[Q164-Q185] Excellent CS0-001 PDF Dumps With 100% PassExamDumps Exam Passing Guaranted [Mar-2022]

Share

Excellent CS0-001 PDF Dumps With 100% PassExamDumps Exam Passing Guaranted [Mar-2022]

100% Pass Your CS0-001 CompTIA Cybersecurity Analyst (CySA+) Certification Exam at First Attempt with PassExamDumps

NEW QUESTION 164
A cybersecurity analyst is currently investigating a server outage. The analyst has discovered the following value was entered for the username: 0xbfff601a. Which of the following attacks may be occurring?

  • A. Smurf attack
  • B. Man-in-the-middle attack
  • C. Denial of service attack
  • D. Buffer overflow attack
  • E. Format string attack

Answer: E

 

NEW QUESTION 165
After completing a vulnerability scan, the following output was noted:

Which of the following vulnerabilities has been identified?

  • A. Active Directory encryption vulnerability.
  • B. Web application cryptography vulnerability.
  • C. VPN tunnel vulnerability.
  • D. PKI transfer vulnerability.

Answer: B

Explanation:
Explanation/Reference:
Explanation:

 

NEW QUESTION 166
A server contains baseline images that are deployed to sensitive workstations on a regular basis. The images are evaluated once per month for patching and other fixes, but do not change otherwise. Which of the following controls should be put in place to secure the file server and ensure the images are not changed?

  • A. Require the use of two-factor authentication for any administrator or user who needs to connect to the server.
  • B. Schedule vulnerability scans of the server at least once per month before the images are updated.
  • C. Install and configure a file integrity monitoring tool on the server and allow updates to the images each month.
  • D. Install a honeypot to identify any attacks before the baseline images can be compromised.

Answer: C

Explanation:
Explanation

 

NEW QUESTION 167
A new zero day vulnerability was discovered within a basic screen capture app, which is used throughout the environment Two days after discovering the vulnerability, the manufacturer of the software has not announced a remediation or it there will be a fix for this newly discovered vulnerability. The vulnerable application is not uniquely critical, but it is used occasionally by the management and executive management teams The vulnerability allows remote code execution to gam privileged access to the system Which of the following is the BEST course of action to mitigate this threat'

  • A. Communicate with the end users that the application should not be used until the manufacturer has reserved the vulnerability.
  • B. Block the vulnerable application traffic at the firewall and disable the application services on each computer.
  • C. Remove the application and replace it with a similar non-vulnerable application.
  • D. Work with the manufacturer to determine the tone frame for the fix.

Answer: A

 

NEW QUESTION 168
A cybersecurity analyst is conducting packet analysis on the following:

Which of the following is occurring in the given packet capture?

  • A. Smurf attack
  • B. Zero-day exploit
  • C. Network enumeration
  • D. ARP spoofing
  • E. Broadcast storm

Answer: C

 

NEW QUESTION 169
A company has recently launched a new billing invoice website for a few key vendors. The cybersecurity analyst is receiving calls that the website is performing slowly and the pages sometimes time out. The analyst notices the website is receiving millions of requests, causing the service to become unavailable. Which of the following can be implemented to maintain the availability of the website?

  • A. DMZ
  • B. MAC filtering
  • C. VPN
  • D. Honeypot
  • E. Whitelisting

Answer: E

 

NEW QUESTION 170
A security analyst is creating baseline system images to remediate vulnerabilities found in different operating systems. Each image needs to be scanned before it is deployed. The security analyst must ensure the configurations match industry standard benchmarks and the process can be repeated frequently. Which of the following vulnerability options would BEST create the process requirements?

  • A. Utilizing an authorized credential scan
  • B. Utilizing an operating system SCAP plugin
  • C. Utilizing a known malware plugin
  • D. Utilizing a non-credential scan

Answer: B

Explanation:
Explanation/Reference:

 

NEW QUESTION 171
A software assurance lab is performing a dynamic assessment on an application by automatically generating and inputting different, random data sets to attempt to cause an error/failure condition. Which of the following software assessment capabilities is the lab performing AND during which phase of the SDLC should this occur? (Select two.)

  • A. Behavior modeling
  • B. Requirements phase
  • C. Prototyping phase
  • D. Planning phase
  • E. Static code analysis
  • F. Fuzzing

Answer: C,F

 

NEW QUESTION 172
A logistics company's vulnerability scan identifies the following vulnerabilities on Internet-facing devices in the DMZ:
SQL injection on an infrequently used web server that provides files to vendors

SSL/TLS not used for a website that contains promotional information

The scan also shows the following vulnerabilities on internal resources:
Microsoft Office Remote Code Execution on test server for a human resources system

TLS downgrade vulnerability on a server in a development network

In order of risk, which of the following should be patched FIRST?

  • A. Microsoft Office Remote Code Execution
  • B. TLS downgrade
  • C. SQL injection
  • D. SSL/TLS not used

Answer: A

 

NEW QUESTION 173
A security analyst received an alert from the antivirus software identifying a complex instance of malware on a company's network. The company does not have the resources to fully analyze the malware and determine its effect on the system. Which of the following is the BEST action to take in the incident recovery and post-incident response process?

  • A. Remove the malware and inappropriate materials; eradicate the incident.
  • B. Wipe hard drives, reimage the systems, and return the affected systems to ready state.
  • C. Perform event correlation; create a log retention policy.
  • D. Detect and analyze the precursors and indicators; schedule a lessons learned meeting.

Answer: A

 

NEW QUESTION 174
A security analyst performs various types of vulnerability scans.
You must review the vulnerability scan results to determine the type of scan that was executed and determine if a false positive occurred for each device.
Instructions:
Select the drop option for whether the results were generated from a credentialed scan, non-credentialed scan, or a compliance scan.
For ONLY the credentialed and non-credentialed scans, evaluate the results for false positives and check the findings that display false positives. NOTE: If you would like to uncheck an option that is currently selected, click on the option a second time.
Lastly, based on the vulnerability scan results, identify the type of Server by dragging the Server to the results.
The Linux Web Server, File-Print Server and Directory Server are draggable.
If at any time you would like to bring back the initial state of the simulation, please select the Reset button.
When you have completed the simulation, please select the Done button to submit. Once the simulation is submitted, please select the Next button to continue.

Answer:

Explanation:

Explanation
1. non-credentialed scan- File Print Server: False positive is first bullet point.
2. credentialed scan - Linux Web Server: No False positives.
3. Compliance scan- Directory Server

 

NEW QUESTION 175
Due to new regulations, a company has decided to institute an organizational vulnerability management program and assign the function to the security team. Which of the following frameworks would BEST support the program? (Choose two.)

  • A. COBIT
  • B. ISO 27000 series
  • C. NIST
  • D. ITIL
  • E. COSO

Answer: C,D

 

NEW QUESTION 176
A cybersecurity analyst is currently checking a newly deployed server that has an access control list applied.
When conducting the scan, the analyst received the following code snippet of results:

Which of the following describes the output of this scan?

  • A. The analyst has discovered a True Positive, and the status code is correct providing a file not found error message.
  • B. The analyst has discovered a True Positive, and the status code is incorrect providing a forbidden message.
  • C. The analyst has discovered a False Positive, and the status code is incorrect providing an OK message.
  • D. The analyst has discovered a False Positive, and the status code is incorrect providing a server error message.

Answer: A

 

NEW QUESTION 177
A security analyst must perform quarterly vulnerability scans to keep the organization In compliance with PCI regulations. The analyst has scheduled the scans to occur early on Monday mornings and uses Nexpose on 192.168.65.32 to run scans on the entire network. The morning after the scan was run. the analyst received the following alert from the network-based IDS system:

Which of the following would be the BEST way to address this alert while remaining in compliance with PCI regulations?

  • A. Disable any services that are vulnerable to XXE attacks on the destination servers.
  • B. Isolate 192.168.65.32 and begin Incident response procedures on the device.
  • C. Validate that the alert is a false positive triggered by the scanning process.
  • D. Create a firewall rule restricting traffic from 192.168.65.32 to the 192.168.70 network.

Answer: D

 

NEW QUESTION 178
Which of the following is a control that allows a mobile application to access and manipulate information
which should only be available by another application on the same mobile device (e.g. a music application
posting the name of the current song playing on the device on a social media site)?

  • A. Dual authentication
  • B. Co-hosted application
  • C. Transitive trust
  • D. Mutually exclusive access

Answer: C

 

NEW QUESTION 179
A security analyst is conducting a vulnerability assessment of older SCADA devices on the corporate network. Which of the following compensating controls is likely to prevent the scans from providing value?

  • A. Implementation of a VLAN that allows all devices on the network to see all SCADA devices on the network.
  • B. Access control list network segmentation that prevents access to the SCADA devices inside the network.
  • C. Detailed and tested firewall rules that effectively prevent outside access of the SCADA devices.
  • D. SCADA systems configured with 'SCADA SUPPORT'=ENABLE

Answer: C

 

NEW QUESTION 180
A security analyst is reviewing packet captures to determine the extent of success during an attacker's
reconnaissance phase following a recent incident.
The following is a hex and ASCII dump of one such packet:

Which of the following BEST describes this packet?

  • A. DNS over UDP standard query
  • B. DNS BIND version request
  • C. DNS over TCP server status query
  • D. DNS zone transfer request

Answer: B

 

NEW QUESTION 181
After scanning the main company's website with the OWASP ZAP tool, a cybersecurity analyst is reviewing the following warning:

The analyst reviews a snippet of the offending code:

Which of the following is the BEST course of action based on the above warning and code snippet?

  • A. The analyst should implement a scanner exception for the false positive.
  • B. The developer should review the code and implement a code fix.
  • C. The system administrator should disable SSL and implement TLS.
  • D. The organization should update the browser GPO to resolve the issue.

Answer: D

Explanation:
Explanation/Reference:
Explanation:

 

NEW QUESTION 182
After reviewing the following packet, a cybersecurity analyst has discovered an unauthorized service is
running on a company's computer.

Which of the following ACLs, if implemented, will prevent further access ONLY to the unauthorized service
and will not impact other services?

  • A. DENY TCP ANY HOST 10.38.219.20 EQ 3389
  • B. DENY TCP ANY HOST 192.168.1.10 EQ 25
  • C. DENY IP HOST192.168.1.10 HOST 10.38.219.20 EQ 3389
  • D. DENY IP HOST 10.38.219.20 ANY EQ 25

Answer: A

Explanation:
Explanation/Reference:
Explanation:

 

NEW QUESTION 183
A server contains baseline images that are deployed to sensitive workstations on a regular basis. The
images are evaluated once per month for patching and other fixes, but do not change otherwise. Which of
the following controls should be put in place to secure the file server and ensure the images are not
changed?

  • A. Require the use of two-factor authentication for any administrator or user who needs to connect to the
    server.
  • B. Schedule vulnerability scans of the server at least once per month before the images are updated.
  • C. Install and configure a file integrity monitoring tool on the server and allow updates to the images each
    month.
  • D. Install a honeypot to identify any attacks before the baseline images can be compromised.

Answer: C

 

NEW QUESTION 184
Nmap scan results on a set of IP addresses returned one or more lines beginning with "cpe:/o:" followed by a company name, product name, and version. Which of the following would this string help an administrator to identify?

  • A. Installed software
  • B. Running services
  • C. Installed hardware
  • D. Operating system

Answer: D

 

NEW QUESTION 185
......

Trend for CS0-001 pdf dumps before actual exam: https://www.passexamdumps.com/CS0-001-valid-exam-dumps.html

Real Exam Questions and Answers - CompTIA CS0-001 Dump is Ready: https://drive.google.com/open?id=1uXhmJJb-U-PWH-faLKFim6BgHxwCX9PG