Weekend Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: my75ex

Home > CompTIA > CompTIA CySA+ > CS0-004

CS0-004 CompTIA Cybersecurity Analyst CySA+ V4 (New Version) Question and Answers

Question # 4

An analyst must provide a visualization of data received from threat intelligence sources. The data includes the Internet Protocols, services, and tools used by threat actors.

Which of the following is the best framework for the analyst to follow to display this data?

A.

Diamond Model of Intrusion Analysis

B.

Exploit Prediction Scoring System

C.

Cyber Kill Chain

D.

MITRE Adversarial Tactics, Techniques, and Common Knowledge and Detection, Denial, and Disruption Framework Empowering Network Defense

Full Access
Question # 5

A vulnerability analyst must perform a security assessment on an edge device running various services.

The analyst runs an Nmap port scan and sees the following output:

Which of the following should the analyst do next to validate the discovered remote access service is secure?

A.

Verify that the web server certificate is added to certificate store.

B.

Verify that the Border Gateway Protocol (BGP) route has been published.

C.

Verify that the virtual private network (VPN) service is utilizing Main Mode.

D.

Verify that the web server can be pinged.

Full Access
Question # 6

A security analyst responds to an alert regarding identity and access management activity within the cloud environment. The attacker is currently trying to gain access from one isolated cloud subscription to another via a compromised user role.

Which of the following aspects of the MITRE ATT & CK framework is the attacker trying to perform?

A.

Privilege escalation

B.

Lateral movement

C.

Persistence

D.

Execution

E.

Credential access

Full Access
Question # 7

An analyst executes the top command on a Linux system for an unresponsive application and observes the following output:

Which of the following is the most likely cause of this issue?

A.

Service disruption

B.

Unauthorized software

C.

Resource exhaustion

D.

Filesystem changes

Full Access
Question # 8

An analyst reviews the following system logs from a recent breach attempt:

Which of the following techniques did the attacker attempt to use?

A.

Exfiltration

B.

Remote code execution

C.

Privilege escalation

D.

Spoofing

Full Access
Question # 9

Which of the following does a phishing campaign click rate measure?

A.

The effectiveness of an organization's email filters

B.

The false-positive rate of data leakage prevention behavior

C.

The employees' security awareness

D.

The speed of responding to a social engineering attack

Full Access
Question # 10

The vulnerability management team must scan the cloud environment to establish security baselines.

Which of the following assessment tools should the team use to perform this task?

A.

Metasploit

B.

Prowler

C.

Maltego

D.

Caldera

Full Access
Question # 11

An analyst prepares an after action report following an incident in which multiple systems were compromised over several days.

The analyst provides raw event logs from each compromised system in the report and determines that a patient-zero system cannot be found.

Which of the following should the analyst do to determine the patient-zero system?

A.

Establish an accurate timeline of events.

B.

Enable monitoring on the compromised systems.

C.

Isolate the compromised systems before remediation.

D.

Improve the content for incident updates during shift handoff.

E.

Perform a reverse composition analysis on malware packages.

Full Access
Question # 12

A security architect reviews a report from a third-party incident response consultant and observes the following:

Which of the following frameworks did the consultant use to perform analysis?

A.

Spoofing, tampering, repudiation, information disclosure, denial of service, elevation of privilege (STRIDE)

B.

MITRE ATT & CK

C.

Diamond Model of Intrusion Analysis

D.

National Institute of Standards and Technology (NIST) Cybersecurity Framework

E.

Cyber Kill Chain

Full Access
Question # 13

Which of the following phases of the incident response process will permanently remove an attacker’s access to corporate resources?

A.

Eradication

B.

Containment

C.

Denial of service

D.

Detection

Full Access
Question # 14

Multiple users report unexpected mouse movements and terminal windows opening.

An analyst reviewing the network traffic logs observes the following:

Which of the following is the most likely reason for the reported symptoms?

A.

Activity is on an internally addressable network.

B.

A reverse tunnel is being used to send commands.

C.

Remote Desktop Protocol (RDP) is being used to remotely control the impacted computers.

D.

Virtual Network Computing is being used to connect to systems.

Full Access
Question # 15

An incident response team identifies a malicious uniform resource locator (URL) associated with a required business process and performs the following activities:

• Access to the URL has been restricted only to the necessary users through firewall rules and Cloud Security Group rules.

• Additional monitoring has been enabled for traffic related to that site and the allowed users.

• All application servers that need to access that site have been patched with the latest security and software updates.

• Application owners have been notified of the severity and need to remediate this reported issue.

Which of the following best describes the overall mitigation the security team is performing?

A.

Patching solutions

B.

Configuration management

C.

Compensating controls

D.

Attack surface management

Full Access
Question # 16

Which of the following network architectures would best implement a perimeter-less network topology?

A.

Hybrid cloud networks

B.

Secure access service edge

C.

Cloud-native computing

D.

Content delivery networks

Full Access
Question # 17

An analyst reviews the following log entries:

Which of the following conclusions should the analyst reach? (Choose two.)

A.

Host ws-57 is performing a network scan against dc-1.

B.

Domain Controller dc-1 is performing a network scan against ws-57.

C.

Host ws-57 delivered a phishing email via Simple Mail Transfer Protocol.

D.

Host ws-57 is communicating on a service using a non-standard port.

E.

Domain Controller dc-1 is infected with ransomware and initiating connections with ws-57.

F.

Domain Controller dc-1 is communicating using a non-standard port.

Full Access
Question # 18

Before merging with a software company, the acquiring company's legal team requires a detailed software scan to determine if all code base is using open-source or paid licensed libraries. The vulnerability management analyst needs to provide this report.

Which of the following scan methods will best meet this requirement?

A.

Static application security testing (SAST)

B.

Dynamic application security testing (DAST)

C.

Software composition analysis (SCA)

D.

Runtime application self-protection (RASP)

E.

Credentialed vulnerability scan

Full Access
Question # 19

A server was recently compromised. A security analyst needs to collect artifacts for further analysis before disconnecting the server from the network.

Which of the following artifacts should the analyst collect first?

A.

ShellBags

B.

Hard disk

C.

Address Resolution Protocol table

D.

Netstat output

Full Access
Question # 20

Which of the following is the most likely reason an organization might implement compensating controls?

A.

A vulnerability does not have a patch, and the system is mission critical.

B.

A vulnerability has been fixed, tested, and deployed to production.

C.

A vulnerability is being actively exploited in the wild, but the organization does not use the affected system.

D.

A vulnerability was detected, but the organization has determined the result is a false positive.

Full Access
Question # 21

A cybersecurity analyst receives an unstructured text document that contains advanced persistent threat (APT)-related indicators of compromise (IoCs). The analyst needs to extract the IPv4 addresses.

Which of the following is the best tool to accomplish this task?

A.

CyberChef

B.

Wireshark

C.

Zeek

D.

Open Cyber Threat Intelligence (OpenCTI)

Full Access
Question # 22

An analyst reviews a summarized vulnerability report through a governance, risk, and compliance (GRC) reporting tool.

The following report correlates asset information from the configuration management database (CMDB) against detected vulnerabilities:

Which of the following servers should the analyst prioritize based on the target value, the risk, and the likelihood of exploitation?

A.

PRODWEB-02

B.

MPC-Control

C.

DEVWIN11-01

D.

PRODWEB-01

Full Access
Question # 23

An analyst needs to perform a baseline security evaluation of the company's cloud infrastructure.

Which of the following tools is most appropriate for this task?

A.

Open Vulnerability Assessment Scanner (OpenVAS)

B.

Nikto

C.

ScoutSuite

D.

Metasploit

Full Access
Question # 24

Which of the following actions should an incident response analyst take during the recovery phase of the incident response process?

A.

Verify that malicious activity has occurred.

B.

Reimage the disk.

C.

Take the system offline.

D.

Write the final report.

Full Access