Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the CompTIA CompTIA CySA+ CS0-003 Questions and answers with CertsForce

Viewing page 9 out of 15 pages
Viewing questions 81-90 out of questions
Questions # 81:

An analyst is conducting routine vulnerability assessments on the company infrastructure. When performing these scans, a business-critical server crashes, and the cause is traced back to the vulnerability scanner. Which of the following is the cause of this issue?

Options:

A.

The scanner is running without an agent installed.


B.

The scanner is running in active mode.


C.

The scanner is segmented improperly.


D.

The scanner is configured with a scanning window.


Expert Solution
Questions # 82:

A security analyst at a company called ACME Commercial notices there is outbound traffic to a host IP that resolves to https://offce365password.acme.co. The site ' s standard VPN logon page is

www.acme.com/logon. Which of the following is most likely true?

Options:

A.

This is a normal password change URL.


B.

The security operations center is performing a routine password audit.


C.

A new VPN gateway has been deployed


D.

A social engineering attack is underway


Expert Solution
Questions # 83:

An analyst finds that an IP address outside of the company network that is being used to run network and vulnerability scans across external-facing assets. Which of the following steps of an attack framework is the analyst witnessing?

Options:

A.

Exploitation


B.

Reconnaissance


C.

Command and control


D.

Actions on objectives


Expert Solution
Questions # 84:

A company patches its servers using automation software. Remote SSH or RDP connections are allowed to the servers only from the service account used by the automation software. All servers are in an internal subnet without direct access to or from the internet. An analyst reviews the following vulnerability summary:

Question # 84

Which of the following vulnerability IDs should the analyst address first?

Options:

A.

1


B.

2


C.

3


D.

4


Expert Solution
Questions # 85:

A systems administrator is reviewing after-hours traffic flows from data center servers and sees regular, outgoing HTTPS connections from one of the servers to a public IP address. The server should not be making outgoing connections after hours. Looking closer, the administrator sees this traffic pattern around the clock during work hours as well. Which of the following is the most likely explanation?

Options:

A.

Command-and-control beaconing activity


B.

Data exfiltration


C.

Anomalous activity on unexpected ports


D.

Network host IP address scanning


E.

A rogue network device


Expert Solution
Questions # 86:

A security analyst is writing a shell script to identify IP addresses from the same country. Which of the following functions would help the analyst achieve the objective?

Options:

A.

function w() { info=$(ping -c 1 $1 | awk -F “/” ‘END{print $1}’) & & echo “$1 | $info” }


B.

function x() { info=$(geoiplookup $1) & & echo “$1 | $info” }


C.

function y() { info=$(dig -x $1 | grep PTR | tail -n 1 ) & & echo “$1 | $info” }


D.

function z() { info=$(traceroute -m 40 $1 | awk ‘END{print $1}’) & & echo “$1 | $info” }


Expert Solution
Questions # 87:

A zero-day command injection vulnerability was published. A security administrator is analyzing the following logs for evidence of adversaries attempting to exploit the vulnerability:

Question # 87

Which of the following log entries provides evidence of the attempted exploit?

Options:

A.

Log entry 1


B.

Log entry 2


C.

Log entry 3


D.

Log entry 4


Expert Solution
Questions # 88:

A penetration tester submitted data to a form in a web application, which enabled the penetration tester to retrieve user credentials. Which of the following should be recommended for remediation of this application vulnerability?

Options:

A.

Implementing multifactor authentication on the server OS


B.

Hashing user passwords on the web application


C.

Performing input validation before allowing submission


D.

Segmenting the network between the users and the web server


Expert Solution
Questions # 89:

A security analyst is conducting a vulnerability assessment of a company ' s online store. The analyst discovers a critical vulnerability in the payment processing system that could be exploited, allowing attackers to steal customer payment information. Which of the following should the analyst do next?

Options:

A.

Leave the vulnerability unpatched until the next scheduled maintenance window to avoid potential disruption to business.


B.

Perform a risk assessment to evaluate the potential impact of the vulnerability and determine whether additional security measures are needed.


C.

Ignore the vulnerability since the company recently passed a payment system compliance audit.


D.

Isolate the payment processing system from production and schedule for reimaging.


Expert Solution
Questions # 90:

An analyst reviews a recent government alert on new zero-day threats and finds the following CVE metrics for the most critical of the vulnerabilities:

CVSS: 3.1/AV:N/AC: L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:W/RC:R

Which of the following represents the exploit code maturity of this critical vulnerability?

Options:

A.

E:U


B.

S:C


C.

RC:R


D.

AV:N


E.

AC:L


Expert Solution
Viewing page 9 out of 15 pages
Viewing questions 81-90 out of questions