CompTIA CS0-004 - CompTIA CySA+ V4 Exam

Question #1 (Topic: Topic 1, Security Operations )
Which of the following is the most important reason why tactics, techniques, and procedures (TTP) are beneficial to a defensive strategy?
A. TTP provides useful insights on the hash values and internet protocol addresses attributed to an attacker. B. TTP provides useful insights on an attacker's indicators of compromise. C. TTP provides useful insights on the tools used by an attacker. D. TTP provides useful insights on the strategy and behavior of an attacker.
Answer: D
Question #2 (Topic: Topic 1, Security Operations )
Which of the following is the best reason to heavily segment business-critical assets from within the network?
A. Legacy systems B. Degraded functionality C. Asset obfuscation D. Proprietary server
Answer: A
Question #3 (Topic: Topic 1, Security Operations )
A cybersecurity analyst receives an unstructured text document that contains advanced persistent threat (APT)-related indicators of compromise (IoCs). The analyst needs to extract the IPv4 addresses. Which of the following is the best tool to accomplish this task?
A. CyberChef B. Wireshark C. Zeek D. Open Cyber Threat Intelligence (OpenCTI)
Answer: A
Question #4 (Topic: Topic 1, Security Operations )
Which of the following best describes why operational technology (OT) devices use compensating controls?
A. Industrial control systems use significant network bandwidth. B. Outage windows are usually scheduled. C. Traditional IT security solutions may not be compatible. D. OT devices are typically not encrypted.
Answer: C
Question #5 (Topic: Topic 1, Security Operations )
The Chief Information Security Officer (CISO) reviews the following security operations metrics from the last month:

Which of the following is the best action to improve overall security operations efficiency?
A. Leverage a cloud security posture management tool to add asset context to alerts. B. Analyze and tune the detections that are causing non-actionable alerts. C. Implement playbooks for the junior analysts to use during investigations. D. Perform internal incident training on the most common alerts from security information and event management (SIEM).
Answer: B
Download Exam
Page: 1 / 17
Total 82 questions