The development team has created a new employee application to allow the 35,000 staff members to communicate via video, chat rooms, and microblogs from anywhere in the world. The application was tested by a small user group, and the code reviews were completed. Which of the following is the best NEXT step the development team should take?
A. Run the application through a web-application vulnerability scanner.A company's blocklist has outgrown the current technologies in place. The ACLs are at maximum, and the IPS signatures only allow a certain amount of space for domains to be added, creating the need for multiple signatures. Which of the following configuration changes to the existing controls would be the MOST appropriate to improve performance?
A. Implement a host-file-based solution that will use a list of all domains to deny for all machines on the network.A company's change management team has asked a security analyst to review a potential change to the email server before it is released into production. The analyst reviews the following change request:
Change request date: 2020-01-30 Change requester: Cindy Richardson Change asset: WIN2K-EMAIL001 Change requested: Modify the following SPF record to change +all to -all
Which of the following is the MOST likely reason for the change?
A. To reject email from servers that are not listed in the SPF recordWhich of the following would best protect sensitive data if a device is stolen?
A. Remote wipe of driveA new policy requires the security team to perform web application and OS vulnerability scans. All of the company's web applications use federated authentication and are accessible via a central portal. Which of the following should be implemented to ensure a more thorough scan of the company's web application, while at the same time reducing false positives?
A. The vulnerability scanner should be configured to perform authenticated scans.An information security analyst discovered a virtual machine server was compromised by an attacker. Which of the following should be the FIRST step to confirm and respond to the incident?
A. Pause the virtual machine,Which of the following sources would a security analyst rely on to provide relevant and timely threat information concerning the financial services industry?
A. Real-time and automated firewall rules subscriptionsA large company would like a security analyst to recommend a solution that will allow only company laptops to connect to the corporate network. Which of the following technologies should the analyst recommend?
A. UEBADuring an incident, an analyst works closely with specific team members. Which of the following best explains why communication is limited to specific team members?
A. To determine when information can be releasedAn employee was conducting research on the Internet when a message from cyber criminals appeared on the screen, stating the hard drive was just encrypted by a ransomware variant. An analyst observes the following:
1.
Antivirus signatures were updated recently
2.
The desktop background was changed
3.
Web proxy logs show browsing to various information security sites and ad network traffic
4.
There is a high volume of hard disk activity on the file server
5.
SMTP server shown the employee recently received several emails from blocked senders
6.
The company recently switched web hosting providers
7.
There are several IPS alerts for external port scans
Which of the following describes how the employee got this type of ransomware?
A. The employee fell victim to a CSRF attackNowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CS0-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.