[Q156-Q173] Real CS0-002 dumps - Real CompTIA dumps PDF in here [Feb-2022]

Share

Real CS0-002 dumps - Real CompTIA dumps PDF in here [Feb-2022]

Realistic PassTestking CS0-002 Dumps PDF - 100% Passing Guarantee


For more information visit:

CompTIA CS0-002 Exam Reference


Incident Response: 22%

  • Analyzing possible indicators of compromise: this domain includes network-related, host-related, and application-related compromises.
  • Applying the relevant incident response procedure: this subject area covers competence in preparation, detection and analysis, containment, eradication & recovery, and post-incident events.
  • Using fundamental forensics methods: this objective covers network, Endpoint, mobile, Cloud, virtualization, legal hold, procedures, hashing, carving, and data acquisition.

CompTIA CS0-002 Exam Syllabus Topics:

TopicDetails

Threat and Vulnerability Management - 22%

Explain the importance of threat data and intelligence.1. Intelligence sources
  • Open-source intelligence
  • Proprietary/closed-source intelligence
  • Timeliness
  • Relevancy
  • Accuracy

2. Confidence levels
3. Indicator management

  • Structured Threat Information eXpression (STIX)
  • Trusted Automated eXchange of Indicator Information (TAXII)
  • OpenIoC

4. Threat classification

  • Known threat vs. unknown threat
  • Zero-day
  • Advanced persistent threat

5. Threat actors

  • Nation-state
  • Hacktivist
  • Organized crime
  • Insider threat
    Intentional
    Unintentional

6. Intelligence cycle

  • Requirements
  • Collection
  • Analysis
  • Dissemination
  • Feedback

7. Commodity malware
8. Information sharing and analysis communities

  • Healthcare
  • Financial
  • Aviation
  • Government
  • Critical infrastructure
Given a scenario, utilize threat intelligence to support organizational security.1. Attack frameworks
  • MITRE ATT&CK
  • The Diamond Model of Intrusion Analysis
  • Kill chain

2. Threat research

  • Reputational
  • Behavioral
  • Indicator of compromise (IoC)
  • Common vulnerability scoring system (CVSS)

3. Threat modeling methodologies

  • Adversary capability
  • Total attack surface
  • Attack vector
  • Impact
  • Likelihood

3. Threat intelligence sharing with supported functions

  • Incident response
  • Vulnerability management
  • Risk management
  • Security engineering
  • Detection and monitoring
Given a scenario, perform vulnerability management activities.1. Vulnerability identification
  • Asset criticality
  • Active vs. passive scanning
  • Mapping/enumeration

2. Validation

  • True positive
  • False positive
  • True negative
  • False negative

3. Remediation/mitigation

  • Configuration baseline
  • Patching
  • Hardening
  • Compensating controls
  • Risk acceptance
  • Verification of mitigation

4. Scanning parameters and criteria

  • Risks associated with scanning activities
  • Vulnerability feed
  • Scope
  • Credentialed vs. non-credentialed
  • Server-based vs. agent-based
  • Internal vs. external
  • Special considerations
    Types of data
    Technical constraints
    Workflow
    Sensitivity levels
    Regulatory requirements
    Segmentation
    Intrusion prevention system (IPS), intrusion detection system (IDS), and firewall settings

5. Inhibitors to remediation

  • Memorandum of understanding (MOU)
  • Service-level agreement (SLA)
  • Organizational governance
  • Business process interruption
  • Degrading functionality
  • Legacy systems
  • Proprietary systems
Given a scenario, analyze the output from common vulnerability assessment tools.1.Web application scanner
  • OWASP Zed Attack Proxy (ZAP)
  • Burp suite
  • Nikto
  • Arachni

2.Infrastructure vulnerability scanner

  • Nessus
  • OpenVAS
  • Qualys

3.Software assessment tools and techniques

  • Static analysis
  • Dynamic analysis
  • Reverse engineering
  • Fuzzing

4.Enumeration

  • Nmap
  • hping
  • Active vs. passive
  • Responder

5. Wireless assessment tools

  • Aircrack-ng
  • Reaver
  • oclHashcat

6. Cloud infrastructure assessment tools

  • ScoutSuite
  • Prowler
  • Pacu
Explain the threats and vulnerabilities associated with specialized technology.1. Mobile
2. Internet of Things (IoT)
3. Embedded
4. Real-time operating system (RTOS)
5. System-on-Chip (SoC)
6. Field programmable gate array (FPGA)
7. Physical access control
8. Building automation systems
9. Vehicles and drones
  • CAN bus

10. Workflow and process automation systems
11. Industrial control system
12. Supervisory control and data acquisition (SCADA)

  • Modbus
Explain the threats and vulnerabilities associated with operating in the cloud.1. Cloud service models
  • Software as a Service (SaaS)
  • Platform as a Service (PaaS)
  • Infrastructure as a Service (IaaS)

2. Cloud deployment models

  • Public
  • Private
  • Community
  • Hybrid

3. Function as a Service (FaaS)/serverless architecture
4. Infrastructure as code (IaC)
5. Insecure application programming interface (API)
6. Improper key management
7. Unprotected storage
8. Logging and monitoring

  • Insufficient logging and monitoring
  • Inability to access
Given a scenario, implement controls to mitigate attacks and software vulnerabilities.1. Attack types
  • Extensible markup language (XML) attack
  • Structured query language (SQL) injection
  • Overflow attack
    Buffer
    Integer
    Heap
  • Remote code execution
  • Directory traversal
  • Privilege escalation
  • Password spraying
  • Credential stuffing
  • Impersonation
  • Man-in-the-middle attack
  • Session hijacking
  • Rootkit
  • Cross-site scripting
    Reflected
    Persistent
    Document object model (DOM)

2. Vulnerabilities

  • Improper error handling
  • Dereferencing
  • Insecure object reference
  • Race condition
  • Broken authentication
  • Sensitive data exposure
  • Insecure components
  • Insufficient logging and monitoring
  • Weak or default configurations
  • Use of insecure functions
    strcpy

Software and Systems Security - 18%

Given a scenario, apply security solutions for infrastructure management.1. Cloud vs. on-premises
2. Asset management
  • Asset tagging

3. Segmentation

  • Physical
  • Virtual
  • Jumpbox
  • System isolation
    Air gap

4. Network architecture

  • Physical
  • Software-defined
  • Virtual private cloud (VPC)
  • Virtual private network (VPN)
  • Serverless

5. Change management
6. Virtualization

  • Virtual desktop infrastructure (VDI)

7. Containerization
8. Identity and access management

  • Privilege management
  • Multifactor authentication (MFA)
  • Single sign-on (SSO)
  • Federation
  • Role-based
  • Attribute-based
  • Mandatory
  • Manual review

9. Cloud access security broker (CASB)
10. Honeypot
11. Monitoring and logging
12. Encryption
13. Certificate management
14. Active defense

Explain software assurance best practices.1. Platforms
Mobile
Web application
Client/server
Embedded
System-on-chip (SoC)
Firmware
2. Software development life cycle (SDLC) integration
3. DevSecOps
4. Software assessment methods
User acceptance testing
Stress test application
Security regression testing
Code review
5. Secure coding best practices
Input validation
Output encoding
Session management
Authentication
Data protection
Parameterized queries
6. Static analysis tools
7. Dynamic analysis tools
8. Formal methods for verification of critical software
9. Service-oriented architecture
  • Security AssertionsMarkup Language (SAML)
  • Simple Object Access Protocol (SOAP)
  • Representational State Transfer (REST)
  • Microservices
Explain hardware assurance best practices.1. Hardware root of trust
Trusted platform module (TPM)
Hardware security module (HSM)
2. eFuse
3. Unified Extensible Firmware Interface (UEFI)
4. Trusted foundry
5. Secure processing
  • Trusted execution
  • Secure enclave
  • Processor security extensions
  • Atomic execution

6. Anti-tamper
7. Self-encrypting drive
8. Trusted firmware updates
9. Measured boot and attestation
10. Bus encryption

Security Operations and Monitoring - 25%

Given a scenario, analyze data as part of security monitoring activities.1. Heuristics
2. Trend analysis
3. Endpoint
  • Malware
    Reverse engineering
  • Memory
  • System and application behavior
    Known-good behavior
    Anomalous behavior
    Exploit techniques
  • File system
  • User and entity behavior analytics (UEBA)

4. Network

  • Uniform Resource Locator (URL) and domain name system (DNS) analysis
    Domain generation algorithm
  • Flow analysis
  • Packet and protocol analysis
    Malware

5. Log review

  • Event logs
  • Syslog
  • Firewall logs
  • Web application firewall (WAF)
  • Proxy
  • Intrusion detection system (IDS)/Intrusion prevention system (IPS)

6. Impact analysis

  • Organization impact vs. localized impact
  • Immediate vs. total

7. Security information and event management (SIEM) review

  • Rule writing
  • Known-bad Internet protocol (IP)
  • Dashboard

8. Query writing

  • String search
  • Script
  • Piping

9. E-mail analysis

  • Malicious payload
  • Domain Keys Identified Mail (DKIM)
  • Domain-based Message Authentication, Reporting, and Conformance (DMARC)
  • Sender Policy Framework (SPF)
  • Phishing
  • Forwarding
  • Digital signature
  • E-mail signature block
  • Embedded links
  • Impersonation
  • Header
Given a scenario, implement configuration changes to existing controls to improve security.1. Permissions
2. Whitelisting
3. Blacklisting
4. Firewall
5. Intrusion prevention system (IPS) rules
6. Data loss prevention (DLP)
7. Endpoint detection and response (EDR)
8. Network access control (NAC)
9. Sinkholing
10. Malware signatures
  • Development/rule writing

11. Sandboxing
12. Port security


 

NEW QUESTION 156
While reviewing web server logs, a security analyst notices the following code:

Which of the following would prevent this code from performing malicious actions?

  • A. Installing a network firewall in front of the application
  • B. Requiring the application to use input validation
  • C. Performing web application penetration testing
  • D. Disabling the use of HTTP and requiring the use of HTTPS

Answer: D

 

NEW QUESTION 157
A security analyst is reviewing the logs from an internal chat server. The chat.logfile is too large to review manually, so the analyst wants to create a shorter log file that only includes lines associated with a user demonstrating anomalous activity. Below is a snippet of the log:

Which of the following commands would work BEST to achieve the desired result?

  • A. grep -v javashark chat.log
  • B. grep -v chatter14 chat.log
  • C. grep -i pythonfun chat.log
  • D. grep -v pythonfun chat.log
  • E. grep -i javashark chat.log
  • F. grep -i chatter14 chat.log

Answer: A

 

NEW QUESTION 158
A company's marketing emails are either being found in a spam folder or not being delivered at all. The security analyst investigates the issue and discovers the emails in question are being sent on behalf of the company by a third party in1marketingpartners.com Below is the exiting SPP word:

Which of the following updates to the SPF record will work BEST to prevent the emails from being marked as spam or blocked?
A)

B)

C)

D)

  • A. Option B
  • B. Option D
  • C. Option C
  • D. Option A

Answer: A

 

NEW QUESTION 159
During a cyber incident, which of the following is the BEST course of action?

  • A. Keep the entire company informed to ensure transparency and integrity during the incident.
  • B. Switch to using a pre-approved, secure, third-party communication system.
  • C. Restrict customer communication until the severity of the breach is confirmed.
  • D. Limit communications to pre-authorized parties to ensure response efforts remain confidential.

Answer: D

 

NEW QUESTION 160
The help desk informed a security analyst of a trend that is beginning to develop regarding a suspicious email that has been reported by multiple users.
The analyst has determined the email includes an attachment named invoice.zip that contains the following files:
Locky.js

xerty.ini

xerty.lib

Further analysis indicates that when the .zip file is opened, it is installing a new version of ransomware on the devices.
Which of the following should be done FIRST to prevent data on the company NAS from being encrypted by infected devices?

  • A. Set permissions on file shares to read-only.
  • B. Add the URL included in the .js file to the company's web proxy filter.
  • C. Email employees instructing them not to open the invoice attachment.
  • D. Disable access to the company VPN.

Answer: C

 

NEW QUESTION 161
A security analyst needs to assess the web server versions on a list of hosts to determine which are running a vulnerable version of the software and output that list into an XML file named Webserverlist. Xml. The host list is provided in a file named werbserverlist,text. Which of the fallowing Nmap commands would BEST accomplish this goal?
A)

B)

C)

D)

  • A. Option D
  • B. Option C
  • C. Option B
  • D. Option A

Answer: D

 

NEW QUESTION 162
A technician is troubleshooting a desktop computer with low disk space. The technician reviews the following information snippets:

Which of the following should the technician do to BEST resolve the issue based on the above information? (Choose two.)

  • A. Disable the movieDB service
  • B. Enable OS auto updates
  • C. Delete the movies/movies directory
  • D. Install a file integrity tool
  • E. Defragment the disk

Answer: A,E

 

NEW QUESTION 163
A security analyst for a large pharmaceutical company was given credentials from a threat intelligence resources organisation for Internal users, which contain usernames and valid passwords for company accounts.
Which of the following is the FIRST action the analyst should take as part of security operations monitoring?

  • A. Change all the user passwords to ensure the malicious actors cannot use them.
  • B. Run scheduled antivirus scans on all employees' machines to look for malicious processes.
  • C. Reimage the machines of all users within the group in case of a malware infection.
  • D. Search the event logs for event identifiers that indicate Mimikatz was used.

Answer: A

 

NEW QUESTION 164
An analyst is observing unusual network traffic from a workstation. The workstation is communicating with a known malicious site over an encrypted tunnel.
A full antivirus scan with an updated antivirus signature file does not show any sign of infection.
Which of the following has occurred on the workstation?

  • A. Known malware attack
  • B. Zero-day attack
  • C. Cookie stealing
  • D. Session hijack

Answer: B

 

NEW QUESTION 165
Which of the following sets of attributes BEST illustrates the characteristics of an insider threat from a security perspective?

  • A. Authorized, unintentional, benign
  • B. Unauthorized, intentional, malicious
  • C. Authorized, intentional, malicious
  • D. Unauthorized, unintentional, benign

Answer: C

 

NEW QUESTION 166
Which of the following session management techniques will help to prevent a session identifier from being stolen via an XSS attack?

  • A. Ensuring the session identifier length is sufficient
  • B. Utilizing transport layer encryption on all requests
  • C. Implementing session cookies with the HttpOnly flag
  • D. Creating proper session identifier entropy
  • E. Applying a secure attribute on session cookies

Answer: D

 

NEW QUESTION 167
During an investigation, a security analyst identified machines that are infected with malware the antivirus was unable to detect.
Which of the following is the BEST place to acquire evidence to perform data carving?

  • A. Network packets
  • B. The system memory
  • C. The Windows Registry
  • D. The hard drive

Answer: B

Explanation:
Explanation/Reference: https://resources.infosecinstitute.com/memory-forensics/#gref
https://www.computerhope.com/jargon/d/data-carving.htm

 

NEW QUESTION 168
An analyst performs a routine scan of a host using Nmap and receives the following output:

Which of the following should the analyst investigate FIRST?

  • A. Port 22
  • B. Port 21
  • C. Port 23
  • D. Port 80

Answer: B

 

NEW QUESTION 169
A large amount of confidential data was leaked during a recent security breach. As part of a forensic investigation, the security team needs to identify the various types of traffic that were captured between two compromised devices.
Which of the following should be used to identify the traffic?

  • A. Hashing
  • B. Disk imaging
  • C. Memory dump
  • D. Carving
  • E. Packet analysis

Answer: E

 

NEW QUESTION 170
Which of the following policies BEST explains the purpose of a data ownership policy?

  • A. The policy should outline the organization's administration of accounts for authorized users to access the appropriate data.
  • B. The policy should describe the roles and responsibilities between users and managers, and the management of specific data types.
  • C. The policy should document practices that users must adhere to in order to access data on the corporate network or Internet.
  • D. The policy should establish the protocol for retaining information types based on regulatory or business needs.

Answer: A

 

NEW QUESTION 171
Which of the following sources would a security analyst rely on to provide relevant and timely threat information concerning the financial services industry?

  • A. Common vulnerability and exposure bulletins
  • B. Real-time and automated firewall rules subscriptions
  • C. Information sharing and analysis membership
  • D. Open-source intelligence, such as social media and blogs

Answer: C

 

NEW QUESTION 172
A security analyst is building a malware analysis lab. The analyst wants to ensure malicious applications are not capable of escaping the virtual machines and pivoting to other networks.
To BEST mitigate this risk, the analyst should use.

  • A. an unmanaged switch to segment the environments from one another.
  • B. an 802.11ac wireless bridge to create an air gap.
  • C. a firewall to isolate the lab network from all other networks.
  • D. a managed switch to segment the lab into a separate VLAN.

Answer: D

 

NEW QUESTION 173
......

Verified CS0-002 dumps Q&As Latest CS0-002 Download: https://www.passtestking.com/CompTIA/CS0-002-practice-exam-dumps.html

Free CompTIA CS0-002 Exam Questions and Answer: https://drive.google.com/open?id=1JJdfUTGAfhXy5baENKkAmXOFMKAyALfF