CompTIA Cybersecurity Analyst (CySA+) Certification - CS0-004 模擬練習
Which of the following describes the main benefits of MITRE ATT&CK Navigator?
正解: B
解説: (PassTest メンバーにのみ表示されます)
A company migrated its email solution from hybrid to on premises only. The administrator made the following changes:
Hybrid, before the migration:
- v=spf1 include:cloud.mailprovider.com ip4:200.100.50.25/32 -all
On premises, after the migration:
- v=spf1 ip4:200.100.50.25/32 -all
A few weeks after the migration, multiple clients report that the company's emails are being marked as spam. The systems administrator notices that the SPF record has been manipulated by a threat actor who is spoofing the company's domain. The unauthorized change:
- v=spf1 include:cloud.mailprovider.com ip4:100.50.25.10 -all
Which of the following explains the reason legitimate emails are being marked as spam?
Hybrid, before the migration:
- v=spf1 include:cloud.mailprovider.com ip4:200.100.50.25/32 -all
On premises, after the migration:
- v=spf1 ip4:200.100.50.25/32 -all
A few weeks after the migration, multiple clients report that the company's emails are being marked as spam. The systems administrator notices that the SPF record has been manipulated by a threat actor who is spoofing the company's domain. The unauthorized change:
- v=spf1 include:cloud.mailprovider.com ip4:100.50.25.10 -all
Which of the following explains the reason legitimate emails are being marked as spam?
正解: B
解説: (PassTest メンバーにのみ表示されます)
Customers are unable to upload files to an SFTP server. Firewall logs show the following activity sourced from multiple IP addresses in one geographic region:

The analyst reviewing the logs notices that the session_end_reason does not change for any of the log entries. Which of the following is the next step the analyst should take to determine what is occurring?

The analyst reviewing the logs notices that the session_end_reason does not change for any of the log entries. Which of the following is the next step the analyst should take to determine what is occurring?
正解: D
解説: (PassTest メンバーにのみ表示されます)
An analyst executes the top command on a Linux system for an unresponsive application and observes the following output:

Which of the following is the most likely cause of this issue?

Which of the following is the most likely cause of this issue?
正解: C
解説: (PassTest メンバーにのみ表示されます)
A vulnerability analyst conducts a security assessment on the Remote Desktop Protocol (RDP) security posture within the environment. The analyst issues the following command for the assessment:
nmap -p 3389 --script rdp* 10.0.0.0/24
The analyst receives responses, which are divided into one of the two categories, from 13 out of the 254 hosts:

Which of the following conclusions can the analyst make about the output on Category 2?
nmap -p 3389 --script rdp* 10.0.0.0/24
The analyst receives responses, which are divided into one of the two categories, from 13 out of the 254 hosts:

Which of the following conclusions can the analyst make about the output on Category 2?
正解: C
解説: (PassTest メンバーにのみ表示されます)
An analyst must provide a visualization of data received from threat intelligence sources. The data includes the Internet Protocols, services, and tools used by threat actors. Which of the following is the best framework for the analyst to follow to display this data?
正解: B
解説: (PassTest メンバーにのみ表示されます)
The Chief Information Officer (CIO) is requiring users to phase out a legacy system that no longer receives security updates because the system will be decommissioned soon. Which of the following risk management strategies is the CIO using?
正解: B
解説: (PassTest メンバーにのみ表示されます)
Which of the following is the most comprehensive type of report associated with a closed incident?
正解: B
解説: (PassTest メンバーにのみ表示されます)