Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

CompTIA CS0-004 - CompTIA Cybersecurity Analyst CySA+ V4 (New Version)

Page: 2 / 3
Total 82 questions

An analyst reviews the following system logs from a recent breach attempt:

Which of the following techniques did the attacker attempt to use?

A.

Exfiltration

B.

Remote code execution

C.

Privilege escalation

D.

Spoofing

Which of the following best explains why sensitive data should be encrypted at rest on laptops?

A.

To prevent end users from copying data to other systems

B.

To protect disclosure of information if physical devices are stolen

C.

To comply with regulatory and legal requirements

D.

To ensure the integrity of the data on the company network

A cybersecurity analyst receives an unstructured text document that contains advanced persistent threat (APT)-related indicators of compromise (IoCs). The analyst needs to extract the IPv4 addresses.

Which of the following is the best tool to accomplish this task?

A.

CyberChef

B.

Wireshark

C.

Zeek

D.

Open Cyber Threat Intelligence (OpenCTI)

A security team deploys a new scanning solution that requires root, domain administrator, and local server administrator permissions on all systems.

Which of the following is the best way to help mitigate the risk for this level of access?

A.

Enabling single sign-on for all administrators

B.

Integrating token-based authentication using a privileged access management (PAM) solution

C.

Using temporary, one-time passwords as part of the login process

D.

Configuring agentless scanning for critical targets

Which of the following is the most comprehensive type of report associated with a closed incident?

A.

Lessons-learned

B.

Situation

C.

Root cause analysis

D.

After action

A security operations center (SOC) manager reviews a document signed by the Chief Financial Officer (CFO), the sales director, and a customer to decide whether a contract breach occurred.

Which of the following best describes the document that includes key performance indicators (KPIs)?

A.

Tactics, techniques, and procedures (TTPs)

B.

Return on investment report

C.

Service-level agreement (SLA)

D.

Risk management plan

E.

Memorandum of understanding

Which of the following best describes a type of risk that exists after mitigations or controls are enacted and implemented?

A.

Residual

B.

Acceptable

C.

Inherent

D.

Appropriate

Which of the following is the most important reason why tactics, techniques, and procedures (TTP) are beneficial to a defensive strategy?

A.

TTP provides useful insights on the hash values and internet protocol addresses attributed to an attacker.

B.

TTP provides useful insights on an attacker's indicators of compromise.

C.

TTP provides useful insights on the tools used by an attacker.

D.

TTP provides useful insights on the strategy and behavior of an attacker.

Which of the following is the main concept behind the use of an attack methodology framework?

A.

Implementing continuous monitoring and rapid deployment of system fixes over the traditional patch, test, and deploy approach

B.

Prioritizing vulnerabilities that can be exploited based on risk calculations and using the consequences and likelihood of the exploits to determine where resources should be allocated

C.

Approaching cybersecurity from the perspective of a threat actor and using their common behaviors and motivations to identify secure solutions

D.

Applying a Zero Trust environment by assuming networks and systems are vulnerable to malicious actions by both external, hostile adversaries and insider threats

The Chief Information Security Officer (CISO) reviews the following security operations metrics from the last month:

Which of the following is the best action to improve overall security operations efficiency?

A.

Leverage a cloud security posture management tool to add asset context to alerts.

B.

Analyze and tune the detections that are causing non-actionable alerts.

C.

Implement playbooks for the junior analysts to use during investigations.

D.

Perform internal incident training on the most common alerts from security information and event management (SIEM).