CompTIA Cybersecurity Analyst (CySA+) Certification - CS0-004 模擬練習

Which of the following contains stakeholder contact information for incident response reporting?

正解: A
解説: (PassTest メンバーにのみ表示されます)
Which of the following best explains the purpose of the Pyramid of Pain in threat intelligence?

正解: C
解説: (PassTest メンバーにのみ表示されます)
An incident response team investigates a possible data leak. Various IT systems collect evidence. Which of the following processes is required to ensure that evidentiary artifacts are properly recorded?

正解: C
解説: (PassTest メンバーにのみ表示されます)
A vulnerability analyst conducts a web application scan on an asset sitting behind a load balancer configured as a pass through:
http://10.203.20.10
The analyst launches the Zed Attack Proxy (ZAP) utility, conducts a scan, and receives the following alert:

Which of the following should the analyst propose as a remediation to the finding while keeping the site operational?

正解: B
解説: (PassTest メンバーにのみ表示されます)
Based on recent alerts, a security analyst thinks a web application server was compromised. The analyst reviews the following server output:

Which of the following best describes what has occurred?

正解: C
解説: (PassTest メンバーにのみ表示されます)
A security analyst is reviewing an alert about connections from an IT member to the Chief Privacy Officer's (CPO) laptop. There was abnormal network traffic from the CPO's laptop to an unknown server located in the IT legacy network and then to an unknown internet location. Based on the following information:

Which of the following best categorizes the detected activity?

正解: C
解説: (PassTest メンバーにのみ表示されます)
A new policy prohibits external access to database servers. A recent external port scan identified the following open Transmission Control Protocol (TCP) ports:
- 21
- 25
- 68
- 80
- 389
- 443
- 587
- 1514
- 3306
- 3389
- 8080
Which of the ports must be closed to be compliant with the new policy? (Choose two.)

正解: B,E
解説: (PassTest メンバーにのみ表示されます)
A security architect reviews a report from a third-party incident response consultant and observes the following:

Which of the following frameworks did the consultant use to perform analysis?

正解: B
解説: (PassTest メンバーにのみ表示されます)
A security operations center (SOC) manager reviews a document signed by the Chief Financial Officer (CFO), the sales director, and a customer to decide whether a contract breach occurred.
Which of the following best describes the document that includes key performance indicators (KPIs)?

正解: B
解説: (PassTest メンバーにのみ表示されます)
Which of the following is the IR activity in which process gaps are identified?

正解: D
解説: (PassTest メンバーにのみ表示されます)
A security director at a remote company is concerned about recent threat intelligence reports regarding threat actors who are hired by the company and steal intellectual property. Which of the following solutions are the best ways to identify the tactics, techniques, and procedures (TTPs) used by these threat actors? (Choose two.)

正解: B,C
解説: (PassTest メンバーにのみ表示されます)
Which of the following will most likely help decrease false positives?

正解: C
解説: (PassTest メンバーにのみ表示されます)
A security operations center manager is concerned that after action reporting is not being completed in a timely manner. Which of the following will allow the manager to quantify this concern?

正解: D
解説: (PassTest メンバーにのみ表示されます)