Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the CompTIA CompTIA CySA+ CS0-003 Questions and answers with CertsForce

Viewing page 7 out of 15 pages
Viewing questions 61-70 out of questions
Questions # 61:

An organization has established a formal change management process after experiencing several critical system failures over the past year. Which of the following are key factors that the change management process will include in order to reduce the impact of system failures? (Select two).

Options:

A.

Ensure users the document system recovery plan prior to deployment.


B.

Perform a full system-level backup following the change.


C.

Leverage an audit tool to identify changes that are being made.


D.

Identify assets with dependence that could be impacted by the change.


E.

Require diagrams to be completed for all critical systems.


F.

Ensure that all assets are properly listed in the inventory management system.


Expert Solution
Questions # 62:

A cybersecurity analyst is recommending a solution to ensure emails that contain links or attachments are tested before they reach a mail server. Which of the following will the analyst most likely recommend?

Options:

A.

Sandboxing


B.

MFA


C.

DKIM


D.

Vulnerability scan


Expert Solution
Questions # 63:

A security analyst receives the below information about the company ' s systems. They need to prioritize which systems should be given the resources to improve security.

Host

OS

Key Software

AV

Server 1

Windows Server 2008 R2

Microsoft IIS

Kaspersky

Server 2

Ubuntu Server 22.04 LTS

Apache 2.4.29

None

Computer 1

Windows 11 Professional

N/A

Windows Defender

Computer 2

Windows 10 Professional

N/A

Windows Defender

Which of the following systems should the analyst remediate first?

Options:

A.

Computer 1


B.

Server 1


C.

Computer 2


D.

Server 2


Expert Solution
Questions # 64:

Which of the following should be updated after a lessons-learned review?

Options:

A.

Disaster recovery plan


B.

Business continuity plan


C.

Tabletop exercise


D.

Incident response plan


Expert Solution
Questions # 65:

The DevSecOps team is remediating a Server-Side Request Forgery (SSRF) issue on the company ' s public-facing website. Which of the following is the best mitigation technique to address this issue?

Options:

A.

Place a Web Application Firewall (WAF) in front of the web server.


B.

Install a Cloud Access Security Broker (CASB) in front of the web server.


C.

Put a forward proxy in front of the web server.


D.

Implement MFA in front of the web server.


Expert Solution
Questions # 66:

An email hosting provider added a new data center with new public IP addresses. Which of the following most likely needs to be updated to ensure emails from the new data center do not get blocked by spam filters?

Options:

A.

DKIM


B.

SPF


C.

SMTP


D.

DMARC


Expert Solution
Questions # 67:

Which of the following concepts is using an API to insert bulk access requests from a file into an identity management system an example of?

Options:

A.

Command and control


B.

Data enrichment


C.

Automation


D.

Single sign-on


Expert Solution
Questions # 68:

An analyst receives an alert for suspicious IIS log activity and reviews the following entries:

2024-05-23 15:57:05 10.203.10.16 HEAT / - 80 - 10.203.10.17 DirBuster-1.0-RC1+(http://www.owasp.org/index.php/Category:OWASP_DirBuster_Project)

...

Which of the following will the analyst infer from the logs?

Options:

A.

An attacker is performing network lateral movement.


B.

An attacker is conducting reconnaissance of the website.


C.

An attacker is exfiltrating data from the network.


D.

An attacker is cloning the website.


Expert Solution
Questions # 69:

A security analyst needs to identify an asset that should be remediated based on the following information:

    File ServerCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H/

    Web ServerCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/

    Mail Server (corrected from “Mall server”)CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/

    Domain ControllerCVSS:3.1/AV:N/AC:L/PR:R/UI:R/S:U/C:H/I:H/A:H/

Which of the following assets should the analyst remediate first?

Options:

A.

Mail server


B.

Domain controller


C.

Web server


D.

File server


Expert Solution
Questions # 70:

An analyst is reviewing a vulnerability report for a server environment with the following entries:

Question # 70

Which of the following systems should be prioritized for patching first?

Options:

A.

10.101.27.98


B.

54.73.225.17


C.

54.74.110.26


D.

54.74.110.228


Expert Solution
Viewing page 7 out of 15 pages
Viewing questions 61-70 out of questions