CompTIA CS0-001 - CompTIA CySA+ Certification Exam Exam
Page: 3 / 84
Total 416 questions
Question #11 (Topic: Topic 1)
File integrity monitoring states the following files have been changed without a written request or approved change. The following change has been made:
chmod 777 â€"Rv /usr
Which of the following may be occurring?
chmod 777 â€"Rv /usr
Which of the following may be occurring?
A. The ownership pf /usr has been changed to the current user.
B. Administrative functions have been locked from users.
C. Administrative commands have been made world readable/writable.
D. The ownership of/usr has been changed to the root user.
Answer: C
Question #12 (Topic: Topic 1)
A security analyst has created an image of a drive from an incident. Which of the following describes what the analyst should do NEXT?
A. The analyst should create a backup of the drive and then hash the drive.
B. The analyst should begin analyzing the image and begin to report findings.
C. The analyst should create a hash of the image and compare it to the original drive’s hash.
D. The analyst should create a chain of custody document and notify stakeholders.
Answer: C
Question #13 (Topic: Topic 1)
A cybersecurity analyst is currently investigating a server outage. The analyst has discovered the following value was entered for the username: 0xbfff601a. Which
of the following attacks may be occurring?
of the following attacks may be occurring?
A. Buffer overflow attack
B. Man-in-the-middle attack
C. Smurf attack
D. Format string attack
E. Denial of service attack
Answer: D
Question #14 (Topic: Topic 1)
External users are reporting that a web application is slow and frequently times out when attempting to submit information. Which of the following software
development best practices would have helped prevent this issue?
development best practices would have helped prevent this issue?
A. Stress testing
B. Regression testing
C. Input validation
D. Fuzzing
Answer: A
Question #15 (Topic: Topic 1)
A vulnerability scan has returned the following information:
[CompTIA-CS0-001-1.0/xmlfile-22_1.png]
Which of the following describes the meaning of these results?
[CompTIA-CS0-001-1.0/xmlfile-22_1.png]
Which of the following describes the meaning of these results?
A. There is an unknown bug in a Lotus server with no Bugtraq ID.
B. Connecting to the host using a null session allows enumeration of share names.
C. Trend Micro has a known exploit that must be resolved or patched.
D. No CVE is present, so it is a false positive caused by Lotus running on a Windows server.
Answer: B