

Passive network foot printing


B.

OS fingerprinting


C.

Service port identification


D.

Application versioning


Expert Solution
Questions # 36:

An organization ' s website was maliciously altered.

INSTRUCTIONS

Review information in each tab to select the source IP the analyst should be concerned

about, the indicator of compromise, and the two appropriate corrective actions.

Question # 36

Question # 36

Question # 36

Question # 36


Expert Solution
Questions # 37:

While performing a dynamic analysis of a malicious file, a security analyst notices the memory address changes every time the process runs. Which of the following controls is most likely preventing the analyst from finding the proper memory address of the piece of malicious code?

Options:

A.

Address space layout randomization


B.

Data execution prevention


C.

Stack canary


D.

Code obfuscation


Expert Solution
Questions # 38:

A security analyst is performing vulnerability scans on the network. The analyst installs a scanner appliance, configures the subnets to scan, and begins the scan of the network. Which of the following

would be missing from a scan performed with this configuration?

Options:

A.

Operating system version


B.

Registry key values


C.

Open ports


D.

IP address


Expert Solution
Questions # 39:

Which of the following is the best metric for an organization to focus on given recent investments in SIEM, SOAR, and a ticketing system?

Options:

A.

Mean time to detect


B.

Number of exploits by tactic


C.

Alert volume


D.

Quantity of intrusion attempts


Expert Solution
Questions # 40:

An analyst reviews a recent government alert on new zero-day threats and finds the following CVE metrics for the most critical of the vulnerabilities:

CVSS: 3.1/AV:N/AC: L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:W/RC:R

Which of the following represents the exploit code maturity of this critical vulnerability?

Options:

A.

E:U


B.

S:C


C.

RC:R


D.

AV:N


E.

AC:L


Expert Solution
Viewing page 4 out of 15 pages
Viewing questions 31-40 out of questions