[Nov 22, 2021] Latest CS0-002 PDF Dumps & Real Tests Free Updated Today [Q29-Q49]

Share

[Nov 22, 2021]  Latest CS0-002 PDF Dumps & Real Tests Free Updated Today

CS0-002 Dumps With 100% Verified Q&As - Pass Guarantee or Full Refund

NEW QUESTION 29
A security engineer has been asked to reduce the attack surface on an organization's production environment. To limit access, direct VPN access to all systems must be terminated, and users must utilize multifactor authentication to access a constrained VPN connection and then pivot to other production systems form a bastion host. The MOST appropriate way to implement the stated requirement is through the use of a:

  • A. sinkhole.
  • B. jump box
  • C. multitenant platform.
  • D. single-tenant platform.

Answer: B

 

NEW QUESTION 30
How many phases does the Spiral model cycle through?

  • A. Five
  • B. Four
  • C. Six
  • D. Three

Answer: B

 

NEW QUESTION 31
While planning segmentation for an ICS environment, a security engineer determines IT resources will need access to devices within the ICS environment without compromising security.
To provide the MOST secure access model in this scenario, the jumpbox should be .

  • A. bridged between the IT and operational technology networks to allow authenticated access.
  • B. placed on the IT side of the network, authenticated, and tunneled into the ICS environment.
  • C. placed on the ICS network with a static firewall rule that allows IT network resources to authenticate.
  • D. placed in an isolated network segment, authenticated on the IT side, and forwarded into the ICS network.

Answer: D

 

NEW QUESTION 32
A security analyst is conducting a post-incident log analysis to determine which indicators can be used to detect further occurrences of a data exfiltration incident. The analyst determines backups were not performed during this time and reviews the following:

Which of the following should the analyst review to find out how the data was exfilltrated?

  • A. Tuesday's logs
  • B. Thursday's logs
  • C. Monday's logs
  • D. Wednesday's logs

Answer: B

 

NEW QUESTION 33
An insurance company employs quick-response team drivers that carry corporate-issued mobile devices with the insurance company's app installed on them. Devices are configuration-hardened by an MDM and kept up to date. The employees use the app to collect insurance claim information and process payments. Recently, a number of customers have filed complaints of credit card fraud against the insurance company, which occurred shortly after their payments were processed via the mobile app. The cyber-incident response team has been asked to investigate. Which of the following is MOST likely the cause?

  • A. The app does not employ TLS.
  • B. USB tethering is enabled.
  • C. 3G and less secure cellular technologies are not restricted.
  • D. The MDM server is misconfigured.

Answer: A

 

NEW QUESTION 34
A security analyst working in the SOC recently discovered Balances m which hosts visited a specific set of domains and IPs and became infected with malware. Which of the following is the MOST appropriate action to take in the situation?

  • A. implement an IPS signature for the malware and update the blacklisting for the associated domains and IPs
  • B. Implement an IPS signature for the malware and another signature request to Nock all the associated domains and IPs
  • C. Implement a change request to the firewall setting to not allow traffic to and from the IPs and domains
  • D. Implement an IPS signature for the malware and a change request to the firewall setting to not allow traffic to and from the IPs and domains

Answer: C

 

NEW QUESTION 35
A security analyst is reviewing the following web server log:
GET %2f..%2f..%2f.. %2f.. %2f.. %2f.. %2f../etc/passwd
Which of the following BEST describes the issue?

  • A. SQL injection
  • B. Cross-site scripting
  • C. Directory traversal exploit
  • D. Cross-site request forgery

Answer: C

 

NEW QUESTION 36
A security analyst is investigating a compromised Linux server. The analyst issues the ps command and receives the following output.

Which of the following commands should the administrator run NEXT to further analyze the compromised system?

  • A. /bin/la -1 /proc/1301/exe
  • B. rpm -V openash-server
  • C. strace /proc/1301
  • D. kill -9 1301

Answer: C

 

NEW QUESTION 37
A human resources employee sends out a mass email to all employees that contains their personnel records. A security analyst is called in to address the concern of the human resources director on how to prevent this from happening in the future.
Which of the following would be the BEST solution to recommend to the director?

  • A. Train all employees. Encrypt data sent on the company network. Bring in privacy personnel to present a plan on how PII should be handled.
  • B. Enforce encryption on all emails sent within the company. Create a PII program and policy on how to handle data. Train all human resources employees.
  • C. Install specific equipment to create a human resources policy that protects PII data. Train company employees on how to handle PII data. Outsource all PII to another company. Send the human resources director to training for PII handling.
  • D. Install a data loss prevention system, and train human resources employees on its use.
    Provide PII training to all employees at the company. Encrypt PII information.

Answer: D

 

NEW QUESTION 38
An analyst has initiated an assessment of an organization's security posture.
As a part of this review, the analyst would like to determine how much information about the organization is exposed externally.
Which of the following techniques would BEST help the analyst accomplish this goal? (Select two.)

  • A. Banner grabbing
  • B. Sourcing social network sites
  • C. DNS query log reviews
  • D. Technical control audits
  • E. Intranet portal reviews
  • F. Fingerprinting
  • G. Internet searches

Answer: B,F

 

NEW QUESTION 39
A critical server was compromised by malware, and all functionality was lost. Backups of this server were taken; however, management believes a logic bomb may have been injected by a rootkit. Which of the following should a security analyst perform to restore functionality quickly?

  • A. Stand up a new server and restore critical data from backups
  • B. Offload the critical data to a new server and continue operations
  • C. Restore the previous backup and scan with a live boot anti-malware scanner
  • D. Work backward, restoring each backup until the server is clean

Answer: A

 

NEW QUESTION 40
An analyst is investigating an anomalous event reported by the SOC After reviewing the system logs the analyst identifies an unexpected addition of a user with root-level privileges on the endpoint. Which of the following data sources will BEST help the analyst to determine whether this event constitutes an incident?

  • A. Backup logs
  • B. Patching logs
  • C. Change requests
  • D. Data classification matrix
  • E. Threat feed

Answer: C

 

NEW QUESTION 41
A company wants to reduce the cost of deploying servers to support increased network growth. The company is currently unable to keep up with the demand, so it wants to outsource the infrastructure to a cloud-based solution.
Which of the following is the GREATEST threat for the company to consider when outsourcing its infrastructure?

  • A. The cloud service provider is unable to issue sufficient documentation for configurations.
  • B. The cloud service provider is unable to provide sufficient logging and monitoring.
  • C. The cloud service provider conducts a system backup each weekend and once a week during peak business times.
  • D. The cloud service provider has an SLA for system uptime that is lower than 99 9%.

Answer: A

 

NEW QUESTION 42
A security analyst wants to scan the network for active hosts. Which of the following host characteristics help to differentiate between a virtual and physical host?

  • A. Gateway settings
  • B. Reserved MACs
  • C. DNS routing tables
  • D. Host IPs

Answer: B

 

NEW QUESTION 43
An organization needs to limit its exposure to accidental disclosure when employees send emails that contain personal information to recipients outside the company Which of the following technical controls would BEST accomplish this goal?

  • A. DLP
  • B. Encryption
  • C. SPF
  • D. Data masking

Answer: A

 

NEW QUESTION 44
During an investigation, an incident responder intends to recover multiple pieces of digital media. Before removing the media, the responder should initiate:

  • A. chain of custody forms.
  • B. secure communications.
  • C. decryption tools.
  • D. malware scans.

Answer: A

 

NEW QUESTION 45
A company has implemented WPA2, a 20-character minimum for the WiFi passphrase, and a new WiFi passphrase every 30 days, and has disabled SSID broadcast on all wireless access points. Which of the following is the company trying to mitigate?

  • A. Downgrade attacks
  • B. SSL pinning
  • C. Forced deauthentication
  • D. Rainbow tables

Answer: A

 

NEW QUESTION 46
After running a packet analyzer on the network, a security analyst has noticed the following output:

Which of the following is occurring?

  • A. A port scan
  • B. A service discovery
  • C. A ping sweep
  • D. A network map

Answer: A

 

NEW QUESTION 47
A cybersecurity analyst is investigating an incident report concerning a specific user workstation.
The workstation is exhibiting high CPU and memory usage, even when first started, and network bandwidth usage is extremely high. The user reports that applications crash frequently, despite the fact that no significant changes in work habits have occurred. An antivirus scan reports no known threats. Which of the following is the MOST likely reason for this?

  • A. Zero day
  • B. Trojan
  • C. Advanced persistent threat
  • D. Logic bomb

Answer: A

 

NEW QUESTION 48
An analyst is conducting a log review and identifies the following snippet in one of the logs:

Which of the following MOST likely caused this activity?

  • A. SQL injection
  • B. Privilege escalation
  • C. Brute force
  • D. Forgotten password

Answer: C

 

NEW QUESTION 49
......

2021 Valid CS0-002  test answers & CompTIA Exam PDF: https://www.test4sure.com/CS0-002-pass4sure-vce.html

Pass CompTIA CS0-002 Exam With  Practice Test Questions Dumps Bundle: https://drive.google.com/open?id=1118Fd8ZxpIW0VB6-3Z9SusoRGkop3h3v