Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the CompTIA CompTIA CySA+ CS0-003 Questions and answers with CertsForce

Viewing page 8 out of 15 pages
Viewing questions 71-80 out of questions
Questions # 71:

A security analyst receives the below information about the company ' s systems. They need to prioritize which systems should be given the resources to improve security.

Host

OS

Key Software

AV

Server 1

Windows Server 2008 R2

Microsoft IIS

Kaspersky

Server 2

Ubuntu Server 22.04 LTS

Apache 2.4.29

None

Computer 1

Windows 11 Professional

N/A

Windows Defender

Computer 2

Windows 10 Professional

N/A

Windows Defender

Which of the following systems should the analyst remediate first?

Options:

A.

Computer 1


B.

Server 1


C.

Computer 2


D.

Server 2


Expert Solution
Questions # 72:

A security analyst performs a vulnerability scan on the corporate assets and finds the following vulnerabilities:

System | Vulnerability | CVSS Severity Score

System A | Buffer overflow | 9.5

System B | Remote code execution | 9.8

System C | DDoS | 8.2

System D | XSS | 8.6

The vulnerability manager reviews the analyst’s recommendations and asks the analyst to add more information in order to confirm prioritization. Which of the following best explains the reason the manager requests more information?

Options:

A.

Host criticality is unknown.


B.

SLA information is missing.


C.

Existing KPIs were not measured.


D.

Zero-day vulnerabilities were excluded.


Expert Solution
Questions # 73:

Which of the following concepts is using an API to insert bulk access requests from a file into an identity management system an example of?

Options:

A.

Command and control


B.

Data enrichment


C.

Automation


D.

Single sign-on


Expert Solution
Questions # 74:

To minimize the impact of a security incident in a heavily regulated company, a cybersecurity analyst has configured audit settings in the organization ' s cloud services. Which of the following security controls has the analyst configured?

Options:

A.

Preventive


B.

Corrective


C.

Directive


D.

Detective


Expert Solution
Questions # 75:

The security operations team is required to consolidate several threat intelligence feeds due to redundant tools and portals. Which of the following will best achieve the goal and maximize results?

Options:

A.

Single pane of glass


B.

Single sign-on


C.

Data enrichment


D.

Deduplication


Expert Solution
Questions # 76:

A security operations center analyst is using the command line to display specific traffic. The analyst uses the following command:

tshark -r file.pcap -Y " http or udp "

Which of the following will the command line display?

Options:

A.

Encrypted web requests and Domain Name System (DNS) traffic


B.

Unencrypted web requests and DNS traffic


C.

Neither encrypted nor unencrypted web and DNS traffic


D.

Both encrypted and unencrypted web and DNS traffic


Expert Solution
Questions # 77:

When undertaking a cloud migration of multiple SaaS application, an organizations system administrator struggled … identity and access management to cloud-based assets. Which of the following service models would have reduced the complexity of this project?

Options:

A.

CASB


B.

SASE


C.

ZTNA


D.

SWG


Expert Solution
Questions # 78:

Which of the following will most likely ensure that mission-critical services are available in the event of an incident?

Options:

A.

Business continuity plan


B.

Vulnerability management plan


C.

Disaster recovery plan


D.

Asset management plan


Expert Solution
Questions # 79:

A regulated organization experienced a security breach that exposed a list of customer names with corresponding PH data. Which of the following is the best reason for developing the organization ' s communication plans?

Options:

A.

For the organization ' s public relations department to have a standard notification


B.

To ensure incidents are immediately reported to a regulatory agency


C.

To automate the notification to customers who were impacted by the breach


D.

To have approval from executive leadership on when communication should occur


Expert Solution
Questions # 80:

Which of the following best describes the threat concept in which an organization works to ensure that all network users only open attachments from known sources?

Options:

A.

Hacktivist threat


B.

Advanced persistent threat


C.

Unintentional insider threat


D.

Nation-state threat


Expert Solution
Viewing page 8 out of 15 pages
Viewing questions 71-80 out of questions