Summer Sale Limited Time 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = simple75

Pass the CompTIA CySA+ CS0-004 Questions and answers with Dumpstech

Exam CS0-004 Premium Access

View all detail and faqs for the CS0-004 exam

Practice at least 50% of the questions to maximize your chances of passing.
Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions
Questions # 1:

Which of the following best explains the purpose of the Pyramid of Pain in threat intelligence?

Options:

A.

To show that changing to different types of indicators and behaviors is difficult for an adversary

B.

To measure how much operational damage a threat actor can cause before detection occurs

C.

To compare open-source intelligence (OSINT) with closed-source intelligence based on collection cost

D.

To organize attack activity into categories such as spoofing, tampering, and repudiation

Questions # 2:

A cybersecurity analyst is reviewing static application security testing scan results and notices a finding for hard-coded credentials.

Which of the following should the analyst recommend to the application team to resolve this concern?

Options:

A.

Implement a privileged access management solution.

B.

Enable single sign-on.

C.

Obfuscate application programming interface keys.

D.

Integrate secrets management.

Questions # 3:

A systems administrator is reviewing the output of a vulnerability scan.

INSTRUCTIONS -

Review the information in each tab.

Based on the organization’s environment architecture and remediation standards, select the server to be patched within 14 days and select the appropriate technique and mitigation.

If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

Question # 3

Question # 3

Question # 3

Question # 3

Options:

Questions # 4:

Which of the following network architectures would best implement a perimeter-less network topology?

Options:

A.

Hybrid cloud networks

B.

Secure access service edge

C.

Cloud-native computing

D.

Content delivery networks

Questions # 5:

A security operations center (SOC) analyst investigates the results of a password spray test conducted by the vulnerability management team.

The analyst must:

Question # 5

Identify Linux systems that have successful and unsuccessful logins with username "User1".

Create an output report named "linux-events" of all the events to a flat file.

The analyst issues the following console command:

ls /var/log/

The shortened output of the command is below:

Which of the following commands should the analyst use to meet the report output requirements?

Options:

A.

cat /var/log/sssd | grep "User1" > linux-events.txt

B.

cat /var/log/faillog.log | grep "User1" > linux-events.txt

C.

cat /var/log/syslog | grep "User1" > linux-events.txt

D.

cat /var/log/auth.log | grep "User1" > linux-events.txt

Questions # 6:

A public threat intelligence report includes indicators of compromise (IoCs) for threat actors. The threat actors are exploiting a zero-day vulnerability that the vendor has not fixed.

Which of the following techniques should be used until a patch is available?

Options:

A.

Sinkholing

B.

Eradication techniques

C.

Continuous monitoring

D.

Evidence acquisition

Questions # 7:

A vulnerability scanner shows discrepancies between the number of Internet Protocol (IP) addresses across the sites being scanned and the number of systems reporting into the patching system.

Which of the following actions will resolve this issue?

Options:

A.

Enable verbose logging in the scanner and check for failures.

B.

Rebuild the vulnerability report selection criteria to account for all sites.

C.

Request the infrastructure team rerun patching deployments.

D.

Conduct a comprehensive asset inventory with the infrastructure team.

Questions # 8:

Which of the following is the most comprehensive type of report associated with a closed incident?

Options:

A.

Lessons-learned

B.

Situation

C.

Root cause analysis

D.

After action

Questions # 9:

Which of the following allows an organization to leverage AI in various forms while protecting business objectives and data?

Options:

A.

Usage policies

B.

Prompt engineering

C.

Non-disclosure agreement

D.

Incident response policy

Questions # 10:

A security analyst responds to an alert regarding identity and access management activity within the cloud environment. The attacker is currently trying to gain access from one isolated cloud subscription to another via a compromised user role.

Which of the following aspects of the MITRE ATT & CK framework is the attacker trying to perform?

Options:

A.

Privilege escalation

B.

Lateral movement

C.

Persistence

D.

Execution

E.

Credential access

Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions