CS0-002 Exam Details

  • Exam Code
    :CS0-002
  • Exam Name
    :CompTIA Cybersecurity Analyst (CySA+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1059 Q&As
  • Last Updated
    :Aug 04, 2026

CompTIA CS0-002 Online Questions & Answers

  • Question 1031:

    An organization is concerned about the security posture of vendors with access to its facilities and systems. The organization wants to implement a vendor review process to ensure the policies implemented by vendors are in line with its own. Which of the following will provide the highest assurance of compliance?

    A. An in-house red-team report
    B. A vendor self-assessment report
    C. An independent third-party audit report
    D. Internal and external scans from an approved third-party vulnerability vendor

  • Question 1032:

    A company has several internal-only, web-based applications on the internal network. Remote employees are allowed to connect to the internal corporate network with a company-supplied VPN client. During a project to upgrade the internal application, contractors were hired to work on a database server and were given copies of the VPN client so they could work remotely. A week later, a security analyst discovered an internal web-server had been compromised by malware that originated from one of the contractor's laptops. Which of the following changes should be made to BEST counter the threat presented in this scenario?

    A. Create a restricted network segment for contractors, and set up a jump box for the contractors to use to access internal resources.
    B. Deploy a web application firewall in the DMZ to stop Internet-based attacks on the web server.
    C. Deploy an application layer firewall with network access control lists at the perimeter, and then create alerts for suspicious Layer 7 traffic.
    D. Require the contractors to bring their laptops on site when accessing the internal network instead of using the VPN from a remote location.
    E. Implement NAC to check for updated anti-malware signatures and location-based rules for PCs connecting to the internal network.

  • Question 1033:

    The IT department is concerned about the possibility of a guest device infecting machines on the corporate network or taking down the company's singe internet connection. Which of the following should a security analyst recommend to BEST meet the requirements outlined by the IT Department?

    A. Require the guest machines to install the corporate-owned EDR solution.
    B. Configure NAC to only alow machines on the network that are patched and have active antivirus.
    C. Place a firewall In between the corporate network and the guest network
    D. Configure the IPS with rules that will detect common malware signatures traveling from the guest network.

  • Question 1034:

    After scanning the main company's website with the OWASP ZAP tool, a cybersecurity analyst is reviewing the following warning:

    The analyst reviews a snippet of the offending code:

    Which of the following is the BEST course of action based on the above warning and code snippet?

    A. The analyst should implement a scanner exception for the false positive.
    B. The system administrator should disable SSL and implement TLS.
    C. The developer should review the code and implement a code fix.
    D. The organization should update the browser GPO to resolve the issue.

  • Question 1035:

    An organization recently had its strategy posted to a social media website. The document posted to the website is an exact copy of a document stored on only one server in the organization. A security analyst sees the following output from a command-line entry on the server suspected of the problem:

    Which of the following would be the BEST course of action?

    A. Remove the malware associated with PID 773
    B. Monitor all the established TCP connections for data exfiltration
    C. Investigate the malware associated with PID 123
    D. Block all TCP connections at the firewall
    E. Figure out which of the Firefox processes is the malware

  • Question 1036:

    Ransomware is identified on a company's network that affects both Windows and MAC hosts. The command and control channel for encryption for this variant uses TCP ports from 11000 to 65000. The channel goes to good1. Iholdbadkeys.com, which resolves to IP address 72.172.16.2. Which of the following is the MOST effective way to prevent any newly infected systems from actually encrypting the data on connected network drives while causing the least disruption to normal Internet traffic?

    A. Block all outbound traffic to web host good1 iholdbadkeys.com at the border gateway.
    B. Block all outbound TCP connections to IP host address 172.172.16.2 at the border gateway.
    C. Block all outbound traffic on TCP ports 11000 to 65000 at the border gateway.
    D. Block all outbound traffic on TCP ports 11000 to 65000 to IP host address 172.172.16.2 at the border gateway.

  • Question 1037:

    Alerts have been received from the SIEM, indicating infections on multiple computers. Based on threat characteristics, these files were quarantined by the host-based antivirus program. At the same time, additional alerts in the SIEM show multiple blocked URLs from the address of the infected computers; the URLs were classified as uncategorized. The domain location of the IP address of the URLs that were blocked is checked, and it is registered to an ISP in Russia. Which of the following steps should be taken NEXT?

    A. Remove those computers from the network and replace the hard drives. Send the infected hard drives out for investigation.
    B. Run a full antivirus scan on all computers and use Splunk to search for any suspicious activity that happened just before the alerts were received in the SIEM.
    C. Run a vulnerability scan and patch discovered vulnerabilities on the next pathing cycle. Have the users restart their computers. Create a use case in the SIEM to monitor failed logins on the infected computers.
    D. Install a computer with the same settings as the infected computers in the DMZ to use as a honeypot. Permit the URLs classified as uncategorized to and from that host.

  • Question 1038:

    While conducting a cloud assessment, a security analyst performs a Prowler scan, which generates the following within the report:

    Based on the Prowler report, which of the following is the BEST recommendation?

    A. Delete CloudDev access key 1.
    B. Delete BusinessUsr access key 1.
    C. Delete access key 1.
    D. Delete access key 2.

  • Question 1039:

    A manufacturing company uses a third-party service provider for Tier 1 security support. One of the requirements is that the provider must only source talent from its own country due to geopolitical and national security interests. Which of the following can the manufacturing company implement to ensure the third-party service provider meets this requirement?

    A. Implement a secure supply chain program with governance.
    B. Implement blacklisting lor IP addresses from outside the county.
    C. Implement strong authentication controls for at contractors.
    D. Implement user behavior analytics tor key staff members.

  • Question 1040:

    A customer notifies a security analyst that a web application is vulnerable to information disclosure The analyst needs to indicate the seventy of the vulnerability based on its CVSS score, which the analyst needs to calculate When analyzing the vulnerability the analyst realizes that tor the attack to be successful, the Tomcat configuration file must be modified.

    Which of the following values should the security analyst choose when evaluating the CVSS score?

    A. Network
    B. Physical
    C. Adjacent
    D. Local

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CS0-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.