[2021] Use Valid Exam CS0-002 by Prep4sures Books For Free Website
Free CompTIA CySA+ CS0-002 Official Cert Guide PDF Download
Prerequisites for Taking the CompTIA CySA+ Certification Exam
CS0-002 has no strict requirements. Anyone, regardless of their knowledge level, can apply to take the test. However, CompTIA does recommend that you have a minimum of 4 years’ experience in the cybersecurity field. Also, the candidates should possess the CompTIA Network+ or CompTIA Security+ certificate or understand everything covered by them.
NEW QUESTION 102
A security analyst has received reports of very slow, intermittent access to a public-facing corporate server.
Suspecting the system may be compromised, the analyst runs the following commands:
Based on the output from the above commands, which of the following should the analyst do NEXT to further the investigation?
- A. Run crontab -r; rm -rf /tmp/.t to remove and disable the malware on the system.
- B. Run kill -9 1325 to bring the load average down so the server is usable again.
- C. Examine the server logs for further indicators of compromise of a web application.
- D. Perform a binary analysis on the /tmp/.t/t file, as it is likely to be a rogue SSHD server.
Answer: C
NEW QUESTION 103
A technician receives an alert indicating an endpoint is beaconing to a suspect dynamic DNS domain. Which of the following countermeasures should be used to BEST protect the network in response to this alert? (Choose two.)
- A. Set up a sinkhole for that dynamic DNS domain to prevent communication.
- B. Perform a risk assessment and implement compensating controls.
- C. Ensure the IDS is active on the network segment where the endpoint resides.
- D. Isolate the infected endpoint to prevent the potential spread of malicious activity.
- E. Implement an internal honeypot to catch the malicious traffic and trace it.
Answer: A,D
NEW QUESTION 104
A cybersecurity analyst is currently using Nessus to scan several FTP servers. Upon receiving the results of the scan, the analyst needs to further test to verify that the vulnerability found exists.
The analyst uses the following snippet of code:
Which of the following vulnerabilities is the analyst checking for?
- A. SQL injection
- B. Buffer overflow
- C. Default passwords
- D. Format string attack
Answer: A
NEW QUESTION 105
During a physical penetration test at a client site, a local law enforcement officer stumbled upon the test questioned the legitimacy of the team.
Which of the following information should be shown to the officer?
- A. Timing information
- B. Team reporting
- C. Scope of work
- D. Letter of engagement
Answer: D
NEW QUESTION 106
Datacenter access is controlled with proximity badges that record all entries and exits from the datacenter.
The access records are used to identify which staff members accessed the data center in the event of equipment theft.
Which of the following MUST be prevented in order for this policy to be effective?
- A. Password reuse
- B. Phishing
- C. Social engineering
- D. Tailgating
Answer: D
NEW QUESTION 107
An analyst was testing the latest version of an internally developed CRM system. The analyst created a basic user account. Using a few tools in Kali's latest distribution, the analyst was able to access configuration files, change permissions on folders and groups, and delete and create new system objects. Which of the following techniques did the analyst use to perform these unauthorized activities?
- A. Input injection
- B. Impersonation
- C. Directory traversal
- D. Privilege escalation
Answer: C
NEW QUESTION 108
An employee was conducting research on the Internet when a message from cyber criminals appeared on the screen, stating the hard drive was just encrypted by a ransomware variant. An analyst observes the following:
Antivirus signatures were updated recently
The desktop background was changed
Web proxy logs show browsing to various information security sites and ad network traffic
There is a high volume of hard disk activity on the file server
SMTP server shown the employee recently received several emails from blocked senders
The company recently switched web hosting providers
There are several IPS alerts for external port scans
Which of the following describes how the employee got this type of ransomware?
- A. The employee was using another user's credentials
- B. The employee opened an email attachment
- C. The employee updated antivirus signatures
- D. The employee fell victim to a CSRF attack
Answer: D
NEW QUESTION 109
It is important to parameterize queries to prevent:
- A. the esrtablishment of a web shell that would allow unauthorized access.
- B. a memory overflow that executes code with elevated privileges.
- C. the execution of unauthorized actions against a database.
- D. the queries from using an outdated library with security vulnerabilities.
Answer: C
NEW QUESTION 110
A user's computer has been running slowly when the user tries to access web pages. A security analyst runs the command netstat -aon from the command line and receives the following output:
Which of the following lines indicates the computer may be compromised?
- A. Line 6
- B. Line 1
- C. Line 4
- D. Line 5
- E. Line 3
- F. Line 2
Answer: C
NEW QUESTION 111
A threat intelligence feed has posted an alert stating there is a critical vulnerability in the kernel.
Unfortunately, the company's asset inventory is not current.
Which of the following techniques would a cybersecurity analyst perform to find all affected servers within an organization?
- A. An OS fingerprinting scan across all hosts
- B. A packet capture of data traversing the server network
- C. A manual log review from data sent to syslog
- D. A service discovery scan on the network
Answer: A
NEW QUESTION 112
A security analyst is evaluating two vulnerability management tools for possible use in an organization. The analyst set up each of the tools according to the respective vendor's instructions and generated a report of vulnerabilities that ran against the same target server.
Tool A reported the following:
Tool B reported the following:
Which of the following BEST describes the method used by each tool? (Choose two.)
- A. Tool A is unauthenticated.
- B. Tool B is agent based.
- C. Tool B utilized machine learning technology.
- D. Tool B is unauthenticated.
- E. Tool A used fuzzing logic to test vulnerabilities.
- F. Tool A is agent based.
Answer: A,B
NEW QUESTION 113
A security analyst was asked to join an outage call for a critical web application. The web middleware support team determined the web server is running and having no trouble processing requests; however, some investigation has revealed firewall denies to the web server that began around 1.00 a.m. that morning. An emergency change was made to enable the access, but management has asked for a root cause determination. Which of the following would be the BEST next step?
- A. Block all traffic to the web server with an ACL.
- B. Use a port scanner to determine all listening ports on the web server.
- C. Search the logging servers for any rule changes.
- D. Install a packet analyzer near the web server to capture sample traffic to find anomalies.
Answer: C
NEW QUESTION 114
A security analyst is reviewing packet captures from a system that was compromised. The system was already isolated from the network, but it did have network access for a few hours after being compromised. When viewing the capture in a packet analyzer, the analyst sees the following:
Which of the following can the analyst conclude?
- A. Data is being exfiltrated over DNS.
- B. Malware is attempting to beacon to 128.50.100.3.
- C. The system is scanning ajgidwle.com for PII.
- D. The system is running a DoS attack against ajgidwle.com.
Answer: C
NEW QUESTION 115
A security analyst on the threat-hunting team has developed a list of unneeded, benign services that are currently running as part of the standard OS deployment for workstations. The analyst will provide this list to the operations team to create a policy that will automatically disable the services for all workstations in the organization.
Which of the following BEST describes the security analyst's goal?
- A. To improve malware detection
- B. To optimize system performance
- C. To reduce the attack surface
- D. To create a system baseline
Answer: B
NEW QUESTION 116
During an investigation, an incident responder intends to recover multiple pieces of digital media.
Before removing the media, the responder should initiate:
- A. decryption tools.
- B. malware scans.
- C. chain of custody forms.
- D. secure communications.
Answer: C
NEW QUESTION 117
......
CompTIA CS0-002 Official Cert Guide PDF: https://www.prep4sures.top/CS0-002-exam-dumps-torrent.html
Exam CS0-002: CompTIA Cybersecurity Analyst (CySA+) Certification Exam - Prep4sures: https://drive.google.com/open?id=1U6zUxSIxebIL-W6FMQuckUXKrSnA6bUj