Labour Day Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bigdisc65

CompTIA CySA+ CS0-001 CompTIA Study Notes

Page: 15 / 16
Question 60

An HR employee began having issues with a device becoming unresponsive after attempting to open an email attachment. When informed, the security analyst became suspicious of the situation, even though there was not any unusual behavior on the IDS or any alerts from the antivirus software. Which of the following BEST describes the type of threat in this situation?

Options:

A.

Packet of death

B.

Zero-day malware

C.

PII exfiltration

D.

Known virus

Question 61

A cybersecurity analyst has been asked to follow a corporate process that will be used to manage vulnerabilities for an organization. The analyst notices the policy has not been updated in three years. Which of the following should the analyst check to ensure the policy is still accurate?

Options:

A.

Threat intelligence reports

B.

Technical constraints

C.

Corporate minutes

D.

Governing regulations

Question 62

An organization has recently recovered from an incident where a managed switch had been accessed and reconfigured without authorization by an insider. The incident response team is working on developing a lessons learned report with recommendations. Which of the following recommendations will BEST prevent the same attack from occurring in the future?

Options:

A.

Remove and replace the managed switch with an unmanaged one.

B.

Implement a separate logical network segment for management interfaces.

C.

Install and configure NAC services to allow only authorized devices to connect to the network.

D.

Analyze normal behavior on the network and configure the IDS to alert on deviations from normal.

Question 63

An organization wants to remediate vulnerabilities associated with its web servers. An initial vulnerability scan has been performed, and analysts are reviewing the results. Before starting any remediation, the analysts want to remove false positives to avoid spending time on issues that are not actual vulnerabilities. Which of the following would be an indicator of a likely false positive?

Options:

A.

Reports show the scanner compliance plug-in is out-of-date.

B.

Any items labeled ‘low’ are considered informational only.

C.

The scan result version is different from the automated asset inventory.

D.

‘HTTPS’ entries indicate the web page is encrypted securely.

Page: 15 / 16
Exam Code: CS0-001
Exam Name: CompTIA CSA+ Certification Exam
Last Update: Apr 14, 2023
Questions: 455
CS0-001 pdf

CS0-001 PDF

$28  $80
CS0-001 Engine

CS0-001 Testing Engine

$33.25  $95
CS0-001 PDF + Engine

CS0-001 PDF + Testing Engine

$45.5  $130