[Dec-2025] Get 100% Real Free CompTIA CySA+ CS0-002 Sample Questions
Accurate CS0-002 Questions with Free and Fast Updates
NEW QUESTION # 50
Which of the following actions should occur to address any open issues while closing an incident involving various departments within the network?
- A. Incident response plan
- B. Chain of custody documentation
- C. Reverse engineering process
- D. Lessons learned report
Answer: D
NEW QUESTION # 51
Several users have reported that when attempting to save documents in team folders, the following message is received:
The File Cannot Be Copied or Moved ?Service Unavailable. Upon further investigation, it is found that the syslog server is not obtaining log events from the file server to which the users are attempting to copy files. Which of the following is the MOST likely scenario causing these issues?
- A. The file server is experiencing high CPU and memory utilization
- B. Malicious processes are running on the file server
- C. The network is saturated, causing network congestion
- D. All the available space on the file server is consumed
Answer: C
NEW QUESTION # 52
An organization has the following policies:
*Services must run on standard ports.
*Unneeded services must be disabled.
The organization has the following servers:
*192.168.10.1 - web server
*192.168.10.2 - database server
A security analyst runs a scan on the servers and sees the following output:
Which of the following actions should the analyst take?
- A. Disable IIS on 192.168.10.1.
- B. Disable SSH on both servers.
- C. Disable HTTPS on 192.168.10.1.
- D. Disable MSSQL on 192.168.10.2.
- E. Disable DNS on 192.168.10.2.
Answer: E
NEW QUESTION # 53
A security analyst identified some potentially malicious processes after capturing the contents of memory from a machine during incident response. Which of the following procedures is the NEXT step for further in investigation?
- A. Reverse engineering
- B. Timeline construction
- C. File cloning
- D. Data carving
Answer: A
Explanation:
Reverse engineering is a process of analyzing a system or a component to understand how it works and how it was made. Reverse engineering can be used to examine malicious processes captured from memory and determine their functionality, origin, and purpose. Reverse engineering can help identify the type of malware, its infection vector, its capabilities, its communication methods, and its indicators of compromise2
NEW QUESTION # 54
An organization is experiencing degradation of critical services and availability of critical external resources. Which of the following can be used to investigate the issue?
- A. Vulnerability analysis
- B. Behavioral analysis
- C. Netflow analysis
- D. Risk analysis
Answer: C
NEW QUESTION # 55
A security analyst received an alert from the SIEM indicating numerous login attempts from users outside their usual geographic zones, all of which were initiated through the web-based mail server. The logs indicate all domain accounts experienced two login attempts during the same time frame.
Which of the following is the MOST likely cause of this issue?
- A. A DDoS attack was performed against the organization.
- B. A credentialed external vulnerability scan was performed.
- C. This was normal shift work activity; the SIEM's AI is learning.
- D. A password-spraying attack was performed against the organization.
Answer: D
Explanation:
Reference: https://doubleoctopus.com/security-wiki/threats-and-tools/password-spraying/
NEW QUESTION # 56
A new zero-day vulnerability was discovered within a basic screen capture app, which is used throughout the environment. Two days after discovering the vulnerability, the manufacturer of the software has not announced a remediation or if there will be a fix for this newly discovered vulnerability. The vulnerable application is not uniquely critical, but it is used occasionally by the management and executive management teams. The vulnerability allows remote code execution to gain privileged access to the system. Which of the following is the BEST course of actions to mitigate this threat?
- A. Remove the application and replace it with a similar non-vulnerable application.
- B. Work with the manufacturer to determine the time frame for the fix.
- C. Communicate with the end users that the application should not be used until the manufacturer has resolved the vulnerability.
- D. Block the vulnerable application traffic at the firewall and disable the application services on each computer.
Answer: C
NEW QUESTION # 57
A business recently acquired a software company. The software company's security posture is unknown.
However, based on an assessment, there are limited security controls. No significant security monitoring exists. Which of the following is the NEXT step that should be completed to obtain information about the software company's security posture?
- A. Perform penetration tests against the software company's Internal and external networks
- B. Review relevant network drawings, diagrams and documentation
- C. Develop an asset inventory to determine the systems within the software company
- D. Baseline the software company's network to determine the ports and protocols in use.
Answer: C
NEW QUESTION # 58
A storage area network (SAN) was inadvertently powered off while power maintenance was being performed in a datacenter. None of the systems should have lost all power during the maintenance. Upon review, it is discovered that a SAN administrator moved a power plug when testing the SAN's fault notification features.
Which of the following should be done to prevent this issue from reoccurring?
- A. Install additional batteries in the SAN power supplies with enough capacity to keep the system powered on during maintenance operations.
- B. Ensure power configuration is covered in the datacenter change management policy and have the SAN administrator review this policy.
- C. Ensure both power supplies on the SAN are serviced by separate circuits, so that if one circuit goes down, the other remains powered.
- D. Install a third power supply in the SAN so loss of any power intuit does not result in the SAN completely powering off.
Answer: C
NEW QUESTION # 59
A security analyst was asked to join an outage call for a critical web application. The web middleware support team determined the web server is running and having no trouble processing requests; however, some investigation has revealed firewall denies to the web server that began around 1.00 a.m. that morning. An emergency change was made to enable the access, but management has asked for a root cause determination. Which of the following would be the BEST next step?
- A. Use a port scanner to determine all listening ports on the web server.
- B. Search the logging servers for any rule changes.
- C. Install a packet analyzer near the web server to capture sample traffic to find anomalies.
- D. Block all traffic to the web server with an ACL.
Answer: B
NEW QUESTION # 60
A security analyst is reviewing the following web server log:
Which of the following BEST describes the issue?
- A. Cross-site scripting
- B. Cross-site request forgery
- C. SQL injection
- D. Directory traversal exploit
Answer: D
NEW QUESTION # 61
The security team for a large, international organization is developing a vulnerability management program. The development staff has expressed concern that the new program will cause service interruptions and downtime as vulnerabilities are remedied.
Which of the following should the security team implement FIRST as a core component of the remediation process to address this concern?
- A. Security regression testing
- B. Automated patch management
- C. Isolation of vulnerable servers
- D. Change control procedures
Answer: A
NEW QUESTION # 62
A company has contracted with a software development vendor to design a web portal for customers to access a medical records database. Which of the following should the security analyst recommend to BEST control the unauthorized disclosure of sensitive data when sharing the development database with the vendor?
- A. Set all database tables to read only.
- B. Enable data masking of sensitive data tables in the database.
- C. Use a de-identified data process for the development database.
- D. Establish an NDA with the vendor.
Answer: C
Explanation:
Explanation
https://privacy-analytics.com/resources/videos/what-is-the-difference-between-data-masking-de-identification-an
NEW QUESTION # 63
A security analyst was alerted to a tile integrity monitoring event based on a change to the vhost-paymonts
.conf file The output of the diff command against the known-good backup reads as follows
Which of the following MOST likely occurred?
- A. The file was altered to verify the card numbers are valid.
- B. The file was altered to harvest credit card numbers
- C. The file was altered to avoid logging credit card information
- D. The file was altered to accept payments without charging the cards
Answer: D
NEW QUESTION # 64
A security analyst wants to confirm a finding from a penetration test report on the internal web server. To do so, the analyst logs into the web server using SSH to send the request locally. The report provides a link to https://hrserver.internal/../../etc/passwd, and the server IP address is
10.10.10.15. However, after several attempts, the analyst cannot get the file, despite attempting to get it using different ways, as shown below.
Which of the following would explain this problem? (Choose two.)
- A. Requests can only be sent remotely to the web server
- B. The web server uses SNI to check for a domain name
- C. The web service has not started
- D. The password file is write protected
Answer: B,D
NEW QUESTION # 65
A security analyst has discovered that an outbound SFTP process is occurring at the same time of day for the past several days. At the time this was discovered, large amounts of business critical data were delivered. The authentication for this process occurred using a service account with proper credentials. The security analyst investigated the destination IP for this transfer and discovered that this new process is not documented in the change management log. Which of the following would be the BEST course of action for the analyst to take?
- A. Investigate a potential incident.
- B. Run a vulnerability scan.
- C. Verify user permissions.
- D. Verify SLA with cloud provider.
Answer: A
NEW QUESTION # 66
......
CS0-002 Study Guide Realistic Verified Dumps: https://www.testbraindump.com/CS0-002-exam-prep.html
Self-Study Guide for Becoming an CompTIA Cybersecurity Analyst (CySA+) Certification Exam Expert: https://drive.google.com/open?id=1LSjmawuntnVvtmFM75JLjWp3GuyKSQJf
