CS0-002 Exam Details

  • Exam Code
    :CS0-002
  • Exam Name
    :CompTIA Cybersecurity Analyst (CySA+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1059 Q&As
  • Last Updated
    :Aug 04, 2026

CompTIA CS0-002 Online Questions & Answers

  • Question 71:

    Joe, an analyst, has received notice that a vendor who is coming in for a presentation will require access to a server outside the network. Currently, users are only able to access remote sites through a VPN connection. Which of the following should Joe use to BEST accommodate the vendor?

    A. Allow incoming IPSec traffic into the vendor's IP address.
    B. Set up a VPN account for the vendor, allowing access to the remote site.
    C. Turn off the firewall while the vendor is in the office, allowing access to the remote site.
    D. Write a firewall rule to allow the vendor to have access to the remote site.

  • Question 72:

    Which of the following best practices is used to identify areas in the network that may be vulnerable to penetration testing from known external sources?

    A. Blue team training exercises
    B. Technical control reviews
    C. White team training exercises
    D. Operational control reviews

  • Question 73:

    A company recently hired a new SOC provider and implemented new incident response procedures. Which of the following conjoined approaches would MOST likely be used to evaluate the new implementations for monitoring and incident response at the same time? (Choose two.)

    A. Blue-team exercise
    B. Disaster recovery exercise
    C. Red-team exercise
    D. Gray-box penetration test
    E. Tabletop exercise
    F. Risk assessment

  • Question 74:

    A large organization wants to move account registration services to the cloud to benefit from faster processing and elasticity. Which of the following should be done FIRST to determine the potential risk to the organization?

    A. Establish a recovery time objective and a recovery point objective for the systems being moved
    B. Calculate the resource requirements for moving the systems to the cloud
    C. Determine recovery priorities for the assets being moved to the cloud-based systems
    D. Identify the business processes that will be migrated and the criticality of each one
    E. Perform an inventory of the servers that will be moving and assign priority to each one

  • Question 75:

    Which of the following stakeholders would need to be aware of an e-discovery notice received by the security office about an ongoing case within the manufacturing department?

    A. Board of trustees
    B. Human resources
    C. Legal
    D. Marketing

  • Question 76:

    An organization is experiencing security incidents in which a systems administrator is creating unauthorized user accounts. A security analyst has created a script to snapshot the system configuration each day.

    Following is one of the scripts: cat /etc/passwd > daily_$(date +"%m_%d_%Y")

    This script has been running successfully every day. Which of the following commands would provide the analyst with additional useful information relevant to the above script?

    A. diff daily_11_03_2019 daily_11_04_2019
    B. ps -ef | grep admin > daily_process_$(date +%m_%d_%Y")
    C. more /etc/passwd > daily_$(date +%m_%d_%Y_%H:%M:%S")
    D. la -lai /usr/sbin > daily_applications

  • Question 77:

    A vulnerability analyst needs to identify all systems with unauthorized web servers on the 10.1.1.0/24 network. The analyst uses the following default Nmap scan:

    nmap -sV -p 1-65535 10.1.1.0/24

    Which of the following would be the result of running the above command?

    A. This scan checks all TCP ports.
    B. This scan probes all ports and returns open ones.
    C. This scan checks all TCP ports and returns versions.
    D. This scan identifies unauthorized servers.

  • Question 78:

    Which of the following technologies can be used to house the entropy keys for disk encryption on desktops and laptops?

    A. Self-encrypting drive
    B. Bus encryption
    C. TPM
    D. HSM

  • Question 79:

    A cybersecurity analyst is completing an organization's vulnerability report and wants it to reflect assets accurately. Which of the following items should be in the report?

    A. Processor utilization
    B. Virtual hosts
    C. Organizational governance
    D. Log disposition
    E. Asset isolation

  • Question 80:

    During the forensic a phase of a security investigation, it was discovered that an attacker was able to find private keys on a poorly secured team shared drive. The attacker used those keys to intercept and decrypt sensitive traffic on a web server. Which of the following describes this type of exploit and the potential remediation?

    A. Session hijacking; network intrusion detection sensors
    B. Cross-site scripting; increased encryption key sizes
    C. Man-in-the-middle; well-controlled storage of private keys
    D. Rootkit; controlled storage of public keys

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CS0-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.