4/5 - (2 votes)

Pass Your CompTIA Exam with CS0-002 Exam Dumps (Updated 328 Questions)

CS0-002 Exam Dumps – CompTIA Practice Test Questions

What is the Exam fee for CompTIA CS0-002 Exam

  • The cost of CompTIA CS0-002 Exam is $359

What can you expect after completing CompTIA CS0-002 exam?

The certified professionals can take up the job roles of a Security Analyst, a Security Engineer, an Incident Handler, a Threat Hunter, a Compliance Analyst, an Application Security Analyst, and a Threat Intelligence Analyst. The salary outlook for these positions is an average of $94,500 per annum. An experience level and specific job title will determine the actual remuneration that an individual can earn.

 

NO.106 Which of the following types of policies is used to regulate data storage on the network?

 
 
 
 

NO.107 While reviewing proxy logs, the security analyst noticed a suspicious traffic pattern. Several internal hosts were observed communicating with an external IP address over port 80 constantly.
An incident was declared, and an investigation was launched. After interviewing the affected users, the analyst determined the activity started right after deploying a new graphic design suite.
Based on this information, which of the following actions would be the appropriate NEXT step in the investigation?

 
 
 
 

NO.108 During an investigation, a security analyst determines suspicious activity occurred during the night shift over the weekend. Further investigation reveals the activity was initiated from an internal IP going to an external website.
Which of the following would be the MOST appropriate recommendation to prevent the activity from happening in the future?

 
 
 
 

NO.109 During an incident, a cybersecurity analyst found several entries in the web server logs that are related to an IP with a bad reputation. Which of the following would cause the analyst to further review the incident?

 
 
 
 
 

NO.110 A company’s Chief Information Security Officer (CISO) is concerned about the integrity of some highly confidential files. Any changes to these files must be tied back to a specific authorized user’s activity session.
Which of the following is the BEST technique to address the CISO’s concerns?

 
 
 
 

NO.111 An employee was conducting research on the Internet when a message from cyber criminals appeared on the screen, stating the hard drive was just encrypted by a ransomware variant. An analyst observes the following:
* Antivirus signatures were updated recently
* The desktop background was changed
* Web proxy logs show browsing to various information security sites and ad network traffic
* There is a high volume of hard disk activity on the file server
* SMTP server shown the employee recently received several emails from blocked senders
* The company recently switched web hosting providers
* There are several IPS alerts for external port scans
Which of the following describes how the employee got this type of ransomware?

 
 
 
 

NO.112 A security analyst suspects a malware infection was caused by a user who downloaded malware after clicking
http://<malwaresource>/a.php in a phishing email.
To prevent other computers from being infected by the same malware variation, the analyst should create a rule on the.

 
 
 
 

NO.113 During an investigation, a computer is being seized. Which of the following is the FIRST step the analyst should take?

 
 
 
 

NO.114 A security analyst, who is working for a company that utilizes Linux servers, receives the following results from a vulnerability scan:

Which of the following is MOST likely a false positive?

 
 
 
 

NO.115 After analyzing and correlating activity from multiple sensors, the security analyst has determined a group from a high-risk country is responsible for a sophisticated breach of the company network and continuous administration of targeted attacks for the past three months. Until now, the attacks went unnoticed. This is an example of:

 
 
 
 

NO.116 An organization wants to harden its web servers. As part of this goal, leadership has directed that vulnerability scans be performed, and the security team should remediate the servers according to industry best practices. The team has already chosen a vulnerability scanner and performed the necessary scans, and now the team needs to prioritize the fixes. Which of the following would help to prioritize the vulnerabilities for remediation in accordance with industry best practices?

 
 
 
 
 

NO.117 During an investigation, an incident responder intends to recover multiple pieces of digital medi
Before removing the media, the responder should initiate:

 
 
 
 

NO.118 A computer has been infected with a virus and is sending out a beacon to command and control server through an unknown service. Which of the following should a security technician implement to drop the traffic going to the command and control server and still be able to identify the infected host through firewall logs?

 
 
 
 

NO.119 The development team recently moved a new application into production for the accounting department. After this occurred, the Chief Information Officer (CIO) was contacted by the head of accounting because the application is missing a key piece of functionality that is needed to complete the corporation’s quarterly tax returns. Which of the following types of testing would help prevent this from reoccurring?

 
 
 
 

NO.120 An organization suspects it has had a breach, and it is trying to determine the potential impact. The organization knows the following:
* The source of the breach is linked to an IP located in a foreign country.
* The breach is isolated to the research and development servers.
* The hash values of the data before and after the breach are unchanged.
* The affected servers were regularly patched, and a recent scan showed no vulnerabilities.
Which of the following conclusions can be drawn with respect to the threat and impact? (Choose two.)

 
 
 
 
 

Pass Your CS0-002 Exam Easily with Accurate PDF Questions: https://www.trainingquiz.com/CS0-002-practice-quiz.html

Related Links: myportal.utt.edu.tt myportal.utt.edu.tt myportal.utt.edu.tt myportal.utt.edu.tt www.stes.tyc.edu.tw myportal.utt.edu.tt

Leave a Reply

Please sing in to post your comment or singup if you don't have account.
Enter the text from the image below