CompTIA CS0-002 - CompTIA CySA+ Certification Exam (CS0-002) Exam

Question #11 (Topic: Single Topic)
Which of the following is a difference between SOAR and SCAP?
A. SOAR can be executed faster and with fewer false positives than SCAP because of advanced heuristics. B. SOAR has a wider breadth of capability using orchestration and automation, while SCAP is more limited in scope. C. SOAR is less expensive because process and vulnerability remediation is more automated than what SCAP does. D. SOAR eliminates the need for people to perform remediation, while SCAP relies heavily on security analysts.
Answer: B
Question #12 (Topic: Single Topic)
An organization has a policy that requires servers to be dedicated to one function and unneeded services to be disabled. Given the following output from an Nmap
scan of a web server:

Which of the following ports should be closed?
A. 21 B. 80 C. 443 D. 1433
Answer: B
Question #13 (Topic: Single Topic)
An organization is upgrading its network and all of its workstations. The project will occur in phases, with infrastructure upgrades each month and workstation
installs every other week. The schedule should accommodate the enterprise-wide changes, while minimizing the impact to the network. Which of the following
schedules BEST addresses these requirements?
A. Monthly vulnerability scans, biweekly topology scans, daily host discovery scans B. Monthly topology scans, biweekly host discovery scans, monthly vulnerability scans C. Monthly host discovery scans, biweekly vulnerability scans, monthly topology scans D. Monthly topology scans, biweekly host discovery scans, weekly vulnerability scans
Answer: C
Question #14 (Topic: Single Topic)
SIMULATION
Malware is suspected on a server in the environment.
The analyst is provided with the output of commands from servers in the environment and needs to review all output files in order to determine which process
running on one of the servers may be malware.
INSTRUCTIONS
Servers 1, 2, and 4 are clickable. Select the Server and the process that host the malware.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.




Answer: See explanation below.
Question #15 (Topic: Single Topic)
While reviewing incident reports from the previous night, a security analyst notices the corporate websites were defaced with political propaganda. Which of the
following BEST describes this type of actor?
A. Hacktivist B. Nation-state C. Insider threat D. Organized crime
Answer: A
Download Exam
Page: 3 / 85
Total 422 questions