Latest [Sep 14, 2021] CompTIA CS0-002 Exam Practice Test To Gain Brilliante Result
Take a Leap Forward in Your Career by Earning CompTIA CS0-002
NEW QUESTION 62
Given the following log snippet:
Which of the following describes the events that have occurred?
- A. An attempt to make an SSH connection from "superman" was done using a password.
- B. An attempt to make an SSH connection from outside the network was done using PKI.
- C. An attempt to make an SSH connection from 192.168.1.166 was done using PKI.
- D. An attempt to make an SSH connection from an unknown IP address was done using a password.
Answer: C
NEW QUESTION 63
A business recently installed a kiosk that is running on a hardened operating system as a restricted user. The kiosk user application is the only application that is allowed to run. A security analyst gets a report that pricing data is being modified on the server, and management wants to know how this is happening. After reviewing the logs, the analyst discovers the root account from the kiosk is accessing the files. After validating the permissions on the server, the analyst confirms the permissions from the kiosk do not allow to write to the server data.
Which of the following is the MOST likely reason for the pricing data modifications on the server?
- A. The kiosk user account has execute permissions on the server data files.
- B. Customers are escaping the application shell and gaining root-level access.
- C. Customers are logging off the kiosk and guessing the root account password.
- D. Data on the server is not encrypted, allowing users to change the pricing data.
Answer: B
NEW QUESTION 64
A staff member reported that a laptop has degraded performance. The security analyst has investigated the issue and discovered that CPU utilization, memory utilization, and outbound network traffic are consuming the laptop resources. Which of the following is the BEST course of actions to resolve the problem?
- A. Identify and remove malicious processes.
- B. Suspend virus scan.
- C. Increase laptop memory.
- D. Ensure the laptop OS is properly patched.
- E. Disable scheduled tasks.
Answer: A
NEW QUESTION 65
You are a cybersecurity analyst tasked with interpreting scan data from Company A's servers. You must verify the requirements are being met for all of the servers and recommend changes if you find they are not.
The company's hardening guidelines indicate the following:
* TLS 1.2 is the only version of TLS running.
* Apache 2.4.18 or greater should be used.
* Only default ports should be used.
INSTRUCTIONS
Using the supplied data, record the status of compliance with the company's guidelines for each server.
The question contains two parts: make sure you complete Part 1 and Part 2. Make recommendations for issues based ONLY on the hardening guidelines provided.




Answer:
Explanation:
See explanation below.
Explanation
Part 1 answer:
Check on the following:
AppServ1 is only using TLS.1.2
AppServ4 is only using TLS.1.2
AppServ1 is using Apache 2.4.18 or greater
AppServ3 is using Apache 2.4.18 or greater
AppServ4 is using Apache 2.4.18 or greater
Part 2 answer:
Recommendation:
Recommendation is to disable TLS v1.1 on AppServ2 and AppServ3. Also upgrade AppServ2 Apache to version 2.4.48 from its current version of 2.3.48
NEW QUESTION 66
A security analyst is investigating a compromised Linux server.
The analyst issues the ps command and receives the following output.
Which of the following commands should the administrator run NEXT to further analyze the compromised system?
- A. kill -9 1301
- B. strace /proc/1301
- C. rpm -V openash-server
- D. /bin/la -1 /proc/1301/exe
Answer: B
NEW QUESTION 67
Who is the best facilitator for a post-incident lessons-learned session?
- A. Independent facilitator
- B. CEO
- C. First responder
- D. CSIRT leader
Answer: A
NEW QUESTION 68
A company wants to update its acceptable use policy (AUP) to ensure it relates to the newly implemented password standard, which requires sponsored authentication of guest wireless devices. Which of the following is MOST likely to be incorporated in the AUP?
- A. The corporate network should have a wireless infrastructure that uses open authentication standards.
- B. Sponsored guest passwords must be at least ten characters in length and contain a symbol.
- C. Guests using the wireless network should provide valid identification when registering their wireless devices.
- D. The network should authenticate all guest users using 802.1x backed by a RADIUS or LDAP server.
Answer: C
NEW QUESTION 69
A security analyst gathered forensics from a recent intrusion in preparation for legal proceedings. The analyst used EnCase to gather the digital forensics, cloned the hard drive, and took the hard drive home for further analysis. Which of the following did the security analyst violate?
- A. Virtualization
- B. Chain of custody
- C. Hashing procedures
- D. Cloning procedures
Answer: B
NEW QUESTION 70
Given a packet capture of the following scan:
Which of the following should MOST likely be inferred on the scan's output?
- A. 192.168.1.55 is a file server.
- B. 192.168.1.55 is hosting a web server.
- C. 192.168.1.115 is hosting a web server.
- D. 192.168.1.55 is a Linux server.
Answer: A
NEW QUESTION 71
An analyst is preparing for a technical security compliance check on all Apache servers. Which of the following will be the BEST to use?
- A. Nagios
- B. CIS benchmark
- C. OWASP
- D. Cain & Abel
- E. Untidy
Answer: B
NEW QUESTION 72
An organization has a practice of running some administrative services on non-standard ports as a way of frustrating any attempts at reconnaissance. The output of the latest scan on host
192.168.1.13 is shown below:
Which of the following statements is true?
- A. Despite the results of the scan, the service running on port 23 is actually Telnet and not SSH, and creates an additional vulnerability
- B. Remote SSH connections will automatically default to the standard SSH port.
- C. Running SSH on port 23 provides little additional security from running it on the standard port.
- D. The use of OpenSSH on its default secure port will supersede any other remote connection attempts.
- E. Running SSH on the Telnet port will now be sent across an unencrypted port.
Answer: C
NEW QUESTION 73
A security analyst has determined the security team should take action based on the following log:
Which of the following should be used to improve the security posture of the system?
- A. Increase password complexity requirements.
- B. Upgrade the firewalls.
- C. Enable login account auditing.
- D. Limit the number of unsuccessful login attempts.
Answer: D
NEW QUESTION 74
A cybersecurity analyst is responding to an incident. The company's leadership team wants to attribute the incident to an attack group. Which of the following models would BEST apply to the situation?
- A. MITRE ATT&CK
- B. Diamond Model of Intrusion Analysis
- C. Intelligence cycle
- D. Kill chain
Answer: B
NEW QUESTION 75
During a review of security controls, an analyst was able to connect to an external, unsecured FTP server from a workstation. The analyst was troubleshooting and reviewed the ACLs of the segment firewall the workstation is connected to:
Based on the ACLs above, which of the following explains why the analyst was able to connect to the FTP server?
- A. FTP was allowed as being included in Seq 3 and Seq 4 of the ACL.
- B. FTP was explicitly allowed in Seq 8 of the ACL.
- C. FTP was allowed in Seq 10 of the ACL.
- D. FTP was allowed as being outbound from Seq 9 of the ACL.
Answer: B
NEW QUESTION 76
An organization has not had an incident for several month. The Chief information Security Officer (CISO) wants to move to proactive stance for security investigations. Which of the following would BEST meet that goal?
- A. Advanced antivirus
- B. Threat hunting
- C. Active response
- D. Root-cause analysis
- E. Information-sharing community
Answer: B
NEW QUESTION 77
A security analyst is evaluating two vulnerability management tools for possible use in an organization. The analyst set up each of the tools according to the respective vendor's instructions and generated a report of vulnerabilities that ran against the same target server.
Tool A reported the following:
Tool B reported the following:
Which of the following BEST describes the method used by each tool? (Choose two.)
- A. Tool B is agent based.
- B. Tool A is unauthenticated.
- C. Tool A is agent based.
- D. Tool A used fuzzing logic to test vulnerabilities.
- E. Tool B is unauthenticated.
- F. Tool B utilized machine learning technology.
Answer: A,B
NEW QUESTION 78
A security administrator needs to create an IDS rule to alert on FTP login attempts by root. Which of the following rules is the BEST solution?
- A. Option D
- B. Option B
- C. Option A
- D. Option C
Answer: B
NEW QUESTION 79
During routine monitoring, a security analyst discovers several suspicious websites that are communicating with a local host. The analyst queries for IP 192.168.50.2 for a 24-hour period:
To further investigate, the analyst should request PCAP for SRC 192.168.50.2 and __________.
- A. DST 172.10.45.5.
- B. DST 138.10.25.5.
- C. DST 175.35.20.5.
- D. DST 138.10.2.5.
- E. DST 172.10.3.5.
Answer: E
NEW QUESTION 80
......
Authentic Best resources for CS0-002 Online Practice Exam: https://www.examdumpsvce.com/CS0-002-valid-exam-dumps.html
Updates Up to 365 days On Developing CS0-002 Braindumps: https://drive.google.com/open?id=1p-F8TQGRFiz1HKf7Y1CeMOKjgV6Hxvyz
