最新的CompTIA Cybersecurity Analyst (CySA+) Certification - CS0-001免費考試真題
問題1
Given the following output from a Linux machine:
file2cable -i eth0 -f file.pcap
Which of the following BEST describes what a security analyst is trying to accomplish?
file2cable -i eth0 -f file.pcap
Which of the following BEST describes what a security analyst is trying to accomplish?
正確答案: E
問題2
An analyst suspects a large database that contains customer information and credit card data was exfiltrated to a known hacker group in a foreign country. Which of the following incident response steps should the analyst take FIRST?
正確答案: B
問題3
The Chief Security Officer (CSO) has requested a vulnerability report of systems on the domain, identifying those running outdated OSs. The automated scan reports are not displaying OS version details, so the CSO cannot determine risk exposure levels from vulnerable systems. Which of the following should the cybersecurity analyst do to enumerate OS information as part of the vulnerability scanning process in the MOST efficient manner?
正確答案: C
問題4
During an investigation, an incident responder intends to recover multiple pieces of digital media. Before removing the media, the responder should initiate:
正確答案: C
問題5
Several accounting department users are reporting unusual Internet traffic in the browsing history of their workstations after returning to work and logging in. The building security team informs the IT security team that the cleaning staff was caught using the systems after the accounting department users left for the day. Which of the following steps should the IT security team take to help prevent this from happening again? (Choose two.)
正確答案: A,E
問題6
An organization has a policy prohibiting remote administration of servers where web services are running. One of the Nmap scans is shown here:

Given the organization's policy, which of the following services should be disabled on this server?

Given the organization's policy, which of the following services should be disabled on this server?
正確答案: D
問題7
A company has received the results of an external vulnerability scan from its approved scanning vendor. The company is required to remediate these vulnerabilities for clients within 72 hours of acknowledgement of the scan results.
Which of the following contract breaches would result if this remediation is not provided for clients within the time frame?
Which of the following contract breaches would result if this remediation is not provided for clients within the time frame?
正確答案: C
問題8
In the development stage of the incident response policy, the security analyst needs to determine the stakeholders for the policy. Who of the following would be the policy stakeholders?
正確答案: A
問題9
During the forensic phase of a security investigation, it was discovered that an attacker was able to find private keys on a poorly secured team shared drive. The attacker used those keys to intercept and decrypt sensitive traffic on a web server. Which of the following describes this type of exploit and the potential remediation?
正確答案: B
問題10
An organization has been conducting penetration testing to identify possible network vulnerabilities. One of the security policies states that web servers and database servers must not be co-located on the same server unless one of them runs on a non-standard. The penetration tester has received the following outputs from the latest set of scans:

Which of the following servers is out of compliance?

Which of the following servers is out of compliance?
正確答案: D
問題11
Due to new regulations, a company has decided to institute an organizational vulnerability management program and assign the function to the security team. Which of the following frameworks would BEST support the program? (Choose two.)
正確答案: A,E
問題12
A security analyst is monitoring authentication exchanges over the company's wireless network. A sample of the Wireshark output is shown below:

Which of the following would improve the security posture of the wireless network?

Which of the following would improve the security posture of the wireless network?
正確答案: D
問題13
The Chief Information Security Officer (CISO) has asked the security staff to identify a framework on which to base the security program. The CISO would like to achieve a certification showing the security program meets all required best practices. Which of the following would be the BEST choice?
正確答案: A
問題14
An analyst wants to build a lab with multiple workstations to practice penetration testing In a test environment. Which or the following will provide the analyst with the MOST penetration-testing-specific features?
正確答案: C

