Weekend Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

CS0-001 Exam Results

Page: 7 / 17
Total 455 questions

CompTIA CSA+ Certification Exam Questions and Answers

Question 25

A datacenter manager just received an SMS alert that a server cage was accessed using an authorized code. The manager does not recall receiving a notification by email for any scheduled maintenance on servers In the cage. Which of the following Is the FIRST step the manager should take?

Options:

A.

Check the change management logs at the earliest convenience to determine if the change was authorized.

B.

Remote access the server and change the password to prevent the Intruder from accessing the system.

C.

Request a firewall administrator to Implement an ACL to contain any potential damage.

D.

Call the security guard to investigate the situation.

Question 26

A cybersecurity analyst wants to use ICMP ECHO_REQUEST on a machine while using Nmap. Which of the following is the correct command to accomplish this?

Options:

A.

$ nmap –PE 192.168.1.7

B.

$ ping --PE 192.168.1.7

C.

$ nmap --traceroute 192.168.1.7

D.

$ nmap –PO 192.168.1.7

Question 27

The Chief Information Security Officer (CISO) asks a security analyst to write a new SIEM search rule to determine if any credit card numbers are being written to log files. The CISO and security analyst suspect the following log snippet contains real customer card data:

Which of the following expressions would find potential credit card numbers in a format that matches the log snippet?

Options:

A.

^[0-9](16)$

B.

(0-9) x 16

C.

“1234-5678”

D.

“04*”

Question 28

A security analyst was asked to join an outage call for a critical web application. The web middleware support team determined the web server is running and having no trouble processing requests; however, some investigation has revealed firewall denies to the web server that began around 1.00 a.m. that morning. An emergency change was made to enable the access, but management has asked for a root cause determination. Which of the following would be the BEST next step?

Options:

A.

Install a packet analyzer near the web server to capture sample traffic to find anomalies.

B.

Block all traffic to the web server with an ACL.

C.

Use a port scanner to determine all listening ports on the web server.

D.

Search the logging servers for any rule changes.

Page: 7 / 17
Total 455 questions