Summer Sale Limited Time 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = simple75

Pass the CompTIA CySA+ CS0-004 Questions and answers with Dumpstech

Exam CS0-004 Premium Access

View all detail and faqs for the CS0-004 exam

Practice at least 50% of the questions to maximize your chances of passing.
Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions
Questions # 11:

Which of the following best describes a type of risk that exists after mitigations or controls are enacted and implemented?

Options:

A.

Residual

B.

Acceptable

C.

Inherent

D.

Appropriate

Questions # 12:

A security architect works with a client on security operations center (SOC) capabilities. The security architect wants to ensure the log correlation and investigation activities are accurate across the infrastructure.

Which of the following is the best for the client to implement?

Options:

A.

Network Time Protocol (NTP)

B.

Zero Trust Network Access (ZTNA)

C.

Account federation

D.

Secure access service edge (SASE)

E.

Application programming interfaces (APIs)

Questions # 13:

A Chief Information Security Officer (CISO) is notified of an ongoing incident.

Which of the following explains why the CISO instructs the Chief Executive Officer not to discuss the incident over email?

Options:

A.

The security team discovered a vulnerability in the Short Message Service email gateway.

B.

The email system may be compromised.

C.

Emails are not encrypted in transit.

D.

The CISO has not notified the public relations team of the incident.

Questions # 14:

An analyst reviews the following log entries:

Question # 14

Which of the following conclusions should the analyst reach? (Choose two.)

Options:

A.

Host ws-57 is performing a network scan against dc-1.

B.

Domain Controller dc-1 is performing a network scan against ws-57.

C.

Host ws-57 delivered a phishing email via Simple Mail Transfer Protocol.

D.

Host ws-57 is communicating on a service using a non-standard port.

E.

Domain Controller dc-1 is infected with ransomware and initiating connections with ws-57.

F.

Domain Controller dc-1 is communicating using a non-standard port.

Questions # 15:

An analyst receives an alert that a user clicked on a malicious link. The analyst verifies that the link is malicious and was intended to capture credentials. The analyst verifies that the user visited the website, but no evidence indicates that the credentials were used. The analyst recommends that the user take remedial training and closes the case.

Which of the following steps in the incident response process did the analyst neglect?

Options:

A.

Analysis

B.

Containment

C.

Recovery

D.

Post-incident

Questions # 16:

Which of the following does a phishing campaign click rate measure?

Options:

A.

The effectiveness of an organization's email filters

B.

The false-positive rate of data leakage prevention behavior

C.

The employees' security awareness

D.

The speed of responding to a social engineering attack

Questions # 17:

The Chief Information Officer (CIO) is requiring users to phase out a legacy system that no longer receives security updates because the system will be decommissioned soon.

Which of the following risk management strategies is the CIO using?

Options:

A.

Avoidance

B.

Mitigation

C.

Acceptance

D.

Transference

Questions # 18:

Based on recent alerts, a security analyst thinks a web application server was compromised. The analyst reviews the following server output:

Question # 18

Which of the following best describes what has occurred?

Options:

A.

An initiated unauthorized session

B.

Too many users logged in at the same time

C.

High resource consumption

D.

Abnormal idle times for each user

Questions # 19:

An analyst executes the top command on a Linux system for an unresponsive application and observes the following output:

Question # 19

Which of the following is the most likely cause of this issue?

Options:

A.

Service disruption

B.

Unauthorized software

C.

Resource exhaustion

D.

Filesystem changes

Questions # 20:

A security operations center manager is concerned that after action reporting is not being completed in a timely manner.

Which of the following will allow the manager to quantify this concern?

Options:

A.

Mean time to remediate

B.

Mean time to close

C.

Mean time between failures

D.

Mean time to respond

Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions