ExamGecko
Home / CompTIA / CS0-003 / List of questions
Ask Question

CompTIA CS0-003 Practice Test - Questions Answers, Page 22

Add to Whishlist

List of questions

Question 211

Report Export Collapse

HOTSPOT

A company recently experienced a security incident. The security team has determined a user clicked on a link embedded in a phishing email that was sent to the entire company. The link resulted in a malware download, which was subsequently installed and run.

INSTRUCTIONS

Part 1

Review the artifacts associated with the security incident. Identify the name of the malware, the malicious IP address, and the date and time when the malware executable entered the organization.

Part 2

Review the kill chain items and select an appropriate control for each that would improve the security posture of the organization and would have helped to prevent this incident from occurring. Each control may only be used once, and not all controls will be used.

CompTIA CS0-003 image Question 211 94832 10022024175105000000

Firewall log:

CompTIA CS0-003 image Question 211 94832 10022024175105000000

CompTIA CS0-003 image Question 211 94832 10022024175105000000

File integrity Monitoring Report:

CompTIA CS0-003 image Question 211 94832 10022024175105000000

CompTIA CS0-003 image Question 211 94832 10022024175105000000

Malware domain list:

CompTIA CS0-003 image Question 211 94832 10022024175105000000

Vulnerability Scan Report:

CompTIA CS0-003 image Question 211 94832 10022024175105000000

CompTIA CS0-003 image Question 211 94832 10022024175105000000

Phishing Email:

CompTIA CS0-003 image Question 211 94832 10022024175105000000


Become a Premium Member for full access
  Unlock Premium Member

Question 212

Report Export Collapse

Which of the following is a nation-state actor least likely to be concerned with?

Become a Premium Member for full access
  Unlock Premium Member

Question 213

Report Export Collapse

Which of the following most accurately describes the Cyber Kill Chain methodology?

Become a Premium Member for full access
  Unlock Premium Member

Question 214

Report Export Collapse

An analyst discovers unusual outbound connections to an IP that was previously blocked at the web proxy and firewall. Upon further investigation, it appears that the proxy and firewall rules that were in place were removed by a service account that is not recognized. Which of the following parts of the Cyber Kill Chain does this describe?

Become a Premium Member for full access
  Unlock Premium Member

Question 215

Report Export Collapse

A SOC manager is establishing a reporting process to manage vulnerabilities. Which of the following would be the best solution to identify potential loss incurred by an issue?

Become a Premium Member for full access
  Unlock Premium Member

Question 216

Report Export Collapse

Which of the following is a benefit of the Diamond Model of Intrusion Analysis?

Become a Premium Member for full access
  Unlock Premium Member

Question 217

Report Export Collapse

Which of the following does 'federation' most likely refer to within the context of identity and access management?

Become a Premium Member for full access
  Unlock Premium Member

Question 218

Report Export Collapse

A security analyst noticed the following entry on a web server log:

Warning: fopen (http://127.0.0.1:16) : failed to open stream:

Connection refused in /hj/var/www/showimage.php on line 7

Which of the following malicious activities was most likely attempted?

Become a Premium Member for full access
  Unlock Premium Member

Question 219

Report Export Collapse

A SOC analyst is analyzing traffic on a network and notices an unauthorized scan. Which of the following types of activities is being observed?

Become a Premium Member for full access
  Unlock Premium Member

Question 220

Report Export Collapse

An analyst is evaluating a vulnerability management dashboard. The analyst sees that a previously remediated vulnerability has reappeared on a database server. Which of the following is the most likely cause?

Become a Premium Member for full access
  Unlock Premium Member
Total 431 questions
Go to page: of 44
Search

Related questions