Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the CompTIA CompTIA CySA+ CS0-003 Questions and answers with CertsForce

Viewing page 7 out of 15 pages
Viewing questions 61-70 out of questions
Questions # 61:

A security manager is looking at a third-party vulnerability metric (SMITTEN) to improve upon the company ' s current method that relies on CVSSv3. Given the following:

Question # 61

Which of the following vulnerabilities should be prioritized?

Options:

A.

Vulnerability 1


B.

Vulnerability 2


C.

Vulnerability 3


D.

Vulnerability 4


Expert Solution
Questions # 62:

A security analyst must preserve a system hard drive that was involved in a litigation request Which of the following is the best method to ensure the data on the device is not modified?

Options:

A.

Generate a hash value and make a backup image.


B.

Encrypt the device to ensure confidentiality of the data.


C.

Protect the device with a complex password.


D.

Perform a memory scan dump to collect residual data.


Expert Solution
Questions # 63:

A security analyst received a malicious binary file to analyze. Which of the following is the best technique to perform the analysis?

Options:

A.

Code analysis


B.

Static analysis


C.

Reverse engineering


D.

Fuzzing


Expert Solution
Questions # 64:

After a risk assessment, a server was found hosting a vulnerable legacy system that has the following characteristics:

• There is no patch or official fix available from the vendor.

• There is no official support provided by the vendor.

• Customers consider the system mission critical.

Which of the following actions will best decrease the risk posed by the legacy system?

Options:

A.

Decommission the server immediately and find a new solution to replace the legacy system.


B.

Implement firewall rules to block inbound connections and allow outbound traffic.


C.

Install and configure a web application firewall tailored to the legacy server.


D.

Apply compensating controls, including isolation, restricted access, and continuous monitoring.


Expert Solution
Questions # 65:

The Chief Information Security Officer wants to eliminate and reduce shadow IT in the enterprise. Several high-risk cloud applications are used that increase the risk to the organization. Which of the following solutions will assist in reducing the risk?

Options:

A.

Deploy a CASB and enable policy enforcement


B.

Configure MFA with strict access


C.

Deploy an API gateway


D.

Enable SSO to the cloud applications


Expert Solution
Questions # 66:

A security analyst has identified outgoing network traffic leaving the enterprise at odd times. The traffic appears to pivot across network segments and target domain servers. The traffic is then routed to a geographic location to which the company has no association. Which of the following best describes this type of threat?

Options:

A.

Hacktivist


B.

Zombie


C.

Insider threat


D.

Nation-state actor


Expert Solution
Questions # 67:

An organization receives a legal hold request from an attorney. The request pertains to emails related to a disputed vendor contract. Which of the following is the first step for the security team to take to ensure compliance with the request?

Options:

A.

Publicly disclose the request to other vendors.


B.

Notify the departments involved to preserve potentially relevant information.


C.

Establish a chain of custody, starting with the attorney ' s request.


D.

Back up the mailboxes on the server and provide the attorney with a copy.


Expert Solution
Questions # 68:

Which of the following is described as a method of enforcing a security policy between cloud customers and cloud services?

Options:

A.

CASB


B.

DMARC


C.

SIEM


D.

PAM


Expert Solution
Questions # 69:

Which of the following can be used to learn more about TTPs used by cybercriminals?

Options:

A.

ZenMAP


B.

MITRE ATT & CK


C.

National Institute of Standards and Technology


D.

theHarvester


Expert Solution
Questions # 70:

A security analyst needs to identify the devices in a critical infrastructure network that handles an oil and gas pipeline. The network has devices connected over IPv4 using either HTTP or Modbus protocols running on the standard ports. Which of the following approaches should the analyst use to achieve the objective?

Options:

A.

Employ the IT vulnerability scanner to target ports 80 and 502.


B.

Use banner grabbing with Netcat on TCP ports 80 and 502.


C.

Perform an Nmap -sS -A -p 80,502 scan.


D.

Scan the ICS network using Masscan --open-only -p80,502.


Expert Solution
Viewing page 7 out of 15 pages
Viewing questions 61-70 out of questions