Skip to main content

CS0-002 Real Exam Questions

CompTIA Cybersecurity Analyst (CySA+)

1,059 questions available · Page 1 of 106

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

Which of the following describes the mam difference between supervised and unsupervised machine-learning algorithms that are used in cybersecurity applications?

  1. A

    Supervised algorithms can be used to block attacks, while unsupervised algorithms cannot.

  2. B

    Supervised algorithms require security analyst feedback, while unsupervised algorithms do not.

  3. C

    Unsupervised algorithms are not suitable for IDS systems, white supervised algorithms are

  4. D

    Unsupervised algorithms produce more false positives. Than supervised algorithms.

Show answer and explanation

Correct answer: B

Question 2 Single choice

A security analyst received a series of antivirus alerts from a workstation segment, and users reported ransomware messages. During lessons-learned activities, the analyst determines the antivirus was able to alert to abnormal behavior but did not stop this newest variant of ransomware.

Which of the following actions should be taken to BEST mitigate the effects of this type of threat in the future?

  1. A

    Enabling sandboxing technology

  2. B

    Purchasing cyber insurance

  3. C

    Enabling application blacklisting

  4. D

    Installing a firewall between the workstations and Internet

Show answer and explanation

Correct answer: A

Question 3 Single choice

An organization that uses SPF has been notified emails sent via its authorized third-party partner are getting rejected. A security analyst reviews the DNS entry and sees the following:

v=spf1 ip4:180.10.6.5 ip4:180.10.6.10 include:robustmail.com `"all

The organization's primary mail server IP is 180.10.6.6, and the secondary mail server IP is 180.10.6.5.
The organization's third-party mail provider is "Robust Mail" with the domain name robustmail.com.

Which of the following is the MOST likely reason for the rejected emails?

  1. A

    SPF version 1 does not support third-party providers.

  2. B

    The primary and secondary email server IP addresses are out of sequence.

  3. C

    An incorrect IP version is being used.

  4. D

    The wrong domain name is in the SPF record.

Show answer and explanation

Correct answer: D

Question 4 Single choice

The Chief Information Security Officer (CISO) of a large financial institution is seeking a solution that will

block a predetermined set of data points from being transferred or downloaded by employees. The CISO also wants to track the data assets by name, type, content, or data profile.

Which of the following BEST describes what the CIS wants to purchase?

  1. A

    Asset tagging

  2. B

    SIEM

  3. C

    File integrity monitor

  4. D

    DLP

Show answer and explanation

Correct answer: D

Question 5 Single choice

The majority of a company's employees have stated they are unable to perform their job duties due to outdated workstations, so the company has decided to institute BYOD.

Which of the following would a security analyst MOST likely recommend for securing the proposed solution?

  1. A

    A Linux-based system and mandatory training on Linux for all BYOD users

  2. B

    A firewalled environment for client devices and a secure VDl for BYOO users

  3. C

    A standardized anti-malware platform and a unified operating system vendor

  4. D

    802.1X lo enforce company policy on BYOD user hardware

Show answer and explanation

Correct answer: D

Question 6 Single choice

The incident response team is working with a third-party forensic specialist to investigate the root cause of a recent intrusion An analyst was asked to submit sensitive network design details for review The forensic specialist recommended electronic delivery for efficiency but email was not an approved communication channel to send network details

Which of the following BEST explains the importance of using a secure method of communication during incident response?

  1. A

    To prevent adversaries from intercepting response and recovery details

  2. B

    To ensure intellectual property remains on company servers

  3. C

    To have a backup plan in case email access is disabled

  4. D

    To ensure the management team has access to all the details that are being exchanged

Show answer and explanation

Correct answer: A

Question 7 Single choice

Which of the following is a vulnerability that is specific to hypervisors?

  1. A

    DDoS

  2. B

    VLAN hopping

  3. C

    Weak encryption

  4. D

    WMescape

Show answer and explanation

Correct answer: D

Question 8 Single choice

An analyst is observing unusual network traffic from a workstation. The workstation is communicating with a known malicious site over an encrypted tunnel. A full antivirus scan with an updated antivirus signature file does not show any sign of infection.

Which of the following has occurred on the workstation?

  1. A

    Zero-day attack

  2. B

    Known malware attack

  3. C

    Session hijack

  4. D

    Cookie stealing

Show answer and explanation

Correct answer: A

Question 9 Single choice

A cybersecurity analyst has been asked to follow a corporate process that will be used to manage vulnerabilities for an organization. The analyst notices the policy has not been updated in three years.

Which of the following should the analyst check to ensure the policy is still accurate?

  1. A

    Threat intelligence reports

  2. B

    Technical constraints

  3. C

    Corporate minutes

  4. D

    Governing regulations

Show answer and explanation

Correct answer: A

Question 10 Single choice

A cybersecurity analyst is reviewing the following outputs:

Which of the following can the analyst infer from the above output?

  1. A

    The remote host is redirecting port 80 to port 8080.

  2. B

    The remote host is running a service on port 8080.

  3. C

    The remote host's firewall is dropping packets for port 80.

  4. D

    The remote host is running a web server on port 80.

Show answer and explanation

Correct answer: B