CompTIA Cybersecurity Analyst (CySA+) Certification - CS0-001 Exam Practice Test

When performing reverse engineering, which of the following file types would be MOST easily decompiled Into source code?
Correct Answer: A Vote an answer
A cybersecurity analyst is reviewing log data and sees the output below:

Which of the following technologies MOST likely generated this log?
Correct Answer: D Vote an answer
During a quarterly review of user accounts and activity, a security analyst noticed that after a password reset the head of human resources has been logging in from multiple locations, including several overseas. Further review of the account showed access rights to a number of corporate applications, including a sensitive accounting application used for employee bonuses. Which of the following security methods could be used to mitigate this risk?
Correct Answer: C Vote an answer
An organization wants to perform network scans to Identify active hosts and vulnerabilities. Management places the highest priority on scans that mimic how an attack would progress. Iftime and resources allow, subsequent scans can be performed using different techniques and methods. Which of the following scan types and sequences would BEST suit the organization's requirements?
Correct Answer: C Vote an answer
An analyst wants to use a command line tool to identify open ports and running services on a host along with the application that is associated with those services and port. Which of the following should the analyst use?
Correct Answer: D Vote an answer
During an investigation, a computer is being seized. Which of the following is the FIRST step the analyst should take?
Correct Answer: B Vote an answer
A security analyst must perform quarterly vulnerability scans to keep the organization In compliance with PCI regulations. The analyst has scheduled the scans to occur early on Monday mornings and uses Nexpose on 192.168.65.32 to run scans on the entire network. The morning after the scan was run. the analyst received the following alert from the network-based IDS system:

Which of the following would be the BEST way to address this alert while remaining in compliance with PCI regulations?
Correct Answer: A Vote an answer
A cybersecurity analyst has been asked to follow a corporate process that will be used to manage vulnerabilities for an organization. The analyst notices the policy has not been updated in three years. Which of the following should the analyst check to ensure the policy is still accurate?
Correct Answer: B Vote an answer
A security analyst is performing ongoing scanning and continuous monitoring of the corporate datacenter. Over time, these scans are repeatedly showing susceptibility to the same vulnerabilities and an increase in new vulnerabilities on a specific group of servers that are clustered to run the same application. Which of the following vulnerability management processes should be implemented?
Correct Answer: A Vote an answer
A centralized tool for organizing security events and managing their response and resolution is known as:
Correct Answer: B Vote an answer