Validated CS0-001 Braindumps 2021

CS0-001 Braindumps for CompTIA certification, Real Success Guaranteed with Updated CS0-001 Braindumps. 100% PASS CS0-001 CompTIA CSA+ Certification Exam exam Today!

Check CS0-001 free dumps before getting the full version:

NEW QUESTION 1
Which of the following best practices is used to identify areas in the network that may be vulnerable to penetration testing from known external sources?

  • A. Blue team training exercises
  • B. Technical control reviews
  • C. White team training exercises
  • D. Operational control reviews

Answer: A

NEW QUESTION 2
A new zero day vulnerability was discovered within a basic screen capture app, which is used throughout the environment Two days after discovering the vulnerability, the manufacturer of the software has not announced a remediation or it there will be a fix for this newly discovered vulnerability. The vulnerable application is not uniquely critical, but it is used occasionally by the management and executive management teams The vulnerability allows remote code execution to gam privileged access to the system Which of the following is the BEST course of action to mitigate this threat'

  • A. Work with the manufacturer to determine the tone frame for the fix.
  • B. Block the vulnerable application traffic at the firewall and disable the application services on each computer.
  • C. Remove the application and replace it with a similar non-vulnerable application.
  • D. Communicate with the end users that the application should not be used until the manufacturer has reserved the vulnerability.

Answer: D

NEW QUESTION 3
An analyst was testing the latest version of an internally developed CRM system. The analyst created a basic user account. Using a few tools in Kali’s latest distribution, the analyst was able to access configuration files, change permissions on folders and groups, and delete and create new system objects. Which of the following techniques did the analyst use to perform these unauthorized activities?

  • A. Impersonation
  • B. Privilege escalation
  • C. Directory traversal
  • D. Input injection

Answer: C

NEW QUESTION 4
A recently issued audit report highlight exception related to end-user handling of sensitive data access and credentials. A security manager is addressing the findings. Which of the following activities should be implemented?

  • A. Update the password policy
  • B. Increase training requirements
  • C. Deploy a single sign-on platform
  • D. Deploy Group Policy Objects

Answer: B

NEW QUESTION 5
An executive tasked a security analyst to aggregate past logs, traffic, and alerts on a particular attack vector. The analyst was then tasked with analyzing the data and making predictions on future complications regarding this attack vector. Which of the following types of analysis is the security analyst MOST likely conducting?

  • A. Trend analysis
  • B. Behavior analysis
  • C. Availability analysis
  • D. Business analysis

Answer: A

NEW QUESTION 6
A company that is hiring a penetration tester wants to exclude social engineering from the list of authorized activities. Which of the following documents should include these details?

  • A. Acceptable use policy
  • B. Service level agreement
  • C. Rules of engagement
  • D. Memorandum of understanding
  • E. Master service agreement

Answer: C

NEW QUESTION 7
During the forensic phase of a security investigation, it was discovered that an attacker was able to find private keys on a poorly secured team shared drive. The attacker used those keys to intercept and decrypt sensitive traffic on a web server. Which of the following describes this type of exploit and the potential remediation?

  • A. Session tracking, network intrusion detection sensors
  • B. Cross-site scripting; increased encryption key sizes
  • C. Man-in-the-middle; well-controlled storage of private keys
  • D. Rootkit, controlled storage of public keys

Answer: C

NEW QUESTION 8
A threat intelligence analyst who works for a technology firm received this report from a vendor.
“There has been an intellectual property theft campaign executed against organizations in the technology industry. Indicators for this activity are unique to each intrusion. The information that appears to be targeted is R&D data. The data exfiltration appears to occur over months via uniform TTPs. Please execute a defensive operation regarding this attack vector.”
Which of the following combinations suggests how the threat should MOST likely be classified and the type of analysis that would be MOST helpful in protecting against this activity?

  • A. Polymorphic malware and secure code analysis
  • B. Insider threat and indicator analysis
  • C. APT and behavioral analysis
  • D. Ransomware and encryption

Answer: B

NEW QUESTION 9
In reviewing firewall logs, a security analyst has discovered the following IP address, which several employees are using frequently:
152.100.57.18
The organization’s servers use IP addresses in the 192.168.0.1/24 CIDR. Additionally, the analyst has noticed that corporate data is being stored at this new location. A few of these employees are on the management and executive management teams. The analyst has also discovered that there is no record of this IP address or service in reviewing the known locations of managing system assets. Which of the following is occurring in this scenario?

  • A. Malicious process
  • B. Unauthorized change
  • C. Data exfiltration
  • D. Unauthorized access

Answer: C

NEW QUESTION 10
Three similar production servers underwent a vulnerability scan. The scan results revealed that the three servers had two different vulnerabilities rated “Critical”.
The administrator observed the following about the three servers:
CS0-001 dumps exhibit The servers are not accessible by the Internet
CS0-001 dumps exhibit AV programs indicate the servers have had malware as recently as two weeks ago
CS0-001 dumps exhibit The SIEM shows unusual traffic in the last 20 days
CS0-001 dumps exhibit Integrity validation of system files indicates unauthorized modifications
Which of the following assessments is valid and what is the most appropriate NEXT step? (Select TWO).

  • A. Servers may have been built inconsistently
  • B. Servers may be generating false positives via the SIEM
  • C. Servers may have been tampered with
  • D. Activate the incident response plan
  • E. Immediately rebuild servers from known good configurations
  • F. Schedule recurring vulnerability scans on the servers

Answer: DE

NEW QUESTION 11
A system administrator recently deployed and verified the installation of a critical patch issued by the company’s primary OS vendor. This patch was supposed to remedy a vulnerability that would allow an adversary to remotely execute code from over the network. However, the administrator just ran a vulnerability assessment of networked systems, and each of them still reported having the same vulnerability. Which of the following is the MOST likely explanation for this?

  • A. The administrator entered the wrong IP range for the assessment.
  • B. The administrator did not wait long enough after applying the patch to run the assessment.
  • C. The patch did not remediate the vulnerability.
  • D. The vulnerability assessment returned false positives.

Answer: C

NEW QUESTION 12
A security analyst is assisting with a computer crime investigator and has been asked to secure a PC and deliver it to the forensics lab. Which of the following items would be MOST helpful to secure the PC (Select THREE)

  • A. Tamper-proof seals
  • B. Fataday cage
  • C. Chan of custody form
  • D. Drive eraser
  • E. Write blocks
  • F. Network tap
  • G. Millimeter

Answer: ABC

NEW QUESTION 13
Alerts have been received from the SIEM, indicating infections on multiple computers. Based on threat characteristic, these files were quarantined by the host-based antivirus program. At the same time, additional alerts in the SIEM show multiple blocked URLs from the address of the infected computers; the URLs were clashed as uncategorized. The domain location of the IP address of the URLs that were blocked is checked, and it is registered to an ISP in Russia. Which of the following steps should be taken NEXT?

  • A. Remove those computers from the network and replace the hard drives Send the Infected hard drives out lot investigation.
  • B. Run a full antivirus scan on all computers and use Splunk to search for any suspicious activity that happened just before the alerts were received in the SIEM.
  • C. Run a vulnerability scan and patch discovered vulnerabilities on the next patching cycle Have the users restart their computer Create a use case in the SIEM to monitor farted logins oninfected computers.
  • D. Install a computer with the same settings as the infected computers in the DM^ to use as a honeypot Permit the URLs classified as uncategorized to and from that host.

Answer: B

NEW QUESTION 14
On winch of the following organizational resources is the lack of an enabled password or PIN a common vulnerability?

  • A. VDI systems
  • B. Mobile devices
  • C. Enterprise server OSs
  • D. VPNs
  • E. VoIP phones

Answer: B

NEW QUESTION 15
During winch of the lo.low.ng NIST risk management framework steps would an information system security engineer identify inherited security controls and tailor those controls to the system?

  • A. Categorize
  • B. Select
  • C. Implement
  • D. Assess

Answer: B

NEW QUESTION 16
A company decides to move three of its business applications to different outsourced cloud providers. After moving the applications, the users report the applications time out too quickly and too much time is spent logging back into the different web-based applications throughout the day. Which of the following should a security architect recommend to improve the end-user experience without lowering the security posture?

  • A. Configure directory services with a federation provider to manage accounts.
  • B. Create a group policy to extend the default system lockout period.
  • C. Configure a web browser to cache the user credentials.
  • D. Configure user accounts for self-service account management.

Answer: B

NEW QUESTION 17
A medical organization recently started accepting payments over the phone. The manager is concerned about the impact of the storage of different types of data. Which of the following types of data incurs the highest regulatory constraints?

  • A. PHI
  • B. PCI
  • C. Pll
  • D. IP

Answer: B

NEW QUESTION 18
A recent vulnerability scan found four vulnerabilities on an organization’s public Internet-facing IP addresses. Prioritizing in order to reduce the risk of a breach to the organization, which of the following should be remediated FIRST?

  • A. A cipher that is known to be cryptographically weak.
  • B. A website using a self-signed SSL certificate.
  • C. A buffer overflow that allows remote code execution.
  • D. An HTTP response that reveals an internal IP address.

Answer: C

100% Valid and Newest Version CS0-001 Questions & Answers shared by prep-labs.com, Get Full Dumps HERE: https://www.prep-labs.com/dumps/CS0-001/ (New 242 Q&As)