최신CompTIA Cybersecurity Analyst (CySA+) Certification - CS0-003무료샘플문제
문제1
A security administrator has found indications of dictionary attacks against the company ' s external-facing portal. Which of the following should be implemented to best mitigate the password attacks?
A security administrator has found indications of dictionary attacks against the company ' s external-facing portal. Which of the following should be implemented to best mitigate the password attacks?
정답: B
설명: (ExamPassdump 회원만 볼 수 있음)
문제2
An organization recently changed its BC and DR plans. Which of the following would best allow for the incident response team to test the changes without any impact to the business?
An organization recently changed its BC and DR plans. Which of the following would best allow for the incident response team to test the changes without any impact to the business?
정답: C
설명: (ExamPassdump 회원만 볼 수 있음)
문제3
An organization has a critical financial application hosted online that does not allow event logging to send to the corporate SIEM. Which of the following is the best option for the security analyst to configure to improve the efficiency of security operations?
An organization has a critical financial application hosted online that does not allow event logging to send to the corporate SIEM. Which of the following is the best option for the security analyst to configure to improve the efficiency of security operations?
정답: B
설명: (ExamPassdump 회원만 볼 수 있음)
문제4
An organization enabled a SIEM rule to send an alert to a security analyst distribution list when ten failed logins occur within one minute. However, the control was unable to detect an attack with nine failed logins.
Which of the following best represents what occurred?
An organization enabled a SIEM rule to send an alert to a security analyst distribution list when ten failed logins occur within one minute. However, the control was unable to detect an attack with nine failed logins.
Which of the following best represents what occurred?
정답: D
설명: (ExamPassdump 회원만 볼 수 있음)
문제5
A security analyst has identified a new malware file that has impacted the organization. The malware is polymorphic and has built-in conditional triggers that require a connection to the internet. The CPU has an idle process of at least 70%. Which of the following best describes how the security analyst can effectively review the malware without compromising the organization ' s network?
A security analyst has identified a new malware file that has impacted the organization. The malware is polymorphic and has built-in conditional triggers that require a connection to the internet. The CPU has an idle process of at least 70%. Which of the following best describes how the security analyst can effectively review the malware without compromising the organization ' s network?
정답: B
설명: (ExamPassdump 회원만 볼 수 있음)
문제6
A systems administrator notices unfamiliar directory names on a production server. The administrator reviews the directory listings and files, and then concludes the server has been compromised. Which of the following steps should the administrator take next?
A systems administrator notices unfamiliar directory names on a production server. The administrator reviews the directory listings and files, and then concludes the server has been compromised. Which of the following steps should the administrator take next?
정답: D
설명: (ExamPassdump 회원만 볼 수 있음)
문제7
Which of the following does " federation " most likely refer to within the context of identity and access management?
Which of the following does " federation " most likely refer to within the context of identity and access management?
정답: B
설명: (ExamPassdump 회원만 볼 수 있음)
문제8
Following an attack, an analyst needs to provide a summary of the event to the Chief Information Security Officer. The summary needs to include the who-what-when information and evaluate the effectiveness of the plans in place. Which of the following incident management life cycle processes does this describe?
Following an attack, an analyst needs to provide a summary of the event to the Chief Information Security Officer. The summary needs to include the who-what-when information and evaluate the effectiveness of the plans in place. Which of the following incident management life cycle processes does this describe?
정답: C
설명: (ExamPassdump 회원만 볼 수 있음)
문제9
After recovering from an incident, the incident response team wants to conduct a lessons-learned session to discuss the steps taken by the analysts. Which of the following best describes the reason for this review?
After recovering from an incident, the incident response team wants to conduct a lessons-learned session to discuss the steps taken by the analysts. Which of the following best describes the reason for this review?
정답: A
설명: (ExamPassdump 회원만 볼 수 있음)
문제10
Which of the following would eliminate the need for different passwords for a variety or internal application?
Which of the following would eliminate the need for different passwords for a variety or internal application?
정답: D
설명: (ExamPassdump 회원만 볼 수 있음)
문제11
Which of the following is the most important reason for an incident response team to develop a formal incident declaration?
Which of the following is the most important reason for an incident response team to develop a formal incident declaration?
정답: D
설명: (ExamPassdump 회원만 볼 수 있음)