CS0-002 Exam Details

  • Exam Code
    :CS0-002
  • Exam Name
    :CompTIA Cybersecurity Analyst (CySA+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1059 Q&As
  • Last Updated
    :Aug 04, 2026

CompTIA CS0-002 Online Questions & Answers

  • Question 101:

    A new vanant of malware is spreading on ihe company network using TCP 443 to contact its command- and-control server The domain name used for callback continues to change, and the analyst is unable to predict future domain name variance.

    Which of the following actions should the analyst take to stop malicious communications with the LEAST disruption to service?

    A. Implement a sinkhole with a high entropy level
    B. Disable TCP/53 at the penmeter firewall
    C. Block TCP/443 at the edge router
    D. Configure the DNS forwarders to use recursion

  • Question 102:

    A threat intelligence analyst has received multiple reports that are suspected to be about the same advanced persistent threat. To which of the following steps in the intelligence cycle would this map?

    A. Dissemination
    B. Analysis
    C. Feedback
    D. Requirements
    E. Collection

  • Question 103:

    A security analyst is reviewing the network security monitoring logs listed below:

    Count: 2 Event#3.3505 2020-01-30 10:40 UTC GPL WEB SERVER robots. txt access

    10.1.1.128 -> 10.0.0.10 IPVer=4 hlen=5 tos=0 dlen=269 ID=0 flags=0 offset=0 tt1=0 chksum=22704 Protocol: 6 sport=45260 => dport=80 Sec=0 Ack=0 Off=5 Res=0 Flags=******** Win=0 urp=23415 chksum=0

    Count: 22 Event#3.3507 2020-01-30 10:40 UTC ET WEB SPECIFIC APPS PHPStudy Remote Code Execution Backdoor

    10.1.1.129 -> 10.0.0.10 IPVer=4 hen=5 tos=0 dlen=269 ID=0 flags=0 offset=0 tt1=0 chksum=22704 Protocol: 6 sport=65200 -> dport=80 Sea=0 Ack=0 off=5 Res=0 Flags=******** win=0 urp=26814 chksum=0

    Count: 30 Event#3.3522 2020-01-30 10:40 UTC ET WEB SERVER WEB-PHP phpinfo access

    10.1.1.130 -> 10.0.0.10 IPVer=4 hen=5 tos=0 dlen=269 ID=0 flags=0 offset=0 tt1=0 chksum=22704 Protocol: 6 sport=58175 -> dport=80 Sec=0 Ack=0 Off=5 Res=0 Flags=******** win=0 urp=22875 chksum=0

    Count: 22 Event#3.3728 2020-01-30 10:40 UTC GPL WEB SERVER 403 Forbidden

    10.0.0.10 -> 10.1.1.129 IPVer=4 hen=5 tos=0 dlen=533 ID=0 flags=0 offset=0 tt1=0 chksum=20471 Protocol: 6 sport=80 -> dport=65200 Sea=0 Ack=0 Off=5 Res=0 Flags=******** win=0 urp=59638 chksum=0

    Which of the following is the analyst MOST likely observing? (Choose two.)

    A. 10.1.1.128 sent potential malicious traffic to the web server.
    B. 10.1.1.128 sent malicious requests, and the alert is a false positive.
    C. 10.1.1.129 successfully exploited a vulnerability on the web server.
    D. 10.1.1.129 sent potential malicious requests to the web server.
    E. 10.1.1.129 sent non-malicious requests, and the alert is a false positive.
    F. 10.1.1.130 can potentially obtain information about the PHP version.

  • Question 104:

    A security analyst has noticed that a particular server has consumed over 1TB of bandwidth over the course of the month. It has port 3333 open; however, there have not been any alerts or notices regarding the server or its activities. Which of the following did the analyst discover?

    A. APT
    B. DDoS
    C. Zero day
    D. False positive

  • Question 105:

    Which of the following systems or services is MOST likely to exhibit issues stemming from the Heartbleed vulnerability (Choose two.)

    A. SSH daemons
    B. Web servers
    C. Modbus devices
    D. TLS VPN services
    E. IPSec VPN concentrators
    F. SMB service

  • Question 106:

    A forensic analyst is conducting an investigation on a compromised server. Which of the following should the analyst do first to preserve evidence?

    A. Restore damaged data from the backup media
    B. Create a system timeline
    C. Monitor user access to compromised systems
    D. Back up all log files and audit trails

  • Question 107:

    A cybersecurity analyst has received an alert that well-known "call home" messages are continuously observed by network sensors at the network boundary. The proxy firewall successfully drops the messages. After determining the alert was a true positive, which of the following represents the MOST likely cause?

    A. Attackers are running reconnaissance on company resources.
    B. An outside command and control system is attempting to reach an infected system.
    C. An insider is trying to exfiltrate information to a remote network.
    D. Malware is running on a company system.

  • Question 108:

    A technician is running an intensive vulnerability scan to detect which ports are open to exploit. During the scan, several network services are disabled and production is affected. Which of the following sources would be used to evaluate which network service was interrupted?

    A. Syslog
    B. Network mapping
    C. Firewall logs
    D. NIDS

  • Question 109:

    Several users have reported that when attempting to save documents in team folders, the following message is received:

    The File Cannot Be Copied or Moved ?Service Unavailable.

    Upon further investigation, it is found that the syslog server is not obtaining log events from the file server to which the users are attempting to copy files. Which of the following is the MOST likely scenario causing these issues?

    A. The network is saturated, causing network congestion
    B. The file server is experiencing high CPU and memory utilization
    C. Malicious processes are running on the file server
    D. All the available space on the file server is consumed

  • Question 110:

    An organization has two environments: development and production. Development is where applications are developed with unit testing. The development environment has many configuration differences from the production environment. All applications are hosted on virtual machines. Vulnerability scans are performed against all systems before and after any application or configuration changes to any environment. Lately, vulnerability remediation activity has caused production applications to crash and behave unpredictably. Which of the following changes should be made to the current vulnerability management process?

    A. Create a third environment between development and production that mirrors production and tests all changes before deployment to the users
    B. Refine testing in the development environment to include fuzzing and user acceptance testing so applications are more stable before they migrate to production
    C. Create a second production environment by cloning the virtual machines, and if any stability problems occur, migrate users to the alternate production environment
    D. Refine testing in the production environment to include more exhaustive application stability testing while continuing to maintain the robust vulnerability remediation activities

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CS0-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.