It is impossible to pass CompTIA CS0-001 exam without any help in the short term. Come to us soon and find the most advanced, correct and guaranteed CS0-001 Dumps Questions. You will get a surprising result by our CS0-001 Study Guides.
Online CompTIA CS0-001 free dumps demo Below:
NEW QUESTION 1
An incident response report indicates a virus was introduced through a remote host that was connected to corporate resources. A cybersecurity analyst has been asked for a recommendation to solve this issue. Which of the following should be applied?
- A. MAC
- B. TAP
- C. NAC
- D. ACL
Answer: C
NEW QUESTION 2
The Chief Information Security Officer (CISO) asked for a topology discovery to be conducted and verified against the asset inventory. The discovery is failing and not providing reliable or complete data. The syslog shows the following information:
Which of the following describes the reason why the discovery is failing?
- A. The scanning tool lacks valid LDAP credentials.
- B. The scan is returning LDAP error code 52255a.
- C. The server running LDAP has antivirus deployed.
- D. The connection to the LDAP server is timing out.
- E. The LDAP server is configured on the wrong port.
Answer: A
NEW QUESTION 3
A security operations team was alerted to abnormal DNS activity coming from a user’s machine. The team performed a forensic investigation and discovered a host had been compromised. Malicious code was using DNS as a tunnel to extract data from the client machine, which had been leaked and transferred to an unsecure public Internet site. Which of the following BEST describes the attack?
- A. Phishing
- B. Pharming
- C. Cache poisoning
- D. Data exfiltration
Answer: D
NEW QUESTION 4
A computer has been infected with a virus and is sending out a beacon to command and control server through an unknown service. Which of the following should a security technician implement to drop the traffic going to the command and control server and still be able to identify the infected host through firewall logs?
- A. Sinkhole
- B. Block ports and services
- C. Patches
- D. Endpoint security
Answer: A
Explanation: reference
https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-DNS-Sinkhole/ta-p/58891
NEW QUESTION 5
The security operations team is conducting a mock forensics investigation. Which of the following should be the FIRST action taken after seizing a compromised workstation?
- A. Activate the escalation checklist
- B. Implement the incident response plan
- C. Analyze the forensic image
- D. Perform evidence acquisition
Answer: D
Explanation: Reference https://staff.washington.edu/dittrich/misc/forensics/
NEW QUESTION 6
A start member reported that a laptop has (traded performance. The security analyst has investigated the issue and discovered that CPU utilization, memory utilization. and outbound network traffic are consuming the laptop resources. Which of the following is the BEST course of action to resolve the problem?
- A. Identity and remove malicious processes.
- B. Disable scheduled tasks
- C. Suspend virus scan
- D. Increase laptop memory.
- E. Ensure the laptop OS is property patched
Answer: A
NEW QUESTION 7
A security analyst is reviewing IDS logs and notices the following entry:
Which of the following attacks is occurring?
- A. Cross-site scripting
- B. Header manipulation
- C. SQL injection
- D. XML injection
Answer: C
NEW QUESTION 8
After running a packet analyzer on the network, a security analyst has noticed the following output:
Which of the following is occurring?
- A. A ping sweep
- B. A port scan
- C. A network map
- D. A service discovery
Answer: B
NEW QUESTION 9
An HR employee began having issues with a device becoming unresponsive after attempting to open an email attachment. When informed, the security analyst became suspicious of the situation, even though there was not any unusual behavior on the IDS or any alerts from the antivirus software. Which of the following BEST describes the type of threat in this situation?
- A. Packet of death
- B. Zero-day malware
- C. PII exfiltration
- D. Known virus
Answer: B
NEW QUESTION 10
During a routine network scan, a security administrator discovered an unidentified service running on a new embedded and unmanaged HVAC controller, which is used to monitor the company’s datacenter:
The enterprise monitoring service requires SNMP and SNMPTRAP connectivity to operate. Which of the following should the security administrator implement to harden the system?
- A. Patch and restart the unknown service.
- B. Segment and firewall the controller’s network.
- C. Disable the unidentified service on the controller.
- D. Implement SNMPv3 to secure communication.
- E. Disable TCP/UDP ports 161 through 163.
Answer: A
NEW QUESTION 11
A security administrator determines several months after the first instance that a local privileged user has been routinely logging into a server interactively as “root” and browsing the Internet. The administrator determines this by performing an annual review of the security logs on that server. For which of the following security architecture areas should the administrator recommend review and modification? (Select TWO).
- A. Log aggregation and analysis
- B. Software assurance
- C. Encryption
- D. Acceptable use policies
- E. Password complexity
- F. Network isolation and separation
Answer: AD
NEW QUESTION 12
Which of the following represent the reasoning behind careful selection of the timelines and time-of-day boundaries for an authorized penetration test? (Select TWO).
- A. To schedule personnel resources required for test activities
- B. To determine frequency of team communication and reporting
- C. To mitigate unintended impacts to operations
- D. To avoid conflicts with real intrusions that may occur
- E. To ensure tests have measurable impact to operations
Answer: AC
NEW QUESTION 13
Creating a lessons learned report following an incident will help an analyst to communicate which of the following information? (Select TWO)
- A. Root cause analysis of the incident and the impact it had on the organization
- B. Outline of the detailed reverse engineering steps for management to review
- C. Performance data from the impacted servers and endpoints to report to management
- D. Enhancements to the policies and practices that will improve business responses
- E. List of IP addresses, applications, and assets
Answer: AD
NEW QUESTION 14
A cybersecurity analyst was hired to resolve a security issue within a company after it was reported that many employee account passwords had been compromised. Upon investigating the incident, the cybersecurity
analyst found that a brute force attack was launched against the company.
Which of the following remediation actions should the cybersecurity analyst recommend to senior management to address these security issues?
- A. Prohibit password reuse using a GPO.
- B. Deploy multifactor authentication.
- C. Require security awareness training.
- D. Implement DLP solution.
Answer: B
NEW QUESTION 15
Following a recent security breach, a post-mortem was done to analyze the driving factors behind the breach. The cybersecurity analysis discussed potential impacts, mitigations, and remediations based on current events and emerging threat vectors tailored to specific stakeholders. Which of the following is this considered to be?
- A. Threat intelligence
- B. Threat information
- C. Threat data
- D. Advanced persistent threats
Answer: A
NEW QUESTION 16
An organization has a practice of running some administrative services on non-standard ports as a way of frustrating any attempts at reconnaissance. The output of the latest scan on host 192.168.1.13 is shown below:
Which of the following statements is true?
- A. Running SSH on the Telnet port will now be sent across an unencrypted port.
- B. Despite the results of the scan, the service running on port 23 is actually Telnet and not SSH, and creates an additional vulnerability
- C. Running SSH on port 23 provides little additional security from running it on the standard port.
- D. Remote SSH connections will automatically default to the standard SSH port.
- E. The use of OpenSSH on its default secure port will supersede any other remote connection attempts.
Answer: C
NEW QUESTION 17
A cybersecurity analyst has received an alert that well-known “call home” messages are continuously observed by network sensors at the network boundary. The proxy firewall successfully drops the messages. After determining the alert was a true positive, which of the following represents the MOST likely cause?
- A. Attackers are running reconnaissance on company resources.
- B. An outside command and control system is attempting to reach an infected system.
- C. An insider is trying to exfiltrate information to a remote network.
- D. Malware is running on a company system.
Answer: B
NEW QUESTION 18
While conducting research on malicious domains, a threat intelligence analyst received a blue screen of death. The analyst rebooted and received a message stating that the computer had been locked and could only be opened by following the instructions on the screen. Which of the following combinations describes the MOST likely threat and the PRIMARY mitigation for the threat?
- A. Ransomware and update antivirus
- B. Account takeover and data backups
- C. Ransomware and full disk encryption
- D. Ransomware and data backups
Answer: D
Recommend!! Get the Full CS0-001 dumps in VCE and PDF From DumpSolutions, Welcome to Download: https://www.dumpsolutions.com/CS0-001-dumps/ (New 242 Q&As Version)
