Real CS0-002 dumps - Real CompTIA dumps PDF in here [Feb-2022]
Realistic PassTestking CS0-002 Dumps PDF - 100% Passing Guarantee
For more information visit:
CompTIA CS0-002 Exam Reference
Incident Response: 22%
- Analyzing possible indicators of compromise: this domain includes network-related, host-related, and application-related compromises.
- Applying the relevant incident response procedure: this subject area covers competence in preparation, detection and analysis, containment, eradication & recovery, and post-incident events.
- Using fundamental forensics methods: this objective covers network, Endpoint, mobile, Cloud, virtualization, legal hold, procedures, hashing, carving, and data acquisition.
CompTIA CS0-002 Exam Syllabus Topics:
| Topic | Details |
|---|---|
Threat and Vulnerability Management - 22% | |
| Explain the importance of threat data and intelligence. | 1. Intelligence sources
2. Confidence levels
4. Threat classification
5. Threat actors
6. Intelligence cycle
7. Commodity malware
|
| Given a scenario, utilize threat intelligence to support organizational security. | 1. Attack frameworks
2. Threat research
3. Threat modeling methodologies
3. Threat intelligence sharing with supported functions
|
| Given a scenario, perform vulnerability management activities. | 1. Vulnerability identification
2. Validation
3. Remediation/mitigation
4. Scanning parameters and criteria
5. Inhibitors to remediation
|
| Given a scenario, analyze the output from common vulnerability assessment tools. | 1.Web application scanner
2.Infrastructure vulnerability scanner
3.Software assessment tools and techniques
4.Enumeration
5. Wireless assessment tools
6. Cloud infrastructure assessment tools
|
| Explain the threats and vulnerabilities associated with specialized technology. | 1. Mobile 2. Internet of Things (IoT) 3. Embedded 4. Real-time operating system (RTOS) 5. System-on-Chip (SoC) 6. Field programmable gate array (FPGA) 7. Physical access control 8. Building automation systems 9. Vehicles and drones
10. Workflow and process automation systems
|
| Explain the threats and vulnerabilities associated with operating in the cloud. | 1. Cloud service models
2. Cloud deployment models
3. Function as a Service (FaaS)/serverless architecture
|
| Given a scenario, implement controls to mitigate attacks and software vulnerabilities. | 1. Attack types
2. Vulnerabilities
|
Software and Systems Security - 18% | |
| Given a scenario, apply security solutions for infrastructure management. | 1. Cloud vs. on-premises 2. Asset management
3. Segmentation
4. Network architecture
5. Change management
7. Containerization
9. Cloud access security broker (CASB) |
| Explain software assurance best practices. | 1. Platforms Mobile Web application Client/server Embedded System-on-chip (SoC) Firmware 2. Software development life cycle (SDLC) integration 3. DevSecOps 4. Software assessment methods User acceptance testing Stress test application Security regression testing Code review 5. Secure coding best practices Input validation Output encoding Session management Authentication Data protection Parameterized queries 6. Static analysis tools 7. Dynamic analysis tools 8. Formal methods for verification of critical software 9. Service-oriented architecture
|
| Explain hardware assurance best practices. | 1. Hardware root of trust Trusted platform module (TPM) Hardware security module (HSM) 2. eFuse 3. Unified Extensible Firmware Interface (UEFI) 4. Trusted foundry 5. Secure processing
6. Anti-tamper |
Security Operations and Monitoring - 25% | |
| Given a scenario, analyze data as part of security monitoring activities. | 1. Heuristics 2. Trend analysis 3. Endpoint
4. Network
5. Log review
6. Impact analysis
7. Security information and event management (SIEM) review
8. Query writing
9. E-mail analysis
|
| Given a scenario, implement configuration changes to existing controls to improve security. | 1. Permissions 2. Whitelisting 3. Blacklisting 4. Firewall 5. Intrusion prevention system (IPS) rules 6. Data loss prevention (DLP) 7. Endpoint detection and response (EDR) 8. Network access control (NAC) 9. Sinkholing 10. Malware signatures
11. Sandboxing |
NEW QUESTION 156
While reviewing web server logs, a security analyst notices the following code:
Which of the following would prevent this code from performing malicious actions?
- A. Installing a network firewall in front of the application
- B. Requiring the application to use input validation
- C. Performing web application penetration testing
- D. Disabling the use of HTTP and requiring the use of HTTPS
Answer: D
NEW QUESTION 157
A security analyst is reviewing the logs from an internal chat server. The chat.logfile is too large to review manually, so the analyst wants to create a shorter log file that only includes lines associated with a user demonstrating anomalous activity. Below is a snippet of the log:
Which of the following commands would work BEST to achieve the desired result?
- A. grep -v javashark chat.log
- B. grep -v chatter14 chat.log
- C. grep -i pythonfun chat.log
- D. grep -v pythonfun chat.log
- E. grep -i javashark chat.log
- F. grep -i chatter14 chat.log
Answer: A
NEW QUESTION 158
A company's marketing emails are either being found in a spam folder or not being delivered at all. The security analyst investigates the issue and discovers the emails in question are being sent on behalf of the company by a third party in1marketingpartners.com Below is the exiting SPP word:
Which of the following updates to the SPF record will work BEST to prevent the emails from being marked as spam or blocked?
A)
B)
C)
D)
- A. Option B
- B. Option D
- C. Option C
- D. Option A
Answer: A
NEW QUESTION 159
During a cyber incident, which of the following is the BEST course of action?
- A. Keep the entire company informed to ensure transparency and integrity during the incident.
- B. Switch to using a pre-approved, secure, third-party communication system.
- C. Restrict customer communication until the severity of the breach is confirmed.
- D. Limit communications to pre-authorized parties to ensure response efforts remain confidential.
Answer: D
NEW QUESTION 160
The help desk informed a security analyst of a trend that is beginning to develop regarding a suspicious email that has been reported by multiple users.
The analyst has determined the email includes an attachment named invoice.zip that contains the following files:
Locky.js
xerty.ini
xerty.lib
Further analysis indicates that when the .zip file is opened, it is installing a new version of ransomware on the devices.
Which of the following should be done FIRST to prevent data on the company NAS from being encrypted by infected devices?
- A. Set permissions on file shares to read-only.
- B. Add the URL included in the .js file to the company's web proxy filter.
- C. Email employees instructing them not to open the invoice attachment.
- D. Disable access to the company VPN.
Answer: C
NEW QUESTION 161
A security analyst needs to assess the web server versions on a list of hosts to determine which are running a vulnerable version of the software and output that list into an XML file named Webserverlist. Xml. The host list is provided in a file named werbserverlist,text. Which of the fallowing Nmap commands would BEST accomplish this goal?
A)
B)
C)
D)
- A. Option D
- B. Option C
- C. Option B
- D. Option A
Answer: D
NEW QUESTION 162
A technician is troubleshooting a desktop computer with low disk space. The technician reviews the following information snippets:
Which of the following should the technician do to BEST resolve the issue based on the above information? (Choose two.)
- A. Disable the movieDB service
- B. Enable OS auto updates
- C. Delete the movies/movies directory
- D. Install a file integrity tool
- E. Defragment the disk
Answer: A,E
NEW QUESTION 163
A security analyst for a large pharmaceutical company was given credentials from a threat intelligence resources organisation for Internal users, which contain usernames and valid passwords for company accounts.
Which of the following is the FIRST action the analyst should take as part of security operations monitoring?
- A. Change all the user passwords to ensure the malicious actors cannot use them.
- B. Run scheduled antivirus scans on all employees' machines to look for malicious processes.
- C. Reimage the machines of all users within the group in case of a malware infection.
- D. Search the event logs for event identifiers that indicate Mimikatz was used.
Answer: A
NEW QUESTION 164
An analyst is observing unusual network traffic from a workstation. The workstation is communicating with a known malicious site over an encrypted tunnel.
A full antivirus scan with an updated antivirus signature file does not show any sign of infection.
Which of the following has occurred on the workstation?
- A. Known malware attack
- B. Zero-day attack
- C. Cookie stealing
- D. Session hijack
Answer: B
NEW QUESTION 165
Which of the following sets of attributes BEST illustrates the characteristics of an insider threat from a security perspective?
- A. Authorized, unintentional, benign
- B. Unauthorized, intentional, malicious
- C. Authorized, intentional, malicious
- D. Unauthorized, unintentional, benign
Answer: C
NEW QUESTION 166
Which of the following session management techniques will help to prevent a session identifier from being stolen via an XSS attack?
- A. Ensuring the session identifier length is sufficient
- B. Utilizing transport layer encryption on all requests
- C. Implementing session cookies with the HttpOnly flag
- D. Creating proper session identifier entropy
- E. Applying a secure attribute on session cookies
Answer: D
NEW QUESTION 167
During an investigation, a security analyst identified machines that are infected with malware the antivirus was unable to detect.
Which of the following is the BEST place to acquire evidence to perform data carving?
- A. Network packets
- B. The system memory
- C. The Windows Registry
- D. The hard drive
Answer: B
Explanation:
Explanation/Reference: https://resources.infosecinstitute.com/memory-forensics/#gref
https://www.computerhope.com/jargon/d/data-carving.htm
NEW QUESTION 168
An analyst performs a routine scan of a host using Nmap and receives the following output:
Which of the following should the analyst investigate FIRST?
- A. Port 22
- B. Port 21
- C. Port 23
- D. Port 80
Answer: B
NEW QUESTION 169
A large amount of confidential data was leaked during a recent security breach. As part of a forensic investigation, the security team needs to identify the various types of traffic that were captured between two compromised devices.
Which of the following should be used to identify the traffic?
- A. Hashing
- B. Disk imaging
- C. Memory dump
- D. Carving
- E. Packet analysis
Answer: E
NEW QUESTION 170
Which of the following policies BEST explains the purpose of a data ownership policy?
- A. The policy should outline the organization's administration of accounts for authorized users to access the appropriate data.
- B. The policy should describe the roles and responsibilities between users and managers, and the management of specific data types.
- C. The policy should document practices that users must adhere to in order to access data on the corporate network or Internet.
- D. The policy should establish the protocol for retaining information types based on regulatory or business needs.
Answer: A
NEW QUESTION 171
Which of the following sources would a security analyst rely on to provide relevant and timely threat information concerning the financial services industry?
- A. Common vulnerability and exposure bulletins
- B. Real-time and automated firewall rules subscriptions
- C. Information sharing and analysis membership
- D. Open-source intelligence, such as social media and blogs
Answer: C
NEW QUESTION 172
A security analyst is building a malware analysis lab. The analyst wants to ensure malicious applications are not capable of escaping the virtual machines and pivoting to other networks.
To BEST mitigate this risk, the analyst should use.
- A. an unmanaged switch to segment the environments from one another.
- B. an 802.11ac wireless bridge to create an air gap.
- C. a firewall to isolate the lab network from all other networks.
- D. a managed switch to segment the lab into a separate VLAN.
Answer: D
NEW QUESTION 173
......
Verified CS0-002 dumps Q&As Latest CS0-002 Download: https://www.passtestking.com/CompTIA/CS0-002-practice-exam-dumps.html
Free CompTIA CS0-002 Exam Questions and Answer: https://drive.google.com/open?id=1JJdfUTGAfhXy5baENKkAmXOFMKAyALfF