New Year Special Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

CS0-002 Exam Dumps - CompTIA CySA+ Certification Exam (CS0-002)

Go to page:
Question # 49

A security analyst is supporting an embedded software team. Which of the following is the best recommendation to ensure proper error handling at runtime?

A.

Perform static code analysis.

B.

Require application fuzzing.

C.

Enforce input validation.

D.

Perform a code review.

Full Access
Question # 50

An organization wants to collect loCs from multiple geographic regions so it can sell the information to its customers. Which of the following should the organization deploy to accomplish this task?

A.

A honeypot

B.

A bastion host

C.

A proxy server

D.

A Jumpbox

Full Access
Question # 51

A security analyst is reviewing WAF alerts and sees the following request:

Which of the following BEST describes the attack?

A.

SQL injection

B.

LDAP injection

C.

Command injection

D.

Denial of service

Full Access
Question # 52

Company A is m the process of merging with Company B As part of the merger, connectivity between the ERP systems must be established so portent financial information can be shared between the two entitles. Which of the following will establish a more automated approach to secure data transfers between the two entities?

A.

Set up an FTP server that both companies can access and export the required financial data to a folder.

B.

Set up a VPN between Company A and Company B. granting access only lo the ERPs within the connection

C.

Set up a PKI between Company A and Company B and Intermediate shared certificates between the two entities

D.

Create static NATs on each entity's firewalls that map lo the ERP systems and use native ERP authentication to allow access.

Full Access
Question # 53

While reviewing system logs, a network administrator discovers the following entry:

Which of the following occurred?

A.

An attempt was made to access a remote workstation.

B.

The PsExec services failed to execute.

C.

A remote shell failed to open.

D.

A user was trying to download a password file from a remote system.

Full Access
Question # 54

A manager asks a security analyst lo provide the web-browsing history of an employee. Which of the following should the analyst do first?

A.

Obtain permission to perform the search.

B.

Obtain the web-browsing history from the proxy.

C.

Obtain the employee's network ID to form the query.

D.

Download the browsing history, encrypt it. and hash it

Full Access
Question # 55

A code review reveals a web application is using lime-based cookies for session management. This is a security concern because lime-based cookies are easy to:

A.

parameterize.

B.

decode.

C.

guess.

D.

decrypt.

Full Access
Question # 56

An analyst Is reviewing a web developer's workstation for potential compromise. While examining the workstation's hosts file, the analyst observes the following:

Which of the following hosts file entries should the analyst use for further investigation?

A.

::1

B.

127.0.0.1

C.

192.168.3.249

D.

198.51.100.5

Full Access
Go to page: