Weekend Sale - Special 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 75onlydt

CS0-004 Questions and Answers

Question # 6

An analyst reviews the following system logs from a recent breach attempt:

Question # 6

Which of the following techniques did the attacker attempt to use?

A.

Exfiltration

B.

Remote code execution

C.

Privilege escalation

D.

Spoofing

Full Access
Question # 7

A security analyst analyzes the output of a web application access log for a company based in the United States.

Given the following output:

Question # 7

Which of the following users should be investigated first?

A.

jschott

B.

dmann

C.

mschultz

D.

tlindy

Full Access
Question # 8

A binary file that might contain malicious code is hosted on an isolated machine. An analyst wants to quickly detect the malicious code.

Which of the following should the analyst use?

A.

strings

B.

VirusTotal

C.

WHOIS

D.

Yet Another Recursive Acronym (YARA)

Full Access
Question # 9

A security architect works with a client on security operations center (SOC) capabilities. The security architect wants to ensure the log correlation and investigation activities are accurate across the infrastructure.

Which of the following is the best for the client to implement?

A.

Network Time Protocol (NTP)

B.

Zero Trust Network Access (ZTNA)

C.

Account federation

D.

Secure access service edge (SASE)

E.

Application programming interfaces (APIs)

Full Access
Question # 10

Which of the following best describes why operational technology (OT) devices use compensating controls?

A.

Industrial control systems use significant network bandwidth.

B.

Outage windows are usually scheduled.

C.

Traditional IT security solutions may not be compatible.

D.

OT devices are typically not encrypted.

Full Access
Question # 11

An analyst performs Nmap scans to determine which hosts may need to be targeted to deploy a critical Windows patch. The patch for the vulnerability is to address a critical security flaw that targets open Server Message Block (SMB) ports on Windows systems only.

The analyst scans with the following command:

Question # 11

$sudo nmap -Pn 10.203.10.0/24

The analyst then receives the following output:

Which of the following hosts should the analyst prioritize for patching?

A.

10.203.10.11

B.

10.203.10.12

C.

10.203.10.13

D.

10.203.10.16

Full Access
Question # 12

Which of the following contains stakeholder contact information for incident response reporting?

A.

The company organization chart

B.

The communication plan

C.

The last incident report

D.

The standard operating procedures

Full Access
Question # 13

An analyst executes the top command on a Linux system for an unresponsive application and observes the following output:

Question # 13

Which of the following is the most likely cause of this issue?

A.

Service disruption

B.

Unauthorized software

C.

Resource exhaustion

D.

Filesystem changes

Full Access
Question # 14

Which of the following is the most difficult for threat actors to change according to the Pyramid of Pain model?

A.

Tactics, techniques, and procedures

B.

Tools

C.

Domain names

D.

Internet Protocol addresses

Full Access
Question # 15

Which of the following best describes a type of risk that exists after mitigations or controls are enacted and implemented?

A.

Residual

B.

Acceptable

C.

Inherent

D.

Appropriate

Full Access
Question # 16

The Chief Information Officer (CIO) is requiring users to phase out a legacy system that no longer receives security updates because the system will be decommissioned soon.

Which of the following risk management strategies is the CIO using?

A.

Avoidance

B.

Mitigation

C.

Acceptance

D.

Transference

Full Access
Question # 17

A systems administrator is reviewing the output of a vulnerability scan.

INSTRUCTIONS -

Review the information in each tab.

Based on the organization’s environment architecture and remediation standards, select the server to be patched within 14 days and select the appropriate technique and mitigation.

If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

Question # 17

Question # 17

Question # 17

Question # 17

Full Access
Question # 18

Which of the following actions should an incident response analyst take during the recovery phase of the incident response process?

A.

Verify that malicious activity has occurred.

B.

Reimage the disk.

C.

Take the system offline.

D.

Write the final report.

Full Access
Question # 19

Which of the following best explains why sensitive data should be encrypted at rest on laptops?

A.

To prevent end users from copying data to other systems

B.

To protect disclosure of information if physical devices are stolen

C.

To comply with regulatory and legal requirements

D.

To ensure the integrity of the data on the company network

Full Access
Question # 20

A public threat intelligence report includes indicators of compromise (IoCs) for threat actors. The threat actors are exploiting a zero-day vulnerability that the vendor has not fixed.

Which of the following techniques should be used until a patch is available?

A.

Sinkholing

B.

Eradication techniques

C.

Continuous monitoring

D.

Evidence acquisition

Full Access
Question # 21

A security team deploys a new scanning solution that requires root, domain administrator, and local server administrator permissions on all systems.

Which of the following is the best way to help mitigate the risk for this level of access?

A.

Enabling single sign-on for all administrators

B.

Integrating token-based authentication using a privileged access management (PAM) solution

C.

Using temporary, one-time passwords as part of the login process

D.

Configuring agentless scanning for critical targets

Full Access
Question # 22

Which of the following is the best reason to heavily segment business-critical assets from within the network?

A.

Legacy systems

B.

Degraded functionality

C.

Asset obfuscation

D.

Proprietary server

Full Access
Question # 23

A new security operations center (SOC) manager joins a team that struggles to meet service-level agreements (SLAs). The alert backlog continues to increase daily.

Which of the following will the manager most likely need to do?

A.

Automate escalation.

B.

Improve the triage processes.

C.

Upgrade threat intelligence.

D.

Enhance the customer service response.

Full Access
Question # 24

The Chief Information Security Officer wants to improve internal security measures by continuously validating and verifying access to the production environment.

Which of the following concepts best describes this practice?

A.

Secure access service edge

B.

Next-generation firewall

C.

Zero Trust

D.

Privileged access management

Full Access