Prepare CS0-002 Question Answers - CS0-002 Exam Dumps [Q41-Q64]

Share

Prepare CS0-002 Question Answers - CS0-002 Exam Dumps

Real CompTIA CS0-002 Exam Questions [Updated 2023]

NEW QUESTION # 41
An email analysis system notifies a security analyst that the following message was quarantined and requires further review.

Which of the following actions should the security analyst take?

  • A. Purchase the gift cards and submit an expense report.
  • B. Immediately contact a purchasing agent to expedite.
  • C. Release the email for delivery due to its importance.
  • D. Delete the email and block the sender.

Answer: D


NEW QUESTION # 42
A technician is troubleshooting a desktop computer with low disk space. The technician reviews the following information snippets:

Which of the following should the technician do to BEST resolve the issue based on the above information? (Choose two.)

  • A. Disable the movieDB service
  • B. Delete the movies/movies directory
  • C. Enable OS auto updates
  • D. Defragment the disk
  • E. Install a file integrity tool

Answer: A,D


NEW QUESTION # 43
An organization is conducting penetration testing to identify possible network vulnerabilities. The penetration tester has already identified active hosts in the network and is now scanning individual hosts to determine if any are running a web server. The output from the latest scan is shown below:

Which of the following commands would have generated the output above?

  • A. -nmap -sV 192.168.1.13 -p 80
  • B. -nmap -sV 192.168.1.1 -p 80
  • C. -nmap -sP 192.168.1.13 -p ALL
  • D. -nmap -sP 192.168.1.0/24 -p ALL

Answer: A


NEW QUESTION # 44
The Cruel Executive Officer (CEO) of a large insurance company has reported phishing emails that contain malicious links are targeting the entire organza lion Which of the following actions would work BEST to prevent against this type of attack?

  • A. Modify the EDR solution to use heuristic analysis techniques for malware.
  • B. Reconfigure the EDR solution to perform real-time scanning of all files
  • C. Turn on full behavioral analysis to avert an infection
  • D. Implement an EOR mail module that will rewrite and analyze email links.
  • E. Ensure EDR signatures are updated every day to avert infection.

Answer: E


NEW QUESTION # 45
The Chief Information Security Officer (CISO) has asked the security analyst to examine abnormally high processor utilization on a key server. The output below is from the company's research and development (R&D) server.

Which of the following actions should the security analyst take FIRST?

  • A. Initiate an investigation
  • B. Determine availability
  • C. Isolate the R&D server
  • D. Reimage the server

Answer: C


NEW QUESTION # 46
A security analyst is reviewing packet captures from a system that was compromised. The system was already isolated from the network, but it did have network access for a few hours after being compromised. When viewing the capture in a packet analyzer, the analyst sees the following:

Which of the following can the analyst conclude?

  • A. The system is running a DoS attack against ajgidwle.com.
  • B. Malware is attempting to beacon to 128.50.100.3.
  • C. The system is scanning ajgidwle.com for PII.
  • D. Data is being exfiltrated over DNS.

Answer: D


NEW QUESTION # 47
Which of the following items represents a document that includes detailed information on when an incident was detected, how impactful the incident was, and how it was remediated, in addition to incident response effectiveness and any identified gaps needing improvement?

  • A. Lessons learned report
  • B. Trends analysis report
  • C. Forensic analysis report
  • D. Chain of custody report

Answer: A


NEW QUESTION # 48
A Chief Information Security Officer (CISO) wants to upgrade an organization's security posture by improving proactive activities associated with attacks from internal and external threats.
Which of the following is the MOST proactive tool or technique that feeds incident response capabilities?

  • A. Quarterly vulnerability scanning using credentialed scans
  • B. Development of a hypothesis as part of threat hunting
  • C. Continuous compliance monitoring using SCAP dashboards
  • D. Log correlation, monitoring, and automated reporting through a SIEM platform

Answer: B

Explanation:
Explanation


NEW QUESTION # 49
Which of the following is MOST effective for correlation analysis by log for threat management?

  • A. IPS
  • B. PCAP
  • C. SIEM
  • D. SCAP

Answer: C


NEW QUESTION # 50
While preparing of an audit of information security controls in the environment an analyst outlines a framework control that has the following requirements:
* All sensitive data must be classified
* All sensitive data must be purged on a quarterly basis
* Certificates of disposal must remain on file for at least three years This framework control is MOST likely classified as:

  • A. corrective
  • B. preventive
  • C. risk-based
  • D. prescriptive

Answer: B


NEW QUESTION # 51
A security analyst identified one server that was compromised and used as a data making machine, and a few of the hard drive that was created. Which of the following will MOST likely provide information about when and how the machine was compromised and where the malware is located?

  • A. Data carving
  • B. System timeline reconstruction
  • C. Volatile memory analysts
  • D. System registry extraction

Answer: C

Explanation:
Explanation
Information security professionals conduct memory forensics to investigate and identify attacks or malicious behaviors that do not leave easily detectable tracks on hard drive data.


NEW QUESTION # 52
An analyst performs a routine scan of a host using Nmap and receives the following output:

Which of the following should the analyst investigate FIRST?

  • A. Port 23
  • B. Port 21
  • C. Port 22
  • D. Port 80

Answer: A


NEW QUESTION # 53
A security analyst is investigating a compromised Linux server.
The analyst issues the ps command and receives the following output.

Which of the following commands should the administrator run NEXT to further analyze the compromised system?

  • A. /bin/la -1 /proc/1301/exe
  • B. kill -9 1301
  • C. rpm -V openash-server
  • D. strace /proc/1301

Answer: D


NEW QUESTION # 54
A security analyst has been asked to scan a subnet. During the scan, the following output was generated:

Based on the output above, which of the following is MOST likely?

  • A. 192.168.100.145 is a DNS server
  • B. 192.168.100.214 is a secure FTP server
  • C. 192.168.100.214 is a web server
  • D. Both hosts are mail servers

Answer: C


NEW QUESTION # 55
A company's senior human resources administrator left for another position, and the assistant administrator was promoted into the senior position. On the official start day, the new senior administrator planned to ask for extended access permissions but noticed the permissions were automatically granted on that day. Which of the following describes the access management policy in place at the company?

  • A. Role-based
  • B. Federated access
  • C. Mandatory-based
  • D. Host-based

Answer: A


NEW QUESTION # 56
A medical organization recently started accepting payments over the phone. The manager is concerned about the impact of the storage of different types of data. Which of the following types of data incurs the highest regulatory constraints?

  • A. IP
  • B. PCI
  • C. PHI
  • D. PII

Answer: B


NEW QUESTION # 57
Which of the following countermeasures should the security administrator apply to MOST effectively mitigate Bootkit-level infections of the organization's workstation devices?

  • A. Configure a BIOS-level password on the device.
  • B. Remove local administrator privileges.
  • C. Enforce a system state recovery after each device reboot.
  • D. Install a secondary virus protection application.

Answer: B


NEW QUESTION # 58
An analyst is reviewing the following output:

Which of the following was MOST likely used to discover this?

  • A. A passive vulnerability scan
  • B. Reverse engineering using a debugger
  • C. A web application vulnerability scan
  • D. A static analysis vulnerability scan

Answer: A


NEW QUESTION # 59
Because some clients have reported unauthorized activity on their accounts, a security analyst is reviewing network packet captures from the company's API server. A portion of a capture file is shown below:
POST /services/v1_0/Public/Members.svc/soap
<s:Envelope+xmlns:s="http://schemas.s/soap/envelope/"><s:Body><GetIPLoc ation+xmlns="http://tempuri.org/">
<request+xmlns:a="http://schemas.somesite.org"+xmlns:i="http://www.w3.o rg/2001/XMLSchema-instance"></s:Body></s:Envelope> 192.168.1.22 - - api.somesite.com 200 0 1006 1001 0 192.168.1.22 POST /services/v1_0/Public/Members.svc/soap
<<a:Password>Password123</a:Password><a:ResetPasswordToken+i:nil="true"
/>
<a:ShouldImpersonatedAuthenticationBePopulated+i:nil="true"/><a:Usernam e>[email protected]</a:Username></request></Login></s:Body></s:E nvelope> 192.168.5.66 - - api.somesite.com 200 0 11558 1712 2024
192.168.4.89
POST /services/v1_0/Public/Members.svc/soap
<s:Envelope+xmlns:s="http://schemas.xmlsoap.org/soap/envelope/"><s:Body
><GetIPLocation+xmlns="http://tempuri.org/">
<a:IPAddress>516.7.446.605</a:IPAddress><a:ZipCode+i:nil="true"/></requ est></GetIPLocation></s:Body></s:Envelope> 192.168.1.22 - - api.somesite.com 200 0 1003 1011 307 192.168.1.22 POST /services/v1_0/Public/Members.svc/soap
<s:Envelope+xmlns:s="http://schemas.xmlsoap.org/soap/envelope/"><s:Body
><IsLoggedIn+xmlns="http://tempuri.org/">
<request+xmlns:a="http://schemas.datacontract.org/2004/07/somesite.web+ xmlns:i="http://www.w3.org/2001/XMLSchema-instance"><a:Authentication>
<a:ApiToken>kmL4krg2CwwWBan5BReGv5Djb7syxXTNKcWFuSjd</a:ApiToken><a:Imp ersonateUserId>0</a:ImpersonateUserId><a:LocationId>161222</a:LocationI d>
<a:NetworkId>4</a:NetworkId><a:ProviderId>''1=1</a:ProviderId><a:UserId
>13026046</a:UserId></a:Authentication></request></IsLoggedIn></s:Body>
</s:Envelope> 192.168.5.66 - - api.somesite.com 200 0 1378 1209 48
192.168.4.89
Which of the following MOST likely explains how the clients' accounts were compromised?

  • A. The clients' authentication tokens were impersonated and replayed.
  • B. An XSS scripting attack was carried out on the server.
  • C. A SQL injection attack was carried out on the server.
  • D. The clients' usernames and passwords were transmitted in cleartext.

Answer: A


NEW QUESTION # 60
A Chief Executive Officer (CEO) is concerned the company will be exposed to data sovereignty issues as a result of some new privacy regulations to help mitigate this risk. The Chief Information Security Officer (CISO) wants to implement an appropriate technical control. Which of the following would meet the requirement?

  • A. Enhanced encryption functions
  • B. Data masking procedures
  • C. Geographic access requirements
  • D. Regular business impact analysis functions

Answer: C

Explanation:
Explanation
Data Sovereignty means that data is subject to the laws and regulations of the geographic location where that data is collected and processed. Data sovereignty is a country-specific requirement that data must remain within the borders of the jurisdiction where it originated. At its core, data sovereignty is about protecting sensitive, private data and ensuring it remains under the control of its owner. You're only worried about that if you're in multiple locations. . https://www.virtru.com/blog/gdpr-data-sovereignty-matters-globally


NEW QUESTION # 61
A security analyst is conducting a post-incident log analysis to determine which indicators can be used to detect further occurrences of a data exfiltration incident. The analyst determines backups were not performed during this time and reviews the following:

Which of the following should the analyst review to find out how the data was exfilltrated?

  • A. Wednesday's logs
  • B. Tuesday's logs
  • C. Thursday's logs
  • D. Monday's logs

Answer: C


NEW QUESTION # 62
An analyst is observing unusual network traffic from a workstation. The workstation is communicating with a known malicious site over an encrypted tunnel.
A full antivirus scan with an updated antivirus signature file does not show any sign of infection.
Which of the following has occurred on the workstation?

  • A. Session hijack
  • B. Known malware attack
  • C. Cookie stealing
  • D. Zero-day attack

Answer: D


NEW QUESTION # 63
An organization has a strict policy that if elevated permissions are needed, users should always run commands under their own account, with temporary administrator privileges if necessary. A security analyst is reviewing syslog entries and sees the following:

Which of the following entries should cause the analyst the MOST concern?

  • A. <100> 2020-01-10T19:33:48.002z webserver sudo 201 32001 = BOM ' su vi syslog.conf failed for jos
  • B. <100>2 2020-01-10T19:33:41.002z webserver su 201 32001 = BOM ' su vi httpd.conf' failed for joe
  • C. <100> 2020-01-10T19:34..002z financeserver su 201 32001 = BOM ' su vi success
  • D. <100>2 2020-01-10T20:36:36.0010z financeserver su 201 32001 = BOM ' sudo vi users.txt success
  • E. <100> 2020-01-10T19:33:48.002z webserver sudo 201 32001 = BOM ' su vi httpd.conf' success

Answer: B


NEW QUESTION # 64
......

CS0-002 Exam Dumps Pass with Updated 2023: https://www.testkingit.com/CompTIA/latest-CS0-002-exam-dumps.html

Free CS0-002 Exam Dumps to Pass Exam Easily: https://drive.google.com/open?id=15LZAKKn9GYulR_1Y8k7qPdHeKeAjHizl