Simulation CS0-001 Exam Questions and Answers 2021

Want to know CS0-001 Dumps features? Want to lear more about CS0-001 Dumps Questions experience? Study CS0-001 Free Practice Questions. Gat a success with an absolute guarantee to pass CompTIA CS0-001 (CompTIA CSA+ Certification Exam) test on your first attempt.

Online CompTIA CS0-001 free dumps demo Below:

NEW QUESTION 1
A SIEM analyst noticed a spike in activities from the guest wireless network to several electronic health record (EHR) systems. After further analysis, the analyst discovered that a large volume of data has been uploaded to a cloud provider in the last six months. Which of the following actions should the analyst do FIRST?

  • A. Contact the Office of Civil Rights (OCR) to report the breach
  • B. Notify the Chief Privacy Officer (CPO)
  • C. Activate the incident response plan
  • D. Put an ACL on the gateway router

Answer: D

NEW QUESTION 2
A company has implemented WPA2, a 20-character minimum for the WiFi passphrase. and a new WiFi passphrase every 30 days, and has disabled SSID broadcast on all wireless access points. Which of the following is the company trying to mitigate?

  • A. Downgrade attacks
  • B. Rainbow tables
  • C. SSL pinning
  • D. Forced deauthentication

Answer: A

NEW QUESTION 3
The board of directors made the decision to adopt a cloud-first strategy. The current security infrastructure was designed for on-premise implementation. A critical application that is subject to the Federal Information Security Management Act (FISMA) of 2002 compliance has been identified as a candidate for a hybrid cloud deployment model. Which of the following should be conducted FIRST?

  • A. Develop a request for proposal.
  • B. Perform a risk assessment.
  • C. Review current security controls.
  • D. Review the SLA for FISMA compliance.

Answer: C

NEW QUESTION 4
A system administrator who was using an account with elevated privileges deleted a large amount of log files generated by a virtual hypervisor in order to free up disk space. These log files are needed by the security team to analyze the health of the virtual machines. Which of the following compensating controls would help prevent this from reoccurring? (Select two.)

  • A. Succession planning
  • B. Separation of duties
  • C. Mandatory vacation
  • D. Personnel training
  • E. Job rotation

Answer: BD

NEW QUESTION 5
A newly discovered malware has a known behavior of connecting outbound to an external destination on port 27500 for the purpose of exfiltrating data. The following are four snippets taken from running netstat –an on separate Windows workstations:
CS0-001 dumps exhibit
CS0-001 dumps exhibit
CS0-001 dumps exhibit
CS0-001 dumps exhibit
Based on the above information, which of the following is MOST likely to be exposed to this malware?

  • A. Workstation A
  • B. Workstation B
  • C. Workstation C
  • D. Workstation D

Answer: A

NEW QUESTION 6
A vulnerability scan has returned the following information:
CS0-001 dumps exhibit
Which of the following describes the meaning of these results?

  • A. There is an unknown bug in a Lotus server with no Bugtraq ID.
  • B. Connecting to the host using a null session allows enumeration of share names.
  • C. Trend Micro has a known exploit that must be resolved or patched.
  • D. No CVE is present, so it is a false positive caused by Lotus running on a Windows server.

Answer: B

NEW QUESTION 7
A security analyst is reviewing packet captures for a specific server that is suspected of containing malware and discovers the following packets:
CS0-001 dumps exhibit
Which of the following traffic patterns or data would be MOST concerning to the security analyst?

  • A. Ports used for SMTP traffic from 73.252.34.101
  • B. Unencrypted password sent from 103.34.243.12
  • C. Anonymous access granted by 103.34.243.12
  • D. Ports used HTTP traffic from 202.53.245.78

Answer: C

NEW QUESTION 8
A security analyst is creating ACLs on a perimeter firewall that will deny inbound packets that are from internal addresses, reserved external addresses, and multicast addresses. Which of the following is the analyst attempting to prevent/

  • A. Broadcast storms
  • B. Spoofing attacks
  • C. UDoS attacks
  • D. Man in-the-middle attacks

Answer: B

NEW QUESTION 9
A cybersecurity analyst was asked to discover the hardware address of 30 networked assets. From a command line, which of the following tools would be used to provide ARP scanning and reflects the MOST efficient method for accomplishing the task?

  • A. nmap
  • B. tracert
  • C. ping –a
  • D. nslookup

Answer: A

Explanation: Reference
https://serverfault.com/questions/10590/how-to-get-a-list-of-all-ip-addresses-and-ideally-device-names-on-a-lan

NEW QUESTION 10
A security analyst is concerned that employees may attempt to exfiltrate data prior to tendering their resignations. Unfortunately, the company cannot afford to purchase a data loss prevention (DLP) system. Which of the following recommendations should the security analyst make to provide defense-in-depth against data loss? (Select THREE).

  • A. Prevent users from accessing personal email and file-sharing sites via web proxy
  • B. Prevent flash drives from connecting to USB ports using Group Policy
  • C. Prevent users from copying data from workstation to workstation
  • D. Prevent users from using roaming profiles when changing workstations
  • E. Prevent Internet access on laptops unless connected to the network in the office or via VPN
  • F. Prevent users from being able to use the copy and paste functions

Answer: ABE

NEW QUESTION 11
Scan results identify critical Apache vulnerabilities on a company’s web servers. A security analyst believes many of these results are false positives because the web environment mostly consists of Windows servers.
Which of the following is the BEST method of verifying the scan results?

  • A. Run a service discovery scan on the identified servers.
  • B. Refer to the identified servers in the asset inventory.
  • C. Perform a top-ports scan against the identified servers.
  • D. Review logs of each host in the SIEM.

Answer: A

NEW QUESTION 12
A company has been a victim of multiple volumetric DoS attacks. Packet analysis of the offending traffic shows the following:
CS0-001 dumps exhibit
Which of the following mitigation techniques is MOST effective against the above attack?

  • A. The company should contact the upstream ISP and ask that RFC1918 traffic be dropped.
  • B. The company should implement a network-based sinkhole to drop all traffic coming from 192.168.1.1 at their gateway router.
  • C. The company should implement the following ACL at their gateway firewall:DENY IP HOST 192.168.1.1 170.43.30.0/24.
  • D. The company should enable the DoS resource starvation protection feature of the gateway NIPS.

Answer: A

Explanation: Topic 3, Exam Set C

NEW QUESTION 13
Which of the following policies BEST explains the purpose of a data ownership policy?

  • A. The policy should describe the roles and responsibilities between users and managers, and the management of specific data types.
  • B. The policy should establish the protocol for retaining information types based on regulatory or business needs.
  • C. The policy should document practices that users must adhere to in order to access data on the corporate network or Internet.
  • D. The policy should outline the organization’s administration of accounts for authorized users to access the appropriate data.

Answer: D

NEW QUESTION 14
After completing a vulnerability scan, the following output was noted:
CS0-001 dumps exhibit
Which of the following vulnerabilities has been identified?

  • A. PKI transfer vulnerability.
  • B. Active Directory encryption vulnerability.
  • C. Web application cryptography vulnerability.
  • D. VPN tunnel vulnerability.

Answer: C

NEW QUESTION 15
The business has been informed of a suspected breach of customer data. The internal audit team, in conjunction with the legal department, has begun working with the cybersecurity team to validate the report. To which of the following response processes should the business adhere during the investigation?

  • A. The security analysts should not respond to internal audit requests during an active investigation
  • B. The security analysts should report the suspected breach to regulators when an incident occurs
  • C. The security analysts should interview system operators and report their findings to the internal auditors
  • D. The security analysts should limit communication to trusted parties conducting the investigation

Answer: D

NEW QUESTION 16
A security analyst’s company uses RADIUS to support a remote sales staff of more than 700 people. The Chief Information Security Officer (CISO) asked to have IPSec using ESP and 3DES enabled to ensure the confidentiality of the communication as per RFC 3162. After the implementation was complete, many sales users reported latency issues and other performance issues when attempting to connect remotely. Which of the following is occurring?

  • A. The device running RADIUS lacks sufficient RAM and processing power to handle ESP implementation.
  • B. RFC 3162 is known to cause significant performance problems.
  • C. The IPSec implementation has significantly increased the amount of bandwidth needed.
  • D. The implementation should have used AES instead of 3DES.

Answer: A

NEW QUESTION 17
Which of the following is a control that allows a mobile application to access and manipulate information which should only be available by another application on the same mobile device (e.g. a music application posting the name of the current song playing on the device on a social media site)?

  • A. Co-hosted application
  • B. Transitive trust
  • C. Mutually exclusive access
  • D. Dual authentication

Answer: B

NEW QUESTION 18
Which of the following could be directly impacted by an unpatched vulnerability m vSphre ESXi?

  • A. The organization's physical routers
  • B. The organization's mobile devices
  • C. The organization's virtual infrastructure
  • D. The organization's VPN

Answer: C

P.S. DumpSolutions now are offering 100% pass ensure CS0-001 dumps! All CS0-001 exam questions have been updated with correct answers: https://www.dumpsolutions.com/CS0-001-dumps/ (242 New Questions)