(2026) PASS CS0-002 exam with CompTIA CS0-002 Real Exam Questions [Q126-Q143]

Share

(2026) PASS CS0-002 exam with CompTIA CS0-002 Real Exam Questions

Real exam questions are provided for CompTIA CySA+ tests, which can make sure you 100% pass

NEW QUESTION # 126
A recent audit included a vulnerability scan that found critical patches released 60 days prior were not applied to servers in the environment. The infrastructure team was able to isolate the issue and determined it was due to a service being disabled on the server running the automated patch management application. Which of the following would be the MOST efficient way to avoid similar audit findings in the future?

  • A. Implement service monitoring to validate that tools are functioning properly.
  • B. Set services on the patch management server to automatically run on start-up.
  • C. Create a patch management policy that requires all servers to be patched within 30 days of patch release.
  • D. Implement a manual patch management application package to regain greater control over the process.

Answer: B


NEW QUESTION # 127
An analyst reviews a legacy Windows XP system and concludes an attacker executed code that modified the contents of the system's memory. Which of the following attack techniques did the attacker use?

  • A. Rootkit
  • B. Buffer overflow
  • C. Privilege escalation
  • D. Backdoor

Answer: B

Explanation:
A buffer overflow is an attack technique that exploits a vulnerability in a program's memory management, by sending more data than the buffer can hold. This can cause the program to overwrite adjacent memory locations, and execute arbitrary code injected by the attacker.


NEW QUESTION # 128
A security analyst is investigating a compromised Linux server. The analyst issues the ps command and receives the following output.

Which of the following commands should the administrator run NEXT to further analyze the compromised system?

  • A. strace /proc/1301
  • B. kill -9 1301
  • C. /bin/la -1 /proc/1301/exe
  • D. rpm -V openash-server

Answer: A


NEW QUESTION # 129
Which of the following policies would state an employee should not disable security safeguards, such as host firewalls and antivirus, on company systems?

  • A. Password policy
  • B. Account management policy
  • C. Code of conduct policy
  • D. Acceptable use policy

Answer: D


NEW QUESTION # 130
The help desk noticed a security analyst that emails from a new email server are not being sent out. The new email server was recently added to the existing ones. The analyst runs the following command on the new server.

Given the output, which of the following should the security analyst check NEXT?

  • A. The DMARC policy
  • B. The DNS name of the new email server
  • C. The version of SPF that is being used
  • D. The IP address of the new email server

Answer: C


NEW QUESTION # 131
A security analyst is conducting a post-incident log analysis to determine which indicators can be used to detect further occurrences of a data exfiltration incident. The analyst determines backups were not performed during this time and reviews the following:

Which of the following should the analyst review to find out how the data was exfilltrated?

  • A. Thursday's logs
  • B. Tuesday's logs
  • C. Monday's logs
  • D. Wednesday's logs

Answer: A


NEW QUESTION # 132
A manager asks a security analyst lo provide the web-browsing history of an employee. Which of the following should the analyst do first?

  • A. Obtain permission to perform the search.
  • B. Obtain the employee's network ID to form the query.
  • C. Download the browsing history, encrypt it. and hash it
  • D. Obtain the web-browsing history from the proxy.

Answer: A

Explanation:
The analyst should obtain permission to perform the search before accessing the web-browsing history of an employee, as this may involve privacy or legal issues. The analyst should follow the organization's policies and procedures, and obtain authorization from the appropriate authority, such as the manager, the human resources department, or the legal department.


NEW QUESTION # 133
During routine monitoring a security analyst identified the following enterpnse network traffic:
Packet capture output:

Which of the following BEST describes what the security analyst observed?

  • A. 66.187.224.210 set up a DNS hijack with 192.168.12.21.
  • B. 192.168.12.21 made a TCP connection to 209 132 177 50
  • C. 192.168.12.21 made a TCP connection to 66 187 224 210
  • D. 209.132.177.50 set up a TCP reset attack to 192 168 12 21

Answer: B

Explanation:
The security analyst observed that 192.168.12.21 made a TCP connection to 209.132.177.50. This can be inferred from the packet capture output, which shows the following sequence of packets:
Packet 1: A SYN packet from 192.168.12.21 to 209.132.177.50 on port 80 (HTTP). This is the first step of the TCP three-way handshake, where the source initiates a connection request to the destination.
Packet 2: A SYN-ACK packet from 209.132.177.50 to 192.168.12.21 on port 80 (HTTP). This is the second step of the TCP three-way handshake, where the destination acknowledges and accepts the connection request from the source.
Packet 3: An ACK packet from 192.168.12.21 to 209.132.177.50 on port 80 (HTTP). This is the third and final step of the TCP three-way handshake, where the source confirms and completes the connection establishment with the destination.
These packets indicate that a TCP connection was successfully established between 192.168.12.21 and 209.132.177.50 on port 80.


NEW QUESTION # 134
An analyst is reviewing a list of vulnerabilities, which were reported from a recent vulnerability scan of a Linux server.
Which of the following is MOST likely to be a false positive?

  • A. HTTP TRACE / TRACK Methods Allowed (002-1208)
  • B. Apache HTTP Server Byte Range DoS
  • C. GDI+ Remote Code Execution Vulnerability (MS08-052)
  • D. OpenSSH/OpenSSL Package Random Number Generator Weakness
  • E. SSL Certificate Expiry

Answer: E


NEW QUESTION # 135
Due to a security breach initiated from South America, the Chief Security Officer (CSO) instructed a team to design and implement an appropriate security control to prevent such an attack from reoccurring. The company has sales and consulting teams across the United States that need access to company resources. The security manager implemented a location-based authentication to prevent non-US-based access to the company networks. Three months later, the same incident reoccurred with an attack originating from a country in Asia. Which of the following security design defects could be the cause?

  • A. The sales and supports are reusing the same passwords for their personal accounts, such as banking and email
  • B. The company just replaced a firewall that had a DDoS vulnerability
  • C. The hackers left a backdoor within the company networks that was not cleaned successfully
  • D. The team did not account for the VPN access and did not ensure non-repudiation

Answer: D


NEW QUESTION # 136
A company stores all of its data in the cloud. All company-owned laptops are currently unmanaged, and all users have administrative rights. The security team is having difficulty identifying a way to secure the environment. Which of the following would be the BEST method to protect the company's data?

  • A. Implement centralized monitoring and logging for an company systems.
  • B. Implement DLP on all workstations and block company data from being sent outside the company
  • C. Implement UEM on an systems and deploy security software.
  • D. Implement a CASB and prevent certain types of data from being downloaded to a workstation

Answer: D

Explanation:
A CASB, or Cloud Access Security Broker, is a software tool or service that acts as an intermediary between an organization's cloud services and its users. A CASB can provide various security functions, such as visibility, compliance, threat protection, and data security2 A CASB can help protect the company's data stored in the cloud by preventing certain types of data from being downloaded to a workstation, such as sensitive or confidential information. This can reduce the risk of data leakage, theft, or loss if a workstation is compromised or stolen.
Reference:
Cloud Access Security Broker (CASB): An enterprise management software designed to mediate access to cloud services by users across all types of devices


NEW QUESTION # 137
An organization is moving its infrastructure to the cloud in an effort to meet the budget and reduce staffing requirements. The organization has three environments: development, testing, and production. These environments have interdependencies but must remain relatively segmented.
Which of the following methods would BEST secure the company's infrastructure and be the simplest to manage and maintain?

  • A. Create three separate cloud accounts for each environment and a single core account for network services.
    Route all traffic through the core account.
  • B. Create three separate cloud accounts for each environment. Configure account peering and security rules to allow access to and from each environment.
  • C. Create one cloud account with one VPC for all environments. Purchase a virtual firewall and create granular security rules.
  • D. Create one cloud account and three separate VPCs for each environment. Create security rules to allow access to and from each environment.

Answer: D


NEW QUESTION # 138
A security analyst received an alert from the SIEM indicating numerous login attempts from users outside their usual geographic zones, all of which were initiated through the web-based mail server. The logs indicate all domain accounts experienced two login attempts during the same time frame.
Which of the following is the MOST likely cause of this issue?

  • A. A DDoS attack was performed against the organization.
  • B. A password-spraying attack was performed against the organization.
  • C. This was normal shift work activity; the SIEM's AI is learning.
  • D. A credentialed external vulnerability scan was performed.

Answer: B

Explanation:
Explanation
Explanation/Reference: https://doubleoctopus.com/security-wiki/threats-and-tools/password-spraying/


NEW QUESTION # 139
An incident response team is responding to a breach of multiple systems that contain PII and PHI. Disclosing the incident to external entities should be based on:

  • A. senior management's guidance
  • B. the responder's discretion
  • C. the communication plan
  • D. the public relations policy

Answer: C


NEW QUESTION # 140
An organization has a strict policy that if elevated permissions are needed, users should always run commands under their own account, with temporary administrator privileges if necessary. A security analyst is reviewing syslog entries and sees the following:

Which of the following entries should cause the analyst the MOST concern?

  • A. <100> 2020-01-10T19:33:48.002z webserver sudo 201 32001 = BOM ' su vi httpd.conf' success
  • B. <100> 2020-01-10T19:33:48.002z webserver sudo 201 32001 = BOM ' su vi syslog.conf failed for jos
  • C. <100>2 2020-01-10T19:33:41.002z webserver su 201 32001 = BOM ' su vi httpd.conf' failed for joe
  • D. <100> 2020-01-10T19:34..002z financeserver su 201 32001 = BOM ' su vi success
  • E. <100>2 2020-01-10T20:36:36.0010z financeserver su 201 32001 = BOM ' sudo vi users.txt success

Answer: C


NEW QUESTION # 141
Which of the following is the best method to review and assess the security of the cloud service models used by a company on multiple CSPs?

  • A. Integrating the security benchmarks of the CSPs with a CASB
  • B. Unifying and migrating all services in a single CSP
  • C. Executing an API hardening process on the CSPs' endpoints
  • D. Deploying cloud instances using Nikto and OpenVAS

Answer: A

Explanation:
This is the best method to review and assess the security of the cloud service models used by a company on multiple CSPs. CSP stands for cloud service provider, which is a company that offers cloud-based services such as infrastructure, platform, or software. CASB stands for cloud access security broker, which is a software or service that acts as a gateway between the company and the CSPs, and provides visibility, control, compliance, and threat protection for the cloud services.
Integrating the security benchmarks of the CSPs with a CASB means that the company can use a common set of standards and metrics to measure and compare the security posture and performance of different cloud service models, such as IaaS, PaaS, or SaaS. Security benchmarks are predefined criteria or best practices that define the minimum level of security required for a cloud service model. For example, some security benchmarks may include encryption, authentication, logging, auditing, patching, backup, etc. By integrating these benchmarks with a CASB, the company can monitor and enforce them across multiple CSPs, and identify any gaps or risks in their cloud security.


NEW QUESTION # 142
A security analyst is looking at the headers of a few emails that appear to be targeting all users at an organization:


Which of the following technologies would MOST likely be used to prevent this phishing attempt?

  • A. STP
  • B. DNSSEC
  • C. S/IMAP
  • D. DMARC

Answer: D


NEW QUESTION # 143
......

Latest CS0-002 Pass Guaranteed Exam Dumps Certification Sample Questions: https://examsboost.realexamfree.com/CS0-002-real-exam-dumps.html