ExamGecko
Home / CompTIA / CS0-003 / List of questions
Ask Question

CompTIA CS0-003 Practice Test - Questions Answers, Page 12

Add to Whishlist

List of questions

Question 111

Report Export Collapse

The vulnerability analyst reviews threat intelligence regarding emerging vulnerabilities affecting workstations that are used within the company:

CompTIA CS0-003 image Question 111 94732 10022024175105000000

Which of the following vulnerabilities should the analyst be most concerned about, knowing that end users frequently click on malicious links sent via email?

Become a Premium Member for full access
  Unlock Premium Member

Question 112

Report Export Collapse

While reviewing web server logs, an analyst notices several entries with the same time stamps, but all contain odd characters in the request line. Which of the following steps should be taken next?

Become a Premium Member for full access
  Unlock Premium Member

Question 113

Report Export Collapse

A security analyst discovers an LFI vulnerability that can be exploited to extract credentials from the underlying host. Which of the following patterns can the security analyst use to search the web server logs for evidence of exploitation of that particular vulnerability?

Become a Premium Member for full access
  Unlock Premium Member

Question 114

Report Export Collapse

A security analyst at a company called ACME Commercial notices there is outbound traffic to a host IP that resolves to https://offce365password.acme.co. The site's standard VPN logon page is www.acme.com/logon. Which of the following is most likely true?

Become a Premium Member for full access
  Unlock Premium Member

Question 115

Report Export Collapse

The security analyst received the monthly vulnerability report. The following findings were included in the report

* Five of the systems only required a reboot to finalize the patch application.

* Two of the servers are running outdated operating systems and cannot be patched

The analyst determines that the only way to ensure these servers cannot be compromised is to isolate them. Which of the following approaches will best minimize the risk of the outdated servers being compromised?

Become a Premium Member for full access
  Unlock Premium Member

Question 116

Report Export Collapse

Which of the following best describes the goal of a tabletop exercise?

Become a Premium Member for full access
  Unlock Premium Member

Question 117

Report Export Collapse

During the log analysis phase, the following suspicious command is detected-

CompTIA CS0-003 image Question 117 94738 10022024175105000000

Which of the following is being attempted?

Become a Premium Member for full access
  Unlock Premium Member

Question 118

Report Export Collapse

A cybersecurity team lead is developing metrics to present in the weekly executive briefs. Executives are interested in knowing how long it takes to stop the spread of malware that enters the network.

Which of the following metrics should the team lead include in the briefs?

Become a Premium Member for full access
  Unlock Premium Member

Question 119

Report Export Collapse

An analyst is examining events in multiple systems but is having difficulty correlating data points. Which of the following is most likely the issue with the system?

Become a Premium Member for full access
  Unlock Premium Member

Question 120

Report Export Collapse

Which of the following would help an analyst to quickly find out whether the IP address in a SIEM alert is a known-malicious IP address?

Become a Premium Member for full access
  Unlock Premium Member
Total 437 questions
Go to page: of 44
Search

Related questions