Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

CompTIA CS0-004 - CompTIA Cybersecurity Analyst CySA+ V4 (New Version)

Page: 3 / 3
Total 82 questions

Which of the following is the most important component to include in the preparation phase of an incident response plan?

A.

Roles and responsibilities

B.

After action reports

C.

Data integrity validation

D.

Chain of custody

A security operations center (SOC) analyst investigates the results of a password spray test conducted by the vulnerability management team.

The analyst must:

Identify Linux systems that have successful and unsuccessful logins with username "User1".

Create an output report named "linux-events" of all the events to a flat file.

The analyst issues the following console command:

ls /var/log/

The shortened output of the command is below:

Which of the following commands should the analyst use to meet the report output requirements?

A.

cat /var/log/sssd | grep "User1" > linux-events.txt

B.

cat /var/log/faillog.log | grep "User1" > linux-events.txt

C.

cat /var/log/syslog | grep "User1" > linux-events.txt

D.

cat /var/log/auth.log | grep "User1" > linux-events.txt

Which of the following does a phishing campaign click rate measure?

A.

The effectiveness of an organization's email filters

B.

The false-positive rate of data leakage prevention behavior

C.

The employees' security awareness

D.

The speed of responding to a social engineering attack

A security analyst receives a notice about a possible data breach. The report identifies unapproved, current access dates for files found in the following personnel archives:

Which of the following actions should the analyst take first?

A.

Perform log correlation.

B.

Reset user credentials.

C.

Restore files from backup.

D.

Establish a timeline.

E.

Establish a legal hold.