Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the CompTIA CompTIA CySA+ CS0-004 Questions and answers with CertsForce

Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions
Questions # 1:

An incident response team identifies a malicious uniform resource locator (URL) associated with a required business process and performs the following activities:

• Access to the URL has been restricted only to the necessary users through firewall rules and Cloud Security Group rules.

• Additional monitoring has been enabled for traffic related to that site and the allowed users.

• All application servers that need to access that site have been patched with the latest security and software updates.

• Application owners have been notified of the severity and need to remediate this reported issue.

Which of the following best describes the overall mitigation the security team is performing?

Options:

A.

Patching solutions


B.

Configuration management


C.

Compensating controls


D.

Attack surface management


Expert Solution
Questions # 2:

A security analyst isolates a Windows 11 workstation from the network after known malware is detected. The list of security information and event management (SIEM) events during the malware installation and timeline does not identify a specific user who was logged in. The security analyst uses the local administrative account to log in and would like a list of logins to the machine.

Which of the following PowerShell commands should the analyst use?

Options:

A.

Eventvwr.exe -LogType "Security" EventID "*" | Export-Csv c:\temp\Seclog.csv -NoTypeInformation


B.

Get-WinEvent -FilterHashTable @{ Logname="Security"

ED=4624;

} | Sort-Object TimeCreated -Descending | Export-Csv c:\temp\Seclog.csv -NoTypeInformation


C.

Get-WinEvent -FilterHashTable @{ Logname="System"

ED=9754;

} | Sort-Object TimeCreated -Descending | Export-Csv c:\temp\Seclog.csv -NoTypeInformation


D.

Get-WinEvent -FilterHashTable @{ Logname="Application"

ED=7124;

} | Sort-Object TimeCreated -Descending | Export-Csv c:\temp\Seclog.csv -NoTypeInformation


Expert Solution
Questions # 3:

An analyst is configuring a security information and event management system to capture fileless malware execution events.

Which of the following log files requires additional configuration to accomplish this task?

Options:

A.

Microsoft-Windows-Crypto-DPAPI/Operational


B.

Microsoft-Windows-PowerShell/Operational


C.

Microsoft-Windows-UserPnp/DeviceInstall


D.

Microsoft-Windows-TerminalServices-LocalSessionManager/Operational


Expert Solution
Questions # 4:

Which of the following best explains why sensitive data should be encrypted at rest on laptops?

Options:

A.

To prevent end users from copying data to other systems


B.

To protect disclosure of information if physical devices are stolen


C.

To comply with regulatory and legal requirements


D.

To ensure the integrity of the data on the company network


Expert Solution
Questions # 5:

Which of the following best explains the purpose of the Pyramid of Pain in threat intelligence?

Options:

A.

To show that changing to different types of indicators and behaviors is difficult for an adversary


B.

To measure how much operational damage a threat actor can cause before detection occurs


C.

To compare open-source intelligence (OSINT) with closed-source intelligence based on collection cost


D.

To organize attack activity into categories such as spoofing, tampering, and repudiation


Expert Solution
Questions # 6:

An analyst prepares an after action report following an incident in which multiple systems were compromised over several days.

The analyst provides raw event logs from each compromised system in the report and determines that a patient-zero system cannot be found.

Which of the following should the analyst do to determine the patient-zero system?

Options:

A.

Establish an accurate timeline of events.


B.

Enable monitoring on the compromised systems.


C.

Isolate the compromised systems before remediation.


D.

Improve the content for incident updates during shift handoff.


E.

Perform a reverse composition analysis on malware packages.


Expert Solution
Questions # 7:

The Chief Information Officer (CIO) is requiring users to phase out a legacy system that no longer receives security updates because the system will be decommissioned soon.

Which of the following risk management strategies is the CIO using?

Options:

A.

Avoidance


B.

Mitigation


C.

Acceptance


D.

Transference


Expert Solution
Questions # 8:

A vulnerability analyst conducts a security assessment on the Remote Desktop Protocol (RDP) security posture within the environment.

The analyst issues the following command for the assessment: nmap -p 3389 --script rdp* 10.0.0.0/24 The analyst receives responses, which are divided into one of the two categories, from 13 out of the 254 hosts:

Question # 8

Which of the following conclusions can the analyst make about the output on Category 2?

Options:

A.

The systems are joined to an Active Directory domain and using New Technology LAN Manager (NTLM) as an authentication method.


B.

The systems are not joined to an Active Directory domain and are using Kerberos as an authentication method.


C.

The systems are not joined to an Active Directory domain and are using NTLM as an authentication method.


D.

The systems are joined to an Active Directory domain and are using Kerberos as an authentication method.


Expert Solution
Questions # 9:

A security analyst receives a notice about a possible data breach. The report identifies unapproved, current access dates for files found in the following personnel archives:

Question # 9

Which of the following actions should the analyst take first?

Options:

A.

Perform log correlation.


B.

Reset user credentials.


C.

Restore files from backup.


D.

Establish a timeline.


E.

Establish a legal hold.


Expert Solution
Questions # 10:

An analyst reviews a summarized vulnerability report through a governance, risk, and compliance (GRC) reporting tool.

The following report correlates asset information from the configuration management database (CMDB) against detected vulnerabilities:

Question # 10

Which of the following servers should the analyst prioritize based on the target value, the risk, and the likelihood of exploitation?

Options:

A.

PRODWEB-02


B.

MPC-Control


C.

DEVWIN11-01


D.

PRODWEB-01


Expert Solution
Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions