Leads4pass > CompTIA > CompTIA Certifications > CS0-003 > CS0-003 Online Practice Questions and Answers

CS0-003 Online Practice Questions and Answers

Questions 4

A new cybersecurity analyst is tasked with creating an executive briefing on possible threats to the organization. Which of the following will produce the data needed for the briefing?

A. Firewall logs

B. Indicators of compromise

C. Risk assessment

D. Access control lists

Buy Now
Questions 5

A company is aiming to test a new incident response plan. The management team has made it clear that the initial test should have no impact on the environment. The company has limited resources to support testing. Which of the following exercises would be the best approach?

A. Tabletop scenarios

B. Capture the flag

C. Red team vs. blue team

D. Unknown-environment penetration test

Buy Now
Questions 6

An end-of-life date was announced for a widely used OS. A business-critical function is performed by some machinery that is controlled by a PC, which is utilizing the OS that is approaching the end-of-life date. Which of the following best describes a security analyst's concern?

A. Any discovered vulnerabilities will not be remediated.

B. An outage of machinery would cost the organization money.

C. Support will not be available for the critical machinery.

D. There are no compensating controls in place for the OS.

Buy Now
Questions 7

An incident response analyst is taking over an investigation from another analyst. The investigation has been going on for the past few days. Which of the following steps is most important during the transition between the two analysts?

A. Identify and discuss the lessons learned with the prior analyst.

B. Accept all findings and continue to investigate the next item target.

C. Review the steps that the previous analyst followed.

D. Validate the root cause from the prior analyst.

Buy Now
Questions 8

A security analyst is responding to an incident that involves a malicious attack on a network data closet. Which of the following best explains how the analyst should properly document the incident?

A. Back up the configuration file for all network devices.

B. Record and validate each connection.

C. Create a full diagram of the network infrastructure.

D. Take photos of the impacted items.

Buy Now
Questions 9

During an incident, some IoCs of possible ransomware contamination were found in a group of servers in a segment of the network. Which of the following steps should be taken next?

A. Isolation

B. Remediation

C. Reimaging

D. Preservation

Buy Now
Questions 10

During a security test, a security analyst found a critical application with a buffer overflow vulnerability. Which of the following would be best to mitigate the vulnerability at the application level?

A. Perform OS hardening.

B. Implement input validation.

C. Update third-party dependencies.

D. Configure address space layout randomization.

Buy Now
Questions 11

Which of the following is a useful tool for mapping, tracking, and mitigating identified threats and vulnerabilities with the likelihood and impact of occurrence?

A. Risk register

B. Vulnerability assessment

C. Penetration test

D. Compliance report

Buy Now
Questions 12

An incident responder was able to recover a binary file through the network traffic. The binary file was also found in some machines with anomalous behavior. Which of the following processes most likely can be performed to understand the purpose of the binary file?

A. File debugging

B. Traffic analysis

C. Reverse engineering

D. Machine isolation

Buy Now
Questions 13

Which of the following is the most appropriate action a security analyst to take to effectively identify the most security risks associated with a locally hosted server?

A. Run the operating system update tool to apply patches that are missing.

B. Contract an external penetration tester to attempt a brute-force attack.

C. Download a vendor support agent to validate drivers that are installed.

D. Execute a vulnerability scan against the target host.

Buy Now
Exam Code: CS0-003
Exam Name: CompTIA Cybersecurity Analyst (CySA+)
Last Update: Jan 12, 2025
Questions: 490
10%OFF Coupon Code: SAVE10

PDF (Q&A)

$49.99

VCE

$55.99

PDF + VCE

$65.99