CS0-002 Exam Details

  • Exam Code
    :CS0-002
  • Exam Name
    :CompTIA Cybersecurity Analyst (CySA+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1059 Q&As
  • Last Updated
    :Aug 04, 2026

CompTIA CS0-002 Online Questions & Answers

  • Question 81:

    A security administrator recently deployed a virtual honeynet. The honeynet is not protected by the company's firewall, while all production networks are protected by a stateful firewall. Which of the following would BEST allow an external penetration tester to determine which one is the honeynet's network?

    A. Banner grab
    B. Packet analyzer
    C. Fuzzer
    D. TCP ACK scan

  • Question 82:

    An organization's network administrator uncovered a rogue device on the network that is emulating the characteristics of a switch. The device is trunking protocols and inserting tagging values to control the flow of traffic at the data link layer. Which of the following BEST describes the attack?

    A. DNS pharming
    B. VLAN hopping
    C. Spoofing
    D. Injection attack

  • Question 83:

    The Chief Security Officer (CSO) has requested a vulnerability report of systems on the domain, identifying those running outdated OSs. The automated scan reports are not displaying OS version details, so the CSO cannot determine risk exposure levels from vulnerable systems. Which of the following should the cybersecurity analyst do to enumerate OS information as part of the vulnerability scanning process in the MOST efficient manner?

    A. Execute the ver command
    B. Execute the nmap -p command
    C. Use Wireshark to export a list
    D. Use credentialed configuration

  • Question 84:

    An incident responder successfully acquired application binaries off a mobile device for later forensic analysis. Which of the following should the analyst do NEXT?

    A. Decompile each binary to derive the source code.
    B. Perform a factory reset on the affected mobile device.
    C. Compute SHA-256 hashes for each binary.
    D. Encrypt the binaries using an authenticated AES-256 mode of operation.
    E. Inspect the permissions manifests within each application.

  • Question 85:

    A security technician configured a NIDS to monitor network traffic. Which of the following is a condition in which harmless traffic is classified as a potential network attack?

    A. True positive
    B. True negative
    C. False positive
    D. False negative

  • Question 86:

    An analyst receives an alert from the continuous-monitoring solution about unauthorized changes to the firmware versions on several field devices. The asset owners confirm that no firmware version updates were performed by authorized technicians, and customers have not reported any performance issues or outages. Which Of the following actions would be BEST for the analyst to recommend to the asset owners to secure the devices from further exploitation?

    A. Change the passwords on the devices.
    B. Implement BIOS passwords.
    C. Remove the assets from the production network for analysis.
    D. Report the findings to the threat intel community.

  • Question 87:

    An organization is performing vendor selection activities for penetration testing, and a security analyst is reviewing the MOA and rules of engagement, which were supplied with proposals. Which of the following should the analyst expect will be included in the documents and why?

    A. The scope of the penetration test should be included in the MOA to ensure penetration testing is conducted against only specifically authorized network resources.
    B. The MOA should address the client SLA in relation to reporting results to regulatory authorities, including issuing banks for organizations that process cardholder data.
    C. The rules of engagement should include detailed results of the penetration scan, including all findings, as well as designation of whether vulnerabilities identified during the scanning phases are found to be exploitable during the penetration test.
    D. The exploitation standards should be addressed in the rules of engagement to ensure both parties are aware of the depth of exploitation that will be attempted by penetration testers.

  • Question 88:

    A company's security administrator needs to automate several security processes related to testing for the existence of changes within the environment. Conditionally, other processes will need to be created based on input from prior processes. Which of the following is the BEST method for accomplishing this task?

    A. Machine learning and process monitoring
    B. Continuous integration and configuration management
    C. API integration and data enrichment
    D. Workflow orchestration and scripting

  • Question 89:

    Which of the following is the BEST way to share incident-related artifacts to provide non-repudiation?

    A. Secure email
    B. Encrypted USB drives
    C. Cloud containers
    D. Network folders

  • Question 90:

    An international company is implementing a marketing campaign for a new product and needs a security analyst to perform a threat-hunting process to identify possible threat actors. Which of the following should be the analyst's primary focus?

    A. Hacktivists
    B. Organized crime
    C. Nation-states
    D. Insider threats

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CS0-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.