CS0-002 Exam Details

  • Exam Code
    :CS0-002
  • Exam Name
    :CompTIA Cybersecurity Analyst (CySA+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1059 Q&As
  • Last Updated
    :Aug 04, 2026

CompTIA CS0-002 Online Questions & Answers

  • Question 31:

    The majority of a company's employees have stated they are unable to perform their job duties due to outdated workstations, so the company has decided to institute BYOD. Which of the following would a security analyst MOST likely recommend for securing the proposed solution?

    A. A Linux-based system and mandatory training on Linux for all BYOD users
    B. A firewalled environment for client devices and a secure VDl for BYOO users
    C. A standardized anti-malware platform and a unified operating system vendor
    D. 802.1X lo enforce company policy on BYOD user hardware

  • Question 32:

    An analyst has initiated an assessment of an organization's security posture. As a part of this review, the analyst would like to determine how much information about the organization is exposed externally. Which of the following techniques

    would BEST help the analyst accomplish this goal? (Select two.)

    A. Fingerprinting
    B. DNS query log reviews
    C. Banner grabbing
    D. Internet searches
    E. Intranet portal reviews
    F. Sourcing social network sites
    G. Technical control audits

  • Question 33:

    An organization has been conducting penetration testing to identify possible network vulnerabilities. One of the security policies states that web servers and database servers must not be co-located on the same server unless one of them runs on a non-standard. The penetration tester has received the following outputs from the latest set of scans:

    Which of the following servers is out of compliance?

    A. finServer
    B. adminServer
    C. orgServer
    D. opsServer

  • Question 34:

    An employee in the billing department accidentally sent a spreadsheet containing payment card data to a recipient outside the organization The employee intended to send the spreadsheet to an internal staff member with a similar name and was unaware of the mistake until the recipient replied to the message In addition to retraining the employee, which of the following would prevent this from happening in the future?

    A. Implement outgoing filter rules to quarantine messages that contain card data
    B. Configure the outgoing mail filter to allow attachments only to addresses on the whitelist
    C. Remove all external recipients from the employee's address book
    D. Set the outgoing mail filter to strip spreadsheet attachments from all messages.

  • Question 35:

    Which of the following is a difference between SOAR and SCAP?

    A. SOAR can be executed taster and with fewer false positives than SCAP because of advanced heunstics
    B. SOAR has a wider breadth of capability using orchestration and automation, while SCAP is more limited in scope
    C. SOAR is less expensive because process and vulnerability remediation is more automated than what SCAP does
    D. SOAR eliminates the need for people to perform remediation, while SCAP relies heavily on security analysts

  • Question 36:

    A computer at a company was used to commit a crime. The system was seized and removed for further analysis. Which of the following is the purpose of labeling cables and connections when seizing the computer system?

    A. To capture the system configuration as it was at the time it was removed
    B. To maintain the chain of custody
    C. To block any communication with the computer system from attack
    D. To document the model, manufacturer, and type of cables connected

  • Question 37:

    A technician working at company.com received the following email: After looking at the above communication, which of the following should the technician recommend to the security team to prevent exposure of sensitive information and reduce the risk of corporate data being stored on non-corporate assets?

    A. Forwarding of corporate email should be disallowed by the company.
    B. A VPN should be used to allow technicians to troubleshoot computer issues securely.
    C. An email banner should be implemented to identify emails coming from external sources.
    D. A rule should be placed on the DLP to flag employee IDs and serial numbers.

  • Question 38:

    A security analyst reviews a recent network capture and notices encrypted inbound traffic on TCP port 465 was coming into the company's network from a database server. Which of the following will the security analyst MOST likely identify as the reason for the traffic on this port?

    A. The traffic is common static data that Windows servers send to Microsoft
    B. Someone has configured an unauthorized SMTP application over SSL
    C. A connection from the database to the web front end is communicating on the port
    D. The server is receiving a secure connection using the new TLS 1.3 standard

  • Question 39:

    A security analyst was transferred to an organization's threat-hunting team to track specific activity throughout the enterprise environment The analyst must observe and assess the number ot times this activity occurs and aggregate the results. Which of the following is the BEST threat-hunting method for the analyst to use?

    A. Stack counting
    B. Searching
    C. Clustering
    D. Grouping

  • Question 40:

    An analyst needs to provide recommendations based on the following vulnerability report:

    Which of the following vulnerabilities should the analyst recommend addressing first?

    A. SSL certificate signed using weak hashing algorithm
    B. TLS version 1.0 protocol detection
    C. PHP 7.1.x
    D. RHEL 7 : qemu-kvm (RHSA-2020:1208)

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CS0-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.