Best CS0-001 Exam Dumps for the Preparation of Latest CS0-001 Exam Questions [Q105-Q122]

Share

Best CS0-001 Exam Dumps for the Preparation of Latest CS0-001 Exam Questions

Download Latest & Valid Questions For CompTIA CS0-001 exam

NEW QUESTION # 105
An analyst is observing unusual network traffic from a workstation. The workstation is communicating with a known malicious site over an encrypted tunnel. A full antivirus scan with an updated antivirus signature file does not show any sign of infection. Which of the following has occurred on the workstation?

  • A. Zero-day attack
  • B. Session hijack
  • C. Known malware attack
  • D. Cookie stealing

Answer: A

Explanation:
Explanation/Reference:
Explanation:


NEW QUESTION # 106
A business-critical application is unable to support the requirements in the current password policy because it does not allow the use of special characters. Management does not want to accept the risk of a possible security incident due to weak password standards. Which of the following is an appropriate means to limit the risks related to the application?

  • A. Encrypting authentication traffic
  • B. Creating new account management procedures
  • C. A compensating control
  • D. Altering the password policy

Answer: A

Explanation:
Section: (none)


NEW QUESTION # 107
A security analyst is preparing for the company's upcoming audit. Upon review of the company's latest
vulnerability scan, the security analyst finds the following open issues:

Which of the following vulnerabilities should be prioritized for remediation FIRST?

  • A. Unsupported web server detection
  • B. ICMP timestamp request remote date disclosure
  • C. Microsoft Windows SMB service enumeration via \srvsvc
  • D. Anonymous FTP enabled

Answer: A


NEW QUESTION # 108
A security audit revealed that port 389 has been used instead of 636 when connecting to LDAP for the authentication of users. The remediation recommended by the audit was to switch the port to 636 wherever technically possible. Which of the following is the BEST response?

  • A. Change all devices and servers that support it to 636, as 389 is a reserved port that requires root access and can expose the server to privilege escalation attacks.
  • B. Correct the audit. This finding is a well-known false positive; the services that typically run on 389 and
    636 are identical.
  • C. Correct the audit. This finding is accurate, but the correct remediation is to update encryption keys on each of the servers to match port 636.
  • D. Change all devices and servers that support it to 636, as encrypted services run by default on 636.

Answer: D

Explanation:
Explanation/Reference:
Explanation:


NEW QUESTION # 109
Which of the following is a control that allows a mobile application to access and manipulate information which should only be available by another application on the same mobile device (e.g. a music application posting the name of the current song playing on the device on a social media site)?

  • A. Co-hosted application
  • B. Dual authentication
  • C. Mutually exclusive access
  • D. Transitive trust

Answer: D


NEW QUESTION # 110
A pharmacy gives its clients online access to their records and the ability to review bills and make payments.
A new SSL vulnerability on a special platform was discovered, allowing an attacker to capture the data between the end user and the web server providing these services. After investigating the platform vulnerability, it was determined that the web services provided are being impacted by this new threat.
Which of the following data types are MOST likely at risk of exposure based on this new threat? (Choose two.)

  • A. Intellectual property
  • B. Personal health information
  • C. Cardholder data
  • D. Employee records
  • E. Corporate financial data

Answer: B,C


NEW QUESTION # 111
An analyst performed the following activities:
1. Review the security logs.
2. Install a surveillance camera.
3. Analyst trend reports.
Which of the following job responsibilities is the analyst performing? (select TWO.)

  • A. Implement network devices
  • B. Prevent unauthorized access.
  • C. Implement monitoring controls
  • D. Detect a security incident.
  • E. Encrypt the devices.
  • F. Reduce attack surface of the system.

Answer: B,C


NEW QUESTION # 112
The following IDS log was discovered by a company's cybersecurity analyst:

Which of the following was launched against the company based on the IDS log?

  • A. Online password crack attack
  • B. SQL injection attack
  • C. Cross-site scripting attack
  • D. Buffer overflow attack

Answer: D


NEW QUESTION # 113
A company wants to update its acceptable use policy (AUP) to ensure it relates to the newly implemented password standard, which requires sponsored authentication of guest wireless devices. Which of the following is MOST likely to be incorporated in the AUP?

  • A. Sponsored guest passwords must be at least ten characters in length and contain a symbol.
  • B. Guests using the wireless network should provide valid identification when registering their wireless devices.
  • C. The corporate network should have a wireless infrastructure that uses open authentication standards.
  • D. The network should authenticate all guest users using 802.1x backed by a RADIUS or
    LDAP server.

Answer: B


NEW QUESTION # 114
During the forensic a phase of a security investigation, it was discovered that an attacker was able to find private keys on a poorly secured team shared drive. The attacker used those keys to intercept and decrypt sensitive traffic on a web server. Which of the following describes this type of exploit and the potential remediation?

  • A. Man-in-the-middle; well-controlled storage of private keys
  • B. Session hijacking; network intrusion detection sensors
  • C. Cross-site scripting; increased encryption key sizes
  • D. Rootkit; controlled storage of public keys

Answer: A


NEW QUESTION # 115
A vulnerability scan returned the following results for a web server that hosts multiple wiki sites:
Apache-HTTPD-cve-2014-023: Apache HTTPD: mod_cgid denial of service CVE-2014-
0231
Due to a flaw found in mog_cgid, a server using mod_cgid to host CGI scripts could be vulnerable to a DoS attack caused by a remote attacker who is exploiting a weakness in non-standard input, causing processes to hang indefinitely.

The security analyst has confirmed the server hosts standard CGI scripts for the wiki sites, does not have mod_cgid installed, is running Apache 2.2.22, and is not behind a WAF. The server is located in the DMZ, and the purpose of the server is to allow customers to add entries into a publicly accessible database.
Which of the following would be the MOST efficient way to address this finding?

  • A. Upgrade to the newest version of Apache.
  • B. Disable the HTTP service and use only HTTPS to access the server.
  • C. Place the server behind a WAF to prevent DoS attacks from occurring.
  • D. Document the finding as a false positive.

Answer: D


NEW QUESTION # 116
An administrator has been investigating the way in which an actor had been exfiltrating confidential data from a web server to a foreign host. After a thorough forensic review, the administrator determined the server's BIOS had been modified by rootkit installation. After removing the rootkit and flashing the BIOS to a known good state, which of the following would BEST protect against future adversary access to the BIOS, in case another rootkit is installed?

  • A. File integrity monitoring
  • B. TPM data sealing
  • C. Anti-malware application
  • D. Host-based IDS

Answer: B

Explanation:
Section: (none)


NEW QUESTION # 117
A cybersecurity analyst traced the source of an attack to compromised user credentials.
Log analysis revealed that the attacker successfully authenticated from an unauthorized foreign country. Management asked the security analyst to research and implement a solution to help mitigate attacks based on compromised passwords. Which of the following should the analyst implement?

  • A. Self-service password reset
  • B. Password complexity
  • C. Context-based authentication
  • D. Single sign-on

Answer: C


NEW QUESTION # 118
A security analyst has determined the security team should take action based on the following log:

Which of the following should be used to improve the security posture of the system?

  • A. Limit the number of unsuccessful login attempts
  • B. Upgrade the firewalls
  • C. Increase password complexity requirements
  • D. Enable login account auditing.

Answer: A


NEW QUESTION # 119
A computer has been infected with a virus and is sending out a beacon to command and control server through an unknown service. Which of the following should a security technician implement to drop the traffic going to the command and control server and still be able to identify the infected host through firewall logs?

  • A. Sinkhole
  • B. Block ports and services
  • C. Patches
  • D. Endpoint security

Answer: A

Explanation:
Explanation/Reference:
reference https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-DNS-Sinkhole/ta- p/58891


NEW QUESTION # 120
After analyzing and correlating activity from multiple sensors, the security analyst has determined a group from a high-risk country is responsible for a sophisticated breach of the company network and continuous administration of targeted attacks for the past three months. Until now, the attacks went unnoticed. This is an example of:

  • A. malicious insider threat.
  • B. advanced persistent threat.
  • C. spear phishing.
  • D. privilege escalation.

Answer: B

Explanation:
Explanation/Reference:


NEW QUESTION # 121
During a routine review of firewall logs, an analyst identified that an IP address from the organization's server subnet had been connecting during nighttime hours to a foreign IP address, and had been sending between 150 and 500 megabytes of data each time. This had been going on for approximately one week, and the affected server was taken offline for forensic review. Which of the following is MOST likely to drive up the incident's impact assessment?

  • A. Forensic review of the server required fall-back on a less efficient service.
  • B. IP addresses and other network-related configurations were exfiltrated.
  • C. Raw financial information about the company was accessed.
  • D. The local root password for the affected server was compromised.
  • E. PII of company employees and customers was exfiltrated.

Answer: E

Explanation:
Explanation/Reference:
Explanation:


NEW QUESTION # 122
......

Exam Materials for You to Prepare & Pass CS0-001 Exam: https://www.actual4exams.com/CS0-001-valid-dump.html