Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the CompTIA CompTIA CySA+ CS0-003 Questions and answers with CertsForce

Viewing page 9 out of 15 pages
Viewing questions 81-90 out of questions
Questions # 81:
Options:

A.

Credentialed scans


B.

Individual scans


C.

Security baseline scans


D.

Agent-based scans


Expert Solution
Questions # 82:

In the last hour, a high volume of failed RDP authentication attempts has been logged on a critical server. All of the authentication attempts originated from the same remote IP address and made use of a single valid domain user account. Which of the following mitigating controls would be most effective to reduce the rate of success of this brute-force attack? (Select two).

Options:

A.

Increase the granularity of log-on event auditing on all devices.


B.

Enable host firewall rules to block all outbound traffic to TCP port 3389.


C.

Configure user account lockout after a limited number of failed attempts.


D.

Implement a firewall block for the IP address of the remote system.


E.

Install a third-party remote access tool and disable RDP on all devices.


F.

Block inbound to TCP port 3389 from untrusted remote IP addresses at the perimeter firewall.


Expert Solution
Questions # 83:

A security analyst detects an email server that had been compromised in the internal network. Users have been reporting strange messages in their email inboxes and unusual network traffic. Which of the following incident response steps should be performed next?

Options:

A.

Preparation


B.

Validation


C.

Containment


D.

Eradication


Expert Solution
Questions # 84:

A cloud team received an alert that unauthorized resources were being auto-provisioned. After investigating, the team suspects that crypto mining is occurring. Which of the following indicators would

most likely lead the team to this conclusion?

.

Options:

A.

High GPU utilization


B.

Bandwidth consumption


C.

Unauthorized changes


D.

Unusual traffic spikes


Expert Solution
Questions # 85:

A SOC manager reviews metrics from the last four weeks to investigate a recurring availability issue. The manager finds similar events correlating to the times of the reported issues.

Which of the following methods would the manager most likely use to resolve the issue?

Options:

A.

Vulnerability assessment


B.

Root cause analysis


C.

Recurrence reports


D.

Lessons learned


Expert Solution
Questions # 86:

Which of the following is the best action to take after the conclusion of a security incident to improve incident response in the future?

Options:

A.

Develop a call tree to inform impacted users


B.

Schedule a review with all teams to discuss what occurred


C.

Create an executive summary to update company leadership


D.

Review regulatory compliance with public relations for official notification


Expert Solution
Questions # 87:

A vulnerability scan of a web server that is exposed to the internet was recently completed. A security analyst is reviewing the resulting vector strings:

Vulnerability 1: CVSS: 3.0/AV:N/AC: L/PR: N/UI : N/S: U/C: H/I : L/A:L

Vulnerability 2: CVSS: 3.0/AV: L/AC: H/PR:N/UI : N/S: U/C: L/I : L/A: H

Vulnerability 3: CVSS: 3.0/AV:A/AC: H/PR: L/UI : R/S: U/C: L/I : H/A:L

Vulnerability 4: CVSS: 3.0/AV: P/AC: L/PR: H/UI : N/S: U/C: H/I:N/A:L

Which of the following vulnerabilities should be patched first?

Options:

A.

Vulnerability 1


B.

Vulnerability 2


C.

Vulnerability 3


D.

Vulnerability 4


Expert Solution
Questions # 88:

While reviewing the web server logs, a security analyst notices the following snippet:

.. \ .. / .. \ .. /boot.ini

Which of the following Is belng attempted?

Options:

A.

Directory traversal


B.

Remote file inclusion


C.

Cross-site scripting


D.

Remote code execution


E.

Enumeration of /etc/passwd


Expert Solution
Questions # 89:

An organization ' s threat intelligence team notes a recent trend in adversary privilege escalation procedures. Multiple threat groups have been observed utilizing native Windows tools to bypass system controls and execute commands with privileged credentials. Which of the following controls would be most effective to reduce the rate of success of such attempts?

Options:

A.

Disable administrative accounts for any operations.


B.

Implement MFA requirements for all internal resources.


C.

Harden systems by disabling or removing unnecessary services.


D.

Implement controls to block execution of untrusted applications.


Expert Solution
Questions # 90:

A security analyst scans a host and generates the following output:

Question # 90

Which of the following best describes the output?

Options:

A.

The host is unresponsive to the ICMP request.


B.

The host Is running a vulnerable mall server.


C.

The host Is allowlng unsecured FTP connectlons.


D.

The host is vulnerable to web-based exploits.


Expert Solution
Viewing page 9 out of 15 pages
Viewing questions 81-90 out of questions