最新的CompTIA Cybersecurity Analyst (CySA+) Certification - CS0-003免費考試真題

問題1
A security administrator has found indications of dictionary attacks against the company ' s external-facing portal. Which of the following should be implemented to best mitigate the password attacks?

正確答案: A
說明:(僅 VCESoft 成員可見)
問題2
After conducting a cybersecurity risk assessment for a new software request, a Chief Information Security Officer (CISO) decided the risk score would be too high. The CISO refused the software request. Which of the following risk management principles did the CISO select?

正確答案: B
說明:(僅 VCESoft 成員可見)
問題3
Which of the following tools would work best to prevent the exposure of PII outside of an organization?

正確答案: D
說明:(僅 VCESoft 成員可見)
問題4
A company is in the process of implementing a vulnerability management program, and there are concerns about granting the security team access to sensitive data. Which of the following scanning methods can be implemented to reduce the access to systems while providing the most accurate vulnerability scan results?

正確答案: B
說明:(僅 VCESoft 成員可見)
問題5
The security team reviews a web server for XSS and runs the following Nmap scan:

Which of the following most accurately describes the result of the scan?

正確答案: C
說明:(僅 VCESoft 成員可見)
問題6
Which of the following explains the reason it is important to secure the file permissions of directories listed in the system path variable?

正確答案: A
說明:(僅 VCESoft 成員可見)
問題7
An organization utilizes multiple vendors, each with its own portal that a security analyst must sign in to daily. Which of the following is the best solution for the organization to use to eliminate the need for multiple authentication credentials?

正確答案: D
說明:(僅 VCESoft 成員可見)
問題8
The SOC receives a number of complaints regarding a recent uptick in desktop error messages that are associated with workstation access to an internal web application. An analyst, identifying a recently modified XML file on the web server, retrieves a copy of this file for review, which contains the following code:

Which of The following XML schema constraints would stop these desktop error messages from appearing?

正確答案: A
說明:(僅 VCESoft 成員可見)
問題9
A regulated organization experienced a security breach that exposed a list of customer names with corresponding PH data. Which of the following is the best reason for developing the organization ' s communication plans?

正確答案: B
說明:(僅 VCESoft 成員可見)
問題10
Which of the following is the most important reason for an incident response team to develop a formal incident declaration?

正確答案: C
說明:(僅 VCESoft 成員可見)
問題11
A web application team notifies a SOC analyst that there are thousands of HTTP/404 events on the public- facing web server. Which of the following is the next step for the analyst to take?

正確答案: B
說明:(僅 VCESoft 成員可見)
問題12
A cryptocurrency service company is primarily concerned with ensuring the accuracy of the data on one of its systems. A security analyst has been tasked with prioritizing vulnerabilities for remediation for the system.
The analyst will use the following CVSSv3.1 impact metrics for prioritization:

Which of the following vulnerabilities should be prioritized for remediation?

正確答案: D
說明:(僅 VCESoft 成員可見)