Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the CompTIA CompTIA CySA+ CS0-003 Questions and answers with CertsForce

Viewing page 6 out of 15 pages
Viewing questions 51-60 out of questions
Questions # 51:

An analyst is designing a message system for a bank. The analyst wants to include a feature that allows the recipient of a message to prove to a third party that the message came from the sender Which of the following information security goals is the analyst most likely trying to achieve?

Options:

A.

Non-repudiation


B.

Authentication


C.

Authorization


D.

Integrity


Expert Solution
Questions # 52:

Two employees in the finance department installed a freeware application that contained embedded malware. The network is robustly segmented based on areas of responsibility. These computers had critical sensitive information stored locally that needs to be recovered. The department manager advised all department employees to turn off their computers until the security team could be contacted about the issue. Which of the following is the first step the incident response staff members should take when they arrive?

Options:

A.

Turn on all systems, scan for infection, and back up data to a USB storage device.


B.

Identify and remove the software installed on the impacted systems in the department.


C.

Explain that malware cannot truly be removed and then reimage the devices.


D.

Log on to the impacted systems with an administrator account that has privileges to perform backups.


E.

Segment the entire department from the network and review each computer offline.


Expert Solution
Questions # 53:

An analyst reviews the following list of vulnerabilities:

CVE ID | CVSS | Weaponized | Count | Location

CVE-2024-9837 | 9.2 | Yes | 58 | Internal

CVE-2024-9964 | 9.0 | Yes | 24 | Internal

CVE-2023-8524 | 9.1 | Yes | 55 | External

CVE-2024-1587 | 8.7 | Yes | 55 | Internal

The analyst determines that CVE-2023-8524 is the highest priority for remediation and should be patched immediately. Which of the following did the analyst use to determine the priority of remediation efforts?

Options:

A.

Context awareness


B.

Criticality


C.

Exploit availability


D.

Recurrence


Expert Solution
Questions # 54:

A vulnerability management team found four major vulnerabilities during an assessment and needs to provide a report for the proper prioritization for further mitigation. Which of the following vulnerabilities should have the highest priority for the mitigation process?

Options:

A.

A vulnerability that has related threats and loCs, targeting a different industry


B.

A vulnerability that is related to a specific adversary campaign, with loCs found in the SIEM


C.

A vulnerability that has no adversaries using it or associated loCs


D.

A vulnerability that is related to an isolated system, with no loCs


Expert Solution
Questions # 55:

A Chief Information Security Officer (CISO) is concerned that a specific threat actor who is known to target the company ' s business type may be able to breach the network and remain inside of it for an extended period of time.

Which of the following techniques should be performed to meet the CISO ' s goals?

Options:

A.

Vulnerability scanning


B.

Adversary emulation


C.

Passive discovery


D.

Bug bounty


Expert Solution
Questions # 56:

A recent penetration test discovered that several employees were enticed to assist attackers by visiting specific websites and running downloaded files when prompted by phone calls. Which of the following would best address this issue?

Options:

A.

Increasing training and awareness for all staff


B.

Ensuring that malicious websites cannot be visited


C.

Blocking all scripts downloaded from the internet


D.

Disabling all staff members ' ability to run downloaded applications


Expert Solution
Questions # 57:

A security alert was triggered when an end user tried to access a website that is not allowed per organizational policy. Since the action is considered a terminable offense, the SOC analyst collects the authentication logs, web logs, and temporary files, reflecting the web searches from the user ' s workstation, to build the case for the investigation. Which of the following is the best way to ensure that the investigation complies with HR or privacy policies?

Options:

A.

Create a timeline of events detailinq the date stamps, user account hostname and IP information associated with the activities


B.

Ensure that the case details do not reflect any user-identifiable information Password protect the evidence and restrict access to personnel related to the investigation


C.

Create a code name for the investigation in the ticketing system so that all personnel with access will not be able to easily identity the case as an HR-related investigation


D.

Notify the SOC manager for awareness after confirmation that the activity was intentional


Expert Solution
Questions # 58:

While reviewing the web server logs a security analyst notices the following snippet

..\../..\../boot.ini

Which of the following is being attempted?

Options:

A.

Directory traversal


B.

Remote file inclusion


C.

Cross-site scripting


D.

Remote code execution


E.

Enumeration of/etc/pasawd


Expert Solution
Questions # 59:

A company was able to reduce triage time by focusing on historical trend analysis. The business partnered with the security team to achieve a 50% reduction in phishing attempts year over year. Which of the following action plans led to this reduced triage time?

Options:

A.

Patching


B.

Configuration management


C.

Awareness, education, and training


D.

Threat modeling


Expert Solution
Questions # 60:

A web application has a function to retrieve content from an internal URL to identify CSRF attacks in the logs. The security analyst is building a regular expression that will filter out the correctly formatted requests. The target URL is https://10.1.2.3/api, and the receiving API only accepts GET requests and uses a single integer argument named " id. " Which of the following regular expressions should the analyst use to achieve the objective?

Options:

A.

(?!https://10\.1\.2\.3/api\?id=[0-9]+)


B.

" https://10\.1\.2\.3/api\?id=\d+


C.

(?: " https://10\.1\.2\.3/api\?id-[0-9]+)


D.

https://10\.1\.2\.3/api\?id«[0-9J$


Expert Solution
Viewing page 6 out of 15 pages
Viewing questions 51-60 out of questions