CS0-003: CompTIA Cybersecurity Analyst (CySA+) Practice Exam
QuestionQ1
Vulnerability Management
Save question
A Chief Information Security Officer wants to implement security by design, beginning with a security-scanning method that identifies vulnerabilities, including SQL injection, RFI, XSS, and so on. Which of the following would most likely satisfy this requirement?
AReverse engineering
BKnown environment testing
CDynamic application security testing
DCode debugging
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ2
Incident Response and Management
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ3
Incident Response and Management
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ4
Security Operations
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ5
Reporting and Communication
0
Community Discussion
No comments yet. Be the first to start the discussion!
It's free
100% of the questions are free for all users. No strings attached.
An organization’s security operations center (SOC) team gives confidentiality and integrity priority over monetary considerations. The SOC team contains a rapidly progressing ransomware incident. Which of the following factors motivated the SOC team to take this action?
Choose two
AAttack vector
BRisk appetite
CScope
DImpact
ECommon Vulnerability Scoring System (CVSS) score
FAsset value
A security analyst is responding to an incident involving a malicious attack on a network data closet. Which option best describes how the analyst should properly document the incident?
ABack up the configuration file for all network devices.
BRecord and validate each connection.
CCreate a full diagram of the network infrastructure.
DTake photos of the impacted items.
Which of the following represents the central concept behind using an attack methodology framework?
AImplementing continuous monitoring and rapid deployment of system fixes over the traditional patch, test, and deploy approach
BPrioritizing vulnerabilities that can be exploited based on risk calculations and using the consequences and likelihood of the exploits to determine where resources should be allocated
CApproaching cybersecurity from the perspective of a threat actor and using their common behaviors and motivations to identify secure solutions
DApplying a Zero Trust environment by assuming networks and systems are vulnerable to malicious actions by both external, hostile adversaries and insider threats
A new cybersecurity analyst must create an executive briefing about potential threats to the organization. Which of the following will generate the data required for the briefing?
AFirewall logs
BIndicators of compromise
CRisk assessment
DAccess control lists
QuestionQ6
Vulnerability Management
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
Vulnerability Management
QuestionQ8
Security Operations
QuestionQ9
Vulnerability Management
QuestionQ10
Security Operations
QuestionQ11
Incident Response and Management
QuestionQ12
Vulnerability Management
QuestionQ13
Security Operations
QuestionQ14
Incident Response and Management
QuestionQ15
Incident Response and Management
QuestionQ16
Incident Response and Management
QuestionQ17
Incident Response and Management
QuestionQ18
Incident Response and Management
QuestionQ19
Vulnerability Management
QuestionQ20
Security Operations
QuestionQ21
Reporting and Communication
QuestionQ22
Security Operations
QuestionQ23
Vulnerability Management
QuestionQ24
Incident Response and Management
QuestionQ25
Incident Response and Management
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
A security analyst is implementing a vulnerability-management process for an OT environment:
Systems must stay on an isolated network.
The process should concentrate on external threats.
No extra software may be deployed on the systems.
Packets in transit must not be modified or dropped.
Additional processing latency is unacceptable.
Which of the following is the best way to securely satisfy these requirements?
AImplement agentless sensors at the network edge.
BUse reverse engineering to detect flaws on the in-scope systems.
CDeploy an IPS In-line with the network traffic.
DCheck the compatibility of an EDR agent with the OSs used on the ОТ environment.
A security analyst is enhancing an organization’s vulnerability-management program. The analyst validates the current reports with the infrastructure teams, but the reports fail to accurately show the current patching levels. Which of the following would most likely fix the reporting inaccuracies?
AUpdating the engine of the vulnerability scanning tool
BInstalling patches through a centralized system
CConfiguring vulnerability scans to be credentialed
DResetting the scanning tool’s plug-ins to default
An analyst has been tasked with validating the possible risk posed by a new ransomware campaign that the Chief Financial Officer read about in the newspaper. The company manufactures a very small spring used in the newest fighter jet and is a critical part of this aircraft's supply chain. Which of the following would be the best threat-intelligence source for learning about this new campaign?
AInformation sharing organization
BBlogs/forums
CCybersecurity incident response team
DDeep/dark web
Before merging with a software company, the acquiring company’s legal team requires a detailed software scan to determine whether the entire code base uses open-source or paid-licensed libraries. The vulnerability management analyst must provide this report. Which of the following scan methods best meets this requirement?
AStatic application security testing (SAST)
BDynamic application security testing (DAST)
CSoftware composition analysis (SCA)
DRuntime application self-protection (RASP)
ECredentialed vulnerability scan
Which option most accurately characterizes the Cyber Kill Chain methodology?
AIt is used to correlate events to ascertain the TTPs of an attacker.
BIt is used to ascertain lateral movements of an attacker, enabling the process to be stopped.
CIt provides a clear model of how an attacker generally operates during an intrusion and the actions to take at each stage.
DIt outlines a clear path for determining the relationships between the attacker, the technology used, and the target.
A security manager reviews permissions for the authorized users of a shared folder and identifies accounts that are not on the approved access list. During an incident investigation, a user finds data discrepancies in the file. Which option best describes this activity?
AFilesystem anomaly
BIllegal software
CUnauthorized changes
DData exfiltration
Several devices are added to a business network. Some of these new devices do not produce traffic during business hours. Which scanning method is the best way to identify the risk?
APassive
BActive
CMapping
DAgentless
A security analyst needs to identify anomalies in network routing. Which of the following shell-script functions can the analyst use to accomplish this objective most accurately?
An organization wants to create a disaster recovery plan for critical applications hosted on premises. Which of the following is the first step in preparing to support this new requirement?
AChoose a vendor to utilize for the disaster recovery location.
BEstablish prioritization of continuity from data and business owners.
CNegotiate vendor agreements to support disaster recovery capabilities.
DAdvise the leadership team that a geographical area for recovery must be defined.
An incident-response team discovered IoCs on a critical server. The team must isolate the server and gather technical evidence for further investigation. Which of the following data should be collected first to preserve sensitive information before isolating the server?
AHard disk
BPrimary boot partition
CMalicious files
DRouting table
EStatic IP address
A security analyst identified the following suspicious entry in the host-based IDS logs:
A new SOC manager reviewed the findings on the strengths and weaknesses from the previous tabletop exercise to make improvements. Which of the following should the SOC manager use to improve the process?
AThe most recent audit report
BThe incident response playbook
CThe incident response plan
DThe lessons-learned register
A finance department employee opens an unsolicited email containing a malicious payload. The payload rapidly spreads throughout the finance department but does not impact other departments. Which option best explains why the payload does not affect every department?
AOS version
BOffline computers
CFirewall configuration
DNetwork segmentation
A security analyst conducts a vulnerability scan. Based on the metrics in the scan results, the analyst must prioritize the hosts to patch. The analyst runs the tool and receives this output:
Which of the following hosts should be patched first based on the metrics?
Ahost01
Bhost02
Chost03
Dhost04
Which of the following attack-methodology frameworks should a cybersecurity analyst use to identify similar TTPs employed by nation-state actors?
ACyber kill chains
BDiamond Model of Intrusion Analysis
COWASP Testing Guide
DMITRE ATT&CK matrix
Which of the following best describes the document that communicates to network customers the expectation that patching will occur only between 2:00 a.m. and 4:00 a.m.?
ASLA
BLOI
CMOU
DKPI
An analyst examines code for a sensitive company application and uploads it to an AI platform. The application is essential to the company’s business operations. Which risk is most important for the analyst to consider?
AHallucinations
BMalicious prompts
CData exposure
DModel poisoning
An end-of-life date has been announced for a widely used OS. Some machinery performs a business-critical function and is controlled by a PC that uses the OS nearing its end-of-life date. Which of the following best describes a security analyst’s concern?
AAny discovered vulnerabilities will not be remediated.
BAn outage of machinery would cost the organization money.
CSupport will not be available for the critical machinery.
DThere are no compensating controls in place for the OS.
The SOC team restores a user's access after a threat actor successfully carried out a business account compromise in which the attacker revoked the legitimate user’s access. The following logs are supplied to a SOC analyst:
Which of the following did the threat actor most likely use during the compromise?
ABrute-force password attack
BA valid, leaked credential
CCommand-and-control traffic
DIntroduction of a new account
A security analyst is responding to an alert involving identity and access management activity in the cloud environment. The attacker is currently attempting to gain access from one isolated cloud subscription to another by using a compromised user role. Which aspect of the MITRE ATT&CK framework is the attacker trying to perform?
Community Discussion