Download CompTIA CSA+ Certification Exam.CS0-001.PassLeader.2018-11-18.145q.tqb

Vendor: CompTIA
Exam Code: CS0-001
Exam Name: CompTIA CSA+ Certification Exam
Date: Nov 18, 2018
File Size: 2 MB

How to open TQB files?

Files with TQB (Taurus Question Bank) extension can be opened by Taurus Exam Studio.

Demo Questions

Question 1
A security analyst is creating baseline system images to remediate vulnerabilities found in different operating systems. Each image needs to be scanned before it is deployed. The security analyst must ensure the configurations match industry standard benchmarks and the process can be repeated frequently. 
Which of the following vulnerability options would BEST create the process requirements?
  1. Utilizing an operating system SCAP plugin
  2. Utilizing an authorized credential scan
  3. Utilizing a non-credential scan
  4. Utilizing a known malware plugin
Correct answer: A
Question 2
A cybersecurity analyst is retained by a firm for an open investigation. Upon arrival, the cybersecurity analyst reviews several security logs. 
Given the following snippet of code:
  
Which of the following combinations BEST describes the situation and recommendations to be made for this situation?
  1. The cybersecurity analyst has discovered host 192.168.0.101 using Windows Task Scheduler at 13:30 to runnc.exe; recommend proceeding with the next step of removing the host from the network.
  2. The cybersecurity analyst has discovered host 192.168.0.101 to be running thenc.exe file at 13:30 using the auto cron job remotely, there are no recommendations since this is not a threat currently.
  3. The cybersecurity analyst has discovered host 192.168.0.101 is beaconing every day at 13:30 using thenc.exe file; recommend proceeding with the next step of removing the host from the network.
  4. The security analyst has discovered host 192.168.0.101 is a rogue device on the network, recommend proceeding with the next step of removing the host from the network.
Correct answer: A
Question 3
An analyst wants to use a command line tool to identify open ports and running services on a host along with the application that is associated with those services and port. 
Which of the following should the analyst use?
  1. Wireshark
  2. Qualys
  3. netstat
  4. nmap
  5. ping
Correct answer: D
Question 4
In order to meet regulatory compliance objectives for the storage of PHI, vulnerability scans must be conducted on a continuous basis. The last completed scan of the network returned 5,682 possible vulnerabilities. The Chief Information Officer (CIO) would like to establish a remediation plan to resolve all known issues. 
Which of the following is the BEST way to proceed?
  1. Attempt to identify all false positives and exceptions, and then resolve all remaining items.
  2. Hold off on additional scanning until the current list of vulnerabilities have been resolved.
  3. Place assets that handle PHI in a sandbox environment, and then resolve all vulnerabilities.
  4. Reduce the scan to items identified as critical in the asset inventory, and resolve these issues first.
Correct answer: D
Question 5
An administrator has been investigating the way in which an actor had been exfiltrating confidential data from a web server to a foreign host. After a thorough forensic review, the administrator determined the server’s BIOS had been modified by rootkit installation. After removing the rootkit and flashing the BIOS to a known good state, which of the following would BEST protect against future adversary access to the BIOS, in case another rootkit is installed?
  1. Anti-malware application
  2. Host-based IDS
  3. TPM data sealing
  4. File integrity monitoring
Correct answer: C
Question 6
A security analyst is reviewing the following log after enabling key-based authentication. 
  
 
Given the above information, which of the following steps should be performed NEXT to secure the system?
  1. Disable anonymous SSH logins.
  2. Disable password authentication for SSH.
  3. Disable SSHv1.
  4. Disable remote root SSH logins.
Correct answer: B
Question 7
A cybersecurity analyst has received a report that multiple systems are experiencing slowness as a result of a DDoS attack. 
Which of the following would be the BEST action for the cybersecurity analyst to perform?
  1. Continue monitoring critical systems.
  2. Shut down all server interfaces.
  3. Inform management of the incident.
  4. Inform users regarding the affected systems.
Correct answer: C
Question 8
A security analyst has been asked to remediate a server vulnerability. Once the analyst has located a patch for the vulnerability, which of the following should happen NEXT?
  1. Start the change control process.
  2. Rescan to ensure the vulnerability still exists.
  3. Implement continuous monitoring.
  4. Begin the incident response process.
Correct answer: A
Question 9
A software assurance lab is performing a dynamic assessment on an application by automatically generating and inputting different, random data sets to attempt to cause an error/failure condition. Which of the following software assessment capabilities is the lab performing AND during which phase of the SDLC should this occur? (Select two.)
  1. Fuzzing
  2. Behavior modeling
  3. Static code analysis
  4. Prototyping phase
  5. Requirements phase
  6. Planning phase
Correct answer: AD
Explanation:
Reference: http://www.brighthub.com/computing/smb-security/articles/9956.aspx
Reference: http://www.brighthub.com/computing/smb-security/articles/9956.aspx
Question 10
Law enforcement has contacted a corporation’s legal counsel because correlated data from a breach shows the organization as the common denominator from all indicators of compromise. An employee overhears the conversation between legal counsel and law enforcement, and then posts a comment about it on social media. The media then starts contacting other employees about the breach. Which of the following steps should be taken to prevent further disclosure of information about the breach?
  1. Perform security awareness training about incident communication.
  2. Request all employees verbally commit to an NDA about the breach.
  3. Temporarily disable employee access to social media
  4. Have law enforcement meet with employees.
Correct answer: A
HOW TO OPEN VCE FILES

Use VCE Exam Simulator to open VCE files
Avanaset

HOW TO OPEN VCEX FILES

Use ProfExam Simulator to open VCEX files
ProfExam Screen

ProfExam
ProfExam at a 20% markdown

You have the opportunity to purchase ProfExam at a 20% reduced price

Get Now!