CompTIA CS0-004 - CompTIA Cybersecurity Analyst CySA+ V4 (New Version)
A security analyst uses a full pcap solution to extract all traffic from the last two days associated with the 10.213.4.27 file server.
This file server is under investigation due to concerns about potential data exfiltration using Domain Name System (DNS) traffic.
Which of the following commands should the analyst use to extract any potentially leaked data from the suspicious.pcap file?
A vulnerability analyst runs a credentialed vulnerability scan covering all addressable enterprise assets. After running the scan, the analyst discovers a large number of critical vulnerabilities that cannot be immediately remediated.
Which of the following are the most likely reasons why the vulnerabilities cannot be immediately addressed?
Which of the following best explains the purpose of the Pyramid of Pain in threat intelligence?
Which of the following occurs during the analysis phase of the incident response process?
Multiple users report unexpected mouse movements and terminal windows opening.
An analyst reviewing the network traffic logs observes the following:

Which of the following is the most likely reason for the reported symptoms?
A vulnerability analyst must perform a security assessment on an edge device running various services.
The analyst runs an Nmap port scan and sees the following output:

Which of the following should the analyst do next to validate the discovered remote access service is secure?
A Chief Information Security Officer (CISO) is notified of an ongoing incident.
Which of the following explains why the CISO instructs the Chief Executive Officer not to discuss the incident over email?
A vulnerability scanner shows discrepancies between the number of Internet Protocol (IP) addresses across the sites being scanned and the number of systems reporting into the patching system.
Which of the following actions will resolve this issue?
An analyst prepares an after action report following an incident in which multiple systems were compromised over several days.
The analyst provides raw event logs from each compromised system in the report and determines that a patient-zero system cannot be found.
Which of the following should the analyst do to determine the patient-zero system?
Despite removing malware from some of the affected hosts, several of an organization's internal resources are still unavailable two weeks after the discovery of a major incident.
Which of the following best describes this phase?
