We offers CS0-001 Exam Questions. "CompTIA CSA+ Certification Exam", also known as CS0-001 exam, is a CompTIA Certification. This set of posts, Passing the CS0-001 exam with CS0-001 Study Guides, will help you answer those questions. The CS0-001 Free Practice Questions covers all the knowledge points of the real exam. 100% real CS0-001 Dumps Questions and revised by experts!
Also have CS0-001 free dumps questions for you:
NEW QUESTION 1
Which of the following commands would a security analyst use to make a copy of an image for forensics use?
- A. dd
- B. wget
- C. touch
- D. rm
Answer: A
NEW QUESTION 2
Which of the following actions should occur to address any open issues while closing an incident involving various departments within the network?
- A. Incident response plan
- B. Lessons learned report
- C. Reverse engineering process
- D. Chain of custody documentation
Answer: B
NEW QUESTION 3
A systems administrator is trying to secure a critical system. The administrator has placed the system behind a firewall, enabled strong authentication, and required all administrators of this system to attend mandatory training.
Which of the following BEST describes the control being implemented?
- A. Audit remediation
- B. Defense in depth
- C. Access control
- D. Multifactor authentication
Answer: B
NEW QUESTION 4
A logistics company’s vulnerability scan identifies the following vulnerabilities on Internet-facing devices in the DMZ:
SQL injection on an infrequently used web server that provides files to vendors
SSL/TLS not used for a website that contains promotional information
The scan also shows the following vulnerabilities on internal resources:
Microsoft Office Remote Code Execution on test server for a human resources system
TLS downgrade vulnerability on a server in a development network
In order of risk, which of the following should be patched FIRST?
- A. Microsoft Office Remote Code Execution
- B. SQL injection
- C. SSL/TLS not used
- D. TLS downgrade
Answer: A
NEW QUESTION 5
A security analyst is concerned that unauthorized users can access confidential data stored in the production server environment. All workstations on a particular network segment have full access to any server in production. Which of the following should be deployed in the production environment to prevent unauthorized access? (Choose two.)
- A. DLP system
- B. Honeypot
- C. Jump box
- D. IPS
- E. Firewall
Answer: CE
NEW QUESTION 6
Considering confidentiality and integrity, which of the following make servers more secure than desktops? (Select THREE).
- A. VLANs
- B. OS
- C. Trained operators
- D. Physical access restriction
- E. Processing power
- F. Hard drive capacity
Answer: BCD
NEW QUESTION 7
Joe, an analyst, has received notice that a vendor who is coming in for a presentation will require access to a server outside the network. Currently, users are only able to access remote sites through a VPN connection.
Which of the following should Joe use to BEST accommodate the vendor?
- A. Allow incoming IPSec traffic into the vendor’s IP address.
- B. Set up a VPN account for the vendor, allowing access to the remote site.
- C. Turn off the firewall while the vendor is in the office, allowing access to the remote site.
- D. Write a firewall rule to allow the vendor to have access to the remote site.
Answer: B
NEW QUESTION 8
A recent audit has uncovered several coding errors and a lack of input validation being used on a public portal. Due to the nature of the portal and the severity of the errors, the portal is unable to be patched. Which of the following tools could be used to reduce the risk of being compromised?
- A. Web application firewall
- B. Network firewall
- C. Web proxy
- D. Intrusion prevention system
Answer: A
NEW QUESTION 9
Which of the following is a feature of virtualization that can potentially create a single point of failure?
- A. Server consolidation
- B. Load balancing hypervisors
- C. Faster server provisioning
- D. Running multiple OS instances
Answer: A
NEW QUESTION 10
The Chief Information Security Officer (CISO) has asked the security staff to identify a framework on which
to base the security program. The CISO would like to achieve a certification showing the security program meets all required best practices. Which of the following would be the BEST choice?
- A. OSSIM
- B. SDLC
- C. SANS
- D. ISO
Answer: D
NEW QUESTION 11
A security analyst received an alert from the antivirus software identifying a complex instance of malware on a company’s network. The company does not have the resources to fully analyze the malware and determine its effect on the system. Which of the following is the BEST action to take in the incident recovery and post-incident response process?
- A. Wipe hard drives, reimage the systems, and return the affected systems to ready state.
- B. Detect and analyze the precursors and indicators; schedule a lessons learned meeting.
- C. Remove the malware and inappropriate materials; eradicate the incident.
- D. Perform event correlation; create a log retention policy.
Answer: C
NEW QUESTION 12
During a recent audit, there were a lot of findings similar to and including the following:
Which of the following would be the BEST way to remediate these finding and minimize similar findings in the future?
- A. Use an automated patch management solution
- B. Remove the affected software programs from the servers
- C. Run Microsoft Baseline Security Analyzer on all of the servers
- D. Schedule regular vulnerability scans for all servers on the network
Answer: A
NEW QUESTION 13
A web application has a newly discovered vulnerability in the authentication method used to validate known company users. The user ID of Admin with a password of “password” grants elevated access to the application over the Internet. Which of the following is the BEST method to discover the vulnerability before a production deployment?
- A. Manual peer review
- B. User acceptance testing
- C. Input validation
- D. Stress test the application
Answer: C
NEW QUESTION 14
A network technician is concerned that an attacker is attempting to penetrate the network, and wants to set a rule on the firewall to prevent the attacker from learning which IP addresses are valid on the network. Which of the following protocols needs to be denied?
- A. TCP
- B. SMTP
- C. ICMP
- D. ARP
Answer: C
NEW QUESTION 15
Management is concerned with administrator access from outside the network to a key server in the company. Specifically, firewall rules allow access to the server from anywhere in the company. Which of the following would be an effective solution?
- A. Honeypot
- B. Jump box
- C. Server hardening
- D. Anti-malware
Answer: B
NEW QUESTION 16
Company A’s security policy states that only PKI authentication should be used for all SSH accounts. A security analyst from Company A is reviewing the following auth.log and configuration settings:
Which of the following changes should be made to the following sshd_config file to establish compliance with the policy?
- A. Change PermitRootLogin no to #PermitRootLogin yes
- B. Change ChallengeResponseAuthentication yes to ChallangeResponseAuthentication no
- C. Change PubkeyAuthentication yes to #PubkeyAuthentication yes
- D. Change #AuthorizedKeysFile sh/.ssh/authorized_keys to AuthorizedKeysFile sh/.ssh/ authorized_keys
- E. Change PassworAuthentication yes to PasswordAuthentication no
Answer: E
NEW QUESTION 17
A malware infection spread to numerous workstations within the marketing department. The workstations were quarantined and replaced with machines.
Which of the following represents a FINAL step in the eradication of the malware?
- A. The workstations should be isolated from the network.
- B. The workstations should be donated for reuse.
- C. The workstations should be reimaged.
- D. The workstations should be patched and scanned.
Answer: D
NEW QUESTION 18
A company discovers an unauthorized device accessing network resources through one of many network drops in a common area used by visitors.
The company decides that it wants to quickly prevent unauthorized devices from accessing the network but policy prevents the company from making changes on every connecting client.
Which of the following should the company implement?
- A. Port security
- B. WPA2
- C. Mandatory Access Control
- D. Network Intrusion Prevention
Answer: A
P.S. Easily pass CS0-001 Exam with 242 Q&As Simply pass Dumps & pdf Version, Welcome to Download the Newest Simply pass CS0-001 Dumps: https://www.simply-pass.com/CompTIA-exam/CS0-001-dumps.html (242 New Questions)
