Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the CompTIA CompTIA CySA+ CS0-003 Questions and answers with CertsForce

Viewing page 8 out of 15 pages
Viewing questions 71-80 out of questions
Questions # 71:

A security analyst must preserve a system hard drive that was involved in a litigation request Which of the following is the best method to ensure the data on the device is not modified?

Options:

A.

Generate a hash value and make a backup image.


B.

Encrypt the device to ensure confidentiality of the data.


C.

Protect the device with a complex password.


D.

Perform a memory scan dump to collect residual data.


Expert Solution
Questions # 72:

An organization has noticed large amounts of data are being sent out of its network. An

analyst is identifying the cause of the data exfiltration.

INSTRUCTIONS

Select the command that generated the output in tabs 1 and 2.

Review the output text in all tabs and identify the file responsible for the malicious

behavior.

If at any time you would like to bring back the initial state of the simulation, please click

the Reset All button.

Question # 72

Question # 72

Question # 72

Question # 72

Question # 72

Question # 72

Question # 72


Expert Solution
Questions # 73:

Which of the following techniques can help a SOC team to reduce the number of alerts related to the internal security activities that the analysts have to triage?

Options:

A.

Enrich the SIEM-ingested data to include all data required for triage.


B.

Schedule a task to disable alerting when vulnerability scans are executing.


C.

Filter all alarms in the SIEM with low severity.


D.

Add a SOAR rule to drop irrelevant and duplicated notifications.


Expert Solution
Questions # 74:

The architecture team has been given a mandate to reduce the triage time of phishing incidents by 20%. Which of the following solutions will most likely help with this effort?

Options:

A.

Integrate a SOAR platform.


B.

Increase the budget to the security awareness program.


C.

Implement an EDR tool.


D.

Install a button in the mail clients to report phishing.


Expert Solution
Questions # 75:

A security analyst is conducting a vulnerability assessment of a company ' s online store. The analyst discovers a critical vulnerability in the payment processing system that could be exploited, allowing attackers to steal customer payment information. Which of the following should the analyst do next?

Options:

A.

Leave the vulnerability unpatched until the next scheduled maintenance window to avoid potential disruption to business.


B.

Perform a risk assessment to evaluate the potential impact of the vulnerability and determine whether additional security measures are needed.


C.

Ignore the vulnerability since the company recently passed a payment system compliance audit.


D.

Isolate the payment processing system from production and schedule for reimaging.


Expert Solution
Questions # 76:

Which of the following actions would an analyst most likely perform after an incident has been investigated?

Options:

A.

Risk assessment


B.

Root cause analysis


C.

Incident response plan


D.

Tabletop exercise


Expert Solution
Questions # 77:

Which of the following explains how MTTD can affect incident response reporting and communication?

Options:

A.

Having a shorter MTTD reduces the potential impact of an incident.


B.

Improved MTTD ensures the leadership team is made aware of threats before exploitation.


C.

MTTD defines the maximum time allowed between detection and response.


D.

MTTD is part of regulatory compliance and outlines an approved process for reporting.


Expert Solution
Questions # 78:

Which of the following would help to minimize human engagement and aid in process improvement in security operations?

Options:

A.

OSSTMM


B.

SIEM


C.

SOAR


D.

QVVASP


Expert Solution
Questions # 79:

Which of the following would eliminate the need for different passwords for a variety or internal application?

Options:

A.

CASB


B.

SSO


C.

PAM


D.

MFA


Expert Solution
Questions # 80:

After identifying a threat, a company has decided to implement a patch management program to remediate vulnerabilities. Which of the following risk management principles is the company exercising?

Options:

A.

Transfer


B.

Accept


C.

Mitigate


D.

Avoid


Expert Solution
Viewing page 8 out of 15 pages
Viewing questions 71-80 out of questions