CS0-002 Exam Dumps - PDF Questions and Testing Engine
CS0-002 Dumps - The Sure Way To Pass Exam
NEW QUESTION # 103
A security analyst conducted a risk assessment on an organization's wireless network and identified a high-risk element in the implementation of data confidentially protection.
Which of the following is the BEST technical security control to mitigate this risk?
- A. Switch to TACACS+ technology.
- B. Switch to the WPA2 protocol.
- C. Switch to 802 IX technology
- D. Switch to RADIUS technology
Answer: A
NEW QUESTION # 104
A company is experiencing a malware attack within its network. A security engineer notices many of the impacted assets are connecting outbound to a number of remote destinations and exfiltrating dat a. The security engineer also see that deployed, up-to-date antivirus signatures are ineffective. Which of the following is the BEST approach to prevent any impact to the company from similar attacks in the future?
- A. IDS signatures
- B. Data loss prevention
- C. Port security
- D. Sinkholing
Answer: A
NEW QUESTION # 105
Which of the following could be directly impacted by an unpatched vulnerability in vSphere ESXi?
- A. The organization's mobile devices
- B. The organization's virtual infrastructure
- C. The organization's physical routers
- D. The organization's VPN
Answer: B
NEW QUESTION # 106
During an incident, a cybersecurity analyst found several entries in the web server logs that are related to an IP with a bad reputation . Which of the following would cause the analyst to further review the incident?
A)
B)
C)
D)
E)
- A. Option C
- B. Option E
- C. Option A
- D. Option B
- E. Option D
Answer: E
NEW QUESTION # 107
A system administrator who was using an account with elevated privileges deleted a large amount of log files generated by a virtual hypervisor in order to free up disk space.
These log files are needed by the security team to analyze the health of the virtual machines.
Which of the following compensating controls would help prevent this from reoccurring? (Select two.)
- A. Job rotation
- B. Personnel training
- C. Succession planning
- D. Separation of duties
- E. Mandatory vacation
Answer: B,D
NEW QUESTION # 108
A company's incident response team is handling a threat that was identified on the network. Security analysts have determined a web server is making multiple connections from TCP port 445 outbound to servers inside its subnet as well as at remote sites. Which of the following is the MOST appropriate next step in the incident response plan?
- A. Capture a forensic image of the memory and disk
- B. Deploy virtual firewalls
- C. Quarantine the web server
- D. Enable web server containerization
Answer: C
Explanation:
Explanation/Reference:
NEW QUESTION # 109
A company recently experienced a break-in whereby a number of hardware assets were stolen through unauthorized access at the back of the building. Which of the following would BEST prevent this type of theft from occurring in the future?
- A. Perimeter fencing
- B. Badged entry
- C. Motion detection
- D. Monitored security cameras
Answer: C
NEW QUESTION # 110
An organizational policy requires one person to input accounts payable and another to do accounts receivable. A separate control requires one person to write a check and another person to sign all checks greater than $5,000 and to get an additional signature for checks greater than $10,000. Which of the following controls has the organization implemented?
- A. Job rotation
- B. Non-repudiaton
- C. Dual control
- D. Segregation of duties
Answer: C
NEW QUESTION # 111
Which of the following is MOST important when developing a threat hunting program?
- A. Understanding penetration testing techniques
- B. Understanding assets and categories of assets
- C. Understanding security software technologies
- D. Understanding how to build correlation rules within a SIEM
Answer: C
Explanation:
Explanation
https://www.stickmancyber.com/cybersecurity-blog/7-threat-hunting-misconceptions
https://www.simplilearn.com/skills-to-become-threat-hunter-article
NEW QUESTION # 112
While conducting a network infrastructure review, a security analyst discovers a laptop that is plugged into a core switch and hidden behind a desk.
The analyst sees the following on the laptop's screen:
Which of the following is the BEST action for the security analyst to take?
- A. Initiate a scan of devices on the network to find password-cracking tools.
- B. Disconnect the laptop and ask the users jsmith and progers to log out.
- C. Take the FILE-SHARE-A server offline and scan it for viruses.
- D. Force all users in the domain to change their passwords at the next login.
Answer: C
NEW QUESTION # 113
A network attack that is exploiting a vulnerability in the SNMP is detected.
Which of the following should the cybersecurity analyst do FIRST?
- A. Apply the required patches to remediate the vulnerability.
- B. Temporarily block the attacking IP address.
Section: (none)
Explanation - C. Escalate the incident to senior management for guidance.
- D. Disable all privileged user accounts on the network.
Answer: A
Explanation:
Reference:
https://beyondsecurity.com/scan-pentest-network-vulnerabilities-snmp-protocol-version- detection.html
NEW QUESTION # 114
A cybersecurity analyst is responding to an incident. The company's leadership team wants to attribute the incident to an attack group. Which of the following models would BEST apply to the situation?
- A. MITRE ATT&CK
- B. Kill chain
- C. Intelligence cycle
- D. Diamond Model of Intrusion Analysis
Answer: B
NEW QUESTION # 115
The majority of a company's employees have stated they are unable to perform their job duties due to outdated workstations, so the company has decided to institute BYOD. Which of the following would a security analyst MOST likely recommend for securing the proposed solution?
- A. A firewalled environment for client devices and a secure VDl for BYOO users
- B. A Linux-based system and mandatory training on Linux for all BYOD users
- C. A standardized anti-malware platform and a unified operating system vendor
- D. 802.1X lo enforce company policy on BYOD user hardware
Answer: A
Explanation:
Explanation
VDI means virtual desktop interface. Using VDI, you can maintain a standard image and remove the threat of an infected machine plugging into your network.
NEW QUESTION # 116
An analyst is working on a method to allow secure access to a highly sensi-tive server. The solution must allow named individuals remote access to data contained on the box and must limit access to a single IP address. Which of the following solutions would best meet these requirements?
- A. Software-defined networking
- B. VLAN
- C. Jump box
- D. ACL
Answer: C
Explanation:
A jump box is a secure computer that can be used to access a remote server or network. It acts as an intermediary between the user and the target system, and can limit access to specific IP addresses. A jump box can also provide logging and auditing of the user's actions on the remote system. A jump box is a common solution for accessing highly sensitive servers or networks1.
NEW QUESTION # 117
While reviewing log files, a security analyst uncovers a brute-force attack that is being performed against an external webmail portal. Which of the following would be BEST to prevent this type of attack from beinq successful1?
- A. Configure a WAF with brute force protection rules in block mode
- B. Leverage password filters to prevent weak passwords on employee accounts from being exploited.
- C. Implement MFA on the email portal using out-of-band code delivery.
- D. Create a new rule in the IDS that triggers an alert on repeated login attempts
- E. Alter the lockout policy to ensure users are permanently locked out after five attempts.
Answer: E
NEW QUESTION # 118
NOTE: Question IP must be 192.168.192.123
During a network reconnaissance engagement, a penetration tester was given perimeter firewall ACLs to accelerate the scanning process. The penetration tester has decided to concentrate on trying to brute force log in to destination IP address 192.168.192.132 via secure shell.
Given a source IP address of 10.10.10.30, which of the following ACLs will permit this access?
- A.

- B.

- C.

- D.

Answer: D
NEW QUESTION # 119
Which of the following BEST explains the function of a managerial control?
- A. To guide the development of training, education, security awareness programs, and system maintenance
- B. To create data classification, risk assessments, security control reviews, and contingency planning
- C. To ensure tactical design, selection of technology to protect data, logical access reviews, and the implementation of audit trails
- D. To help design and implement the security planning, program development, and maintenance of the security life cycle
Answer: B
Explanation:
Managerial controls are procedural mechanisms that focus on the mechanics of the risk management process. Examples of administrative controls include periodic risk assessments, security planning exercises, and the incorporation of security into the organization's change management, service acquisition, and project management practices
NEW QUESTION # 120
An application server runs slowly and then triggers a high CPU alert. After investigating, a security analyst finds an unauthorized program is running on the server. The analyst reviews the application log below.
Which of the following conclusions is supported by the application log?
- A. An attacker was attempting to perform a buffer overflow attack to execute a payload in memory.
- B. An attacker was attempting to perform a DoS attack against the server.
- C. An attacker was attempting to download files via a remote command execution vulnerability
- D. An attacker was attempting to perform an XSS attack via a vulnerable third-party library.
Answer: A
NEW QUESTION # 121
A routine vulnerability scan detected a known vulnerability in a critical enterprise web application. Which of the following would be the BEST next step?
- A. Notify a manager of the breach and initiate emergency procedures.
- B. Remove the application from production and Inform the users.
- C. Submit a change request to have the system patched
- D. Evaluate the risk and criticality to determine it further action is necessary
Answer: C
NEW QUESTION # 122
While investigating an incident in a company's SIEM console, a security analyst found hundreds of failed SSH login attempts, which all occurred in rapid succession. The failed attempts were followed by a successful login on the root user Company policy allows systems administrators to manage their systems only from the company's internal network using their assigned corporate logins. Which of the following are the BEST actions the analyst can take to stop any further compromise? (Select TWO).
- A. Add a rule on the network IPS to block SSH user sessions
- B. Add a rule on the perimeter firewall to block the source IP address.
- C. Configure /etc/sshd_config to deny root logins and restart the SSHD service.
- D. Add a rule on the affected system to block access to port TCP/22.
- E. Configure /etc/passwd to deny root logins and restart the SSHD service.
- F. Reset the passwords for all accounts on the affected system.
Answer: B,C
NEW QUESTION # 123
External users are reporting that a web application is slow and frequently times out when attempting to submit information.
Which of the following software development best practices would have helped prevent this issue?
- A. Input validation
- B. Fuzzing
- C. Regression testing
- D. Stress testing
Answer: D
NEW QUESTION # 124
While reviewing three months of logs, a security analyst notices probes from random company laptops going to SCADA equipment at the company's manufacturing location. Some of the probes are getting responses from the equipment even though firewall rules are in place, which should block this type of unauthorized activity. Which of the following should the analyst recommend to keep this activity from originating from company laptops?
- A. Install security software and a host-based firewall on the SCADA equipment.
- B. Implement a group policy on company systems to block access to SCADA networks.
- C. Update the firewall rules to block SCADA network access from those laptop IP addresses.
- D. Require connections to the SCADA network to go through a forwarding proxy.
Answer: B
NEW QUESTION # 125
Which of the following are essential components within the rules of engagement for a penetration test? (Select TWO).
- A. Business justification
- B. Schedule
- C. Payment terms
- D. List of system administrators
- E. Authorization
Answer: B,E
NEW QUESTION # 126
......
Pass CompTIA CS0-002 Exam Quickly With ActualTorrent: https://www.actualtorrent.com/CS0-002-questions-answers.html
CS0-002 Exam Questions (Updated 2024) 100% Real Question Answers: https://drive.google.com/open?id=1_vl_Zwp2CamR3pJBEs9iRH6bY_X1RPZE