Exam Details

  • Exam Code
    :CS0-002
  • Exam Name
    :CompTIA Cybersecurity Analyst (CySA+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :1059 Q&As
  • Last Updated
    :Apr 17, 2025

CompTIA CompTIA Certifications CS0-002 Questions & Answers

  • Question 521:

    An HR employee began having issues with a device becoming unresponsive after attempting to open an email attachment. When informed, the security analyst became suspicious of the situation, even though there was not any unusual behavior on the IDS or any alerts from the antivirus software. Which of the following BEST describes the type of threat in this situation?

    A. Packet of death

    B. Zero-day malware

    C. PII exfiltration

    D. Known virus

  • Question 522:

    An organization wants to remediate vulnerabilities associated with its web servers. An initial vulnerability scan has been performed, and analysts are reviewing the results. Before starting any remediation, the analysts want to remove false positives to avoid spending time on issues that are not actual vulnerabilities. Which of the following would be an indicator of a likely false positive?

    A. Reports show the scanner compliance plug-in is out-of-date.

    B. Any items labeled `low' are considered informational only.

    C. The scan result version is different from the automated asset inventory.

    D. `HTTPS' entries indicate the web page is encrypted securely.

  • Question 523:

    Company A permits visiting business partners from Company B to utilize Ethernet ports available in Company A's conference rooms. This access is provided to allow partners the ability to establish VPNs back to Company B's network. The security architect for Company A wants to ensure partners from Company B are able to gain direct Internet access from available ports only, while Company A employees can gain access to the Company A internal network from those same ports. Which of the following can be employed to allow this?

    A. ACL

    B. SIEM

    C. MAC

    D. NAC

    E. SAML

  • Question 524:

    Which of the following commands would a security analyst use to make a copy of an image for forensics use?

    A. dd

    B. wget

    C. touch

    D. rm

  • Question 525:

    As part of an upcoming engagement for a client, an analyst is configuring a penetration testing application to ensure the scan complies with information defined in the SOW. Which of the following types of information should be considered based on information traditionally found in the SOW? (Select two.)

    A. Timing of the scan

    B. Contents of the executive summary report

    C. Excluded hosts

    D. Maintenance windows

    E. IPS configuration

    F. Incident response policies

  • Question 526:

    Which of the following items represents a document that includes detailed information on when an incident was detected, how impactful the incident was, and how it was remediated, in addition to incident response effectiveness and any identified gaps needing improvement?

    A. Forensic analysis report

    B. Chain of custody report

    C. Trends analysis report

    D. Lessons learned report

  • Question 527:

    After scanning the main company's website with the OWASP ZAP tool, a cybersecurity analyst is reviewing the following warning:

    The analyst reviews a snippet of the offending code:

    Which of the following is the BEST course of action based on the above warning and code snippet?

    A. The analyst should implement a scanner exception for the false positive.

    B. The system administrator should disable SSL and implement TLS.

    C. The developer should review the code and implement a code fix.

    D. The organization should update the browser GPO to resolve the issue.

  • Question 528:

    An alert has been distributed throughout the information security community regarding a critical Apache vulnerability. Which of the following courses of action would ONLY identify the known vulnerability?

    A. Perform an unauthenticated vulnerability scan on all servers in the environment.

    B. Perform a scan for the specific vulnerability on all web servers.

    C. Perform a web vulnerability scan on all servers in the environment.

    D. Perform an authenticated scan on all web servers in the environment.

  • Question 529:

    An analyst finds that unpatched servers have undetected vulnerabilities because the vulnerability scanner does not have the latest set of signatures. Management directed the security team to have personnel update the scanners with the latest signatures at least 24 hours before conducting any scans, but the outcome is unchanged. Which of the following is the BEST logical control to address the failure?

    A. Configure a script to automatically update the scanning tool.

    B. Manually validate that the existing update is being performed.

    C. Test vulnerability remediation in a sandbox before deploying.

    D. Configure vulnerability scans to run in credentialed mode.

  • Question 530:

    A cybersecurity analyst has received an alert that well-known "call home" messages are continuously observed by network sensors at the network boundary. The proxy firewall successfully drops the messages. After determining the alert was a true positive, which of the following represents the MOST likely cause?

    A. Attackers are running reconnaissance on company resources.

    B. An outside command and control system is attempting to reach an infected system.

    C. An insider is trying to exfiltrate information to a remote network.

    D. Malware is running on a company system.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CS0-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.