
CompTIA CySA+ Practice Tests
Description
Alles über E-Books | Antworten auf Fragen rund um E-Books, Kopierschutz und Dateiformate finden Sie in unserem Info- & Hilfebereich.
In the newly updated 3rd edition of the CompTIA CySA+ Practice Tests: Exam CS0-003, veteran information security experts and educators Mike Chapple and David Seidl deliver an effective and efficient collection of study resources for the challenging CompTIA Cybersecurity Analyst+ (CySA+) certification exam. In the book, you'll find 1000 practice questions, complete with answers and explanations, covering every domain tested by Exam CS0-003.
You'll hone your skills in security operations, vulnerability management, incident response and management, and reporting and communication, improving your ability to detect and respond to malicious activity on the job and dramatically increasingly your chances of success on the CySA+ exam. You'll also get:
* Techniques for threat hunting and the collection of threat intelligence
* Strategies for effective incident response processes and activities, ensuring you're able to react appropriately to cybersecurity incidents at work
* Complimentary access to Sybex's superior online test bank, including all the practice questions you need to review and test your knowledge before you walk into the exam room
Perfect for anyone studying for the CompTIA CySA+ CS0-003 certification exam, CompTIA CySA+ Practice Tests: Exam CS0-003, Third Edition, will also benefit IT security practitioners looking to test and improve their skillset.
More details
Other editions
Additional editions

Persons
DAVID SEIDL, CYSA+, CISSP, PENTEST+, is Vice President for Information Technology and CIO at Miami University. He has led major IT initiatives at multiple institutions and is a top selling cybersecurity and cyberwarfare author with over 18 books published on the subject.
Content
Chapter 1 Domain 1.0: Security Operations 1
Chapter 2 Domain 2.0: Vulnerability Management 67
Chapter 3 Domain 3.0: Incident Response and Management 167
Chapter 4 Reporting and Communication 207
Chapter 5 Practice Test 1 227
Chapter 6 Practice Test 2 253
Appendix Answers and Explanations 281
Chapter 1: Domain 1.0: Security Operations 282
Chapter 2: Domain 2.0: Vulnerability Management 309
Chapter 3: Domain 3.0: Incident Response and Management 345
Chapter 4: Reporting and Communication 361
Chapter 5: Practice Test 1 371
Chapter 6: Practice Test 2 380
Index 391
Chapter 1
Domain 1.0: Security Operations
EXAM OBJECTIVES COVERED IN THIS CHAPTER:
- 1.1 Explain the importance of system and network architecture concepts in security operations
- Log ingestion
- Operating system (OS) concepts
- Infrastructure concepts
- Network architecture
- Identity and access management
- Encryption
- Sensitive data protection
- 1.2 Given a scenario, analyze indicators of potentially malicious activity
- Network-related
- Host-related
- Application-related
- Other
- 1.3. Given a scenario, use appropriate tools or techniques to determine malicious activity
- Tools
- Common techniques
- Programming languages/scripting
- 1.4. Compare and contrast threat-intelligence and threat-hunting concepts
- Threat actors
- Tactics, techniques, and procedures (TTP)
- Confidence levels
- Collection methods and sources
- Threat intelligence sharing
- Threat hunting
- 1.5. Explain the importance of efficiency and process improvement in security operations
- Standardize processes
- Streamline operations
- Technology and tool integration
- Single pane of glass
- Olivia is considering potential sources for threat intelligence information that she might incorporate into her security program. Which one of the following sources is most likely to be available without a subscription fee?
- Vulnerability feeds
- Open source
- Closed source
- Proprietary
- Roger is evaluating threat intelligence information sources and finds that one source results in quite a few false positive alerts. This lowers his confidence level in the source. What criteria for intelligence is not being met by this source?
- Timeliness
- Expense
- Relevance
- Accuracy
- Brad is working on a threat classification exercise, analyzing known threats and assessing the possibility of unknown threats. Which one of the following threat actors is most likely to be associated with an advanced persistent threat (APT)?
- Hacktivist
- Nation-state
- Insider
- Organized crime
- What term is used to describe the groups of related organizations that pool resources to share cybersecurity threat information and analyses?
- SOC
- ISAC
- CERT
- CIRT
- Singh incorporated the Cisco Talos tool into his organization's threat intelligence program. He uses it to automatically look up information about the past activity of IP addresses sending email to his mail servers. What term best describes this intelligence source?
- Open source
- Behavioral
- Reputational
- Indicator of compromise
- Jamal is assessing the risk to his organization from their planned use of AWS Lambda, a serverless computing service that allows developers to write code and execute functions directly on the cloud platform. What cloud tier best describes this service?
- SaaS
- PaaS
- IaaS
- FaaS
- Lauren's honeynet, shown here, is configured to use a segment of unused network space that has no legitimate servers in it. This design is particularly useful for detecting what types of threats?
- Zero-day attacks
- SQL injection
- Network scans
- DDoS attacks
- Fred believes that the malware he is tracking uses a fast flux DNS network, which associates many IP addresses with a single fully qualified domain name as well as using multiple download hosts. How many distinct hosts should he review based on the NetFlow shown here?
Date flow start Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows2020-07-11 14:39:30.606 0.448 TCP 192.168.2.1:1451->10.2.3.1:443 10 1510 12020-07-11 14:39:30.826 0.448 TCP 10.2.3.1:443->192.168.2.1:1451 7 360 12020-07-11 14:45:32.495 18.492 TCP 10.6.2.4:443->192.168.2.1:1496 5 1107 12020-07-11 14:45:32.255 18.888 TCP 192.168.2.1:1496->10.6.2.4:443 11 1840 12020-07-11 14:46:54.983 0.000 TCP 192.168.2.1:1496->10.6.2.4:443 1 49 12020-07-11 16:45:34.764 0.362 TCP 10.6.2.4:443->192.168.2.1:4292 4 1392 12020-07-11 16:45:37.516 0.676 TCP 192.168.2.1:4292->10.6.2.4:443 4 462 12020-07-11 16:46:38.028 0.000 TCP 192.168.2.1:4292->10.6.2.4:443 2 89 12020-07-11 14:45:23.811 0.454 TCP 192.168.2.1:1515->10.6.2.5:443 4 263 12020-07-11 14:45:28.879 1.638 TCP 192.168.2.1:1505->10.6.2.5:443 18 2932 12020-07-11 14:45:29.087 2.288 TCP 10.6.2.5:443->192.168.2.1:1505 37 48125 12020-07-11 14:45:54.027 0.224 TCP 10.6.2.5:443->192.168.2.1:1515 2 1256 12020-07-11 14:45:58.551 4.328 TCP 192.168.2.1:1525->10.6.2.5:443 10 648 12020-07-11 14:45:58.759 0.920 TCP 10.6.2.5:443->192.168.2.1:1525 12 15792 12020-07-11 14:46:32.227 14.796 TCP 192.168.2.1:1525->10.8.2.5:443 31 1700 12020-07-11 14:46:52.983 0.000 TCP 192.168.2.1:1505->10.8.2.5:443 1 40 1- 1
- 3
- 4
- 5
- Which one of the following functions is not a common recipient of threat intelligence information?
- Legal counsel
- Risk management
- Security engineering
- Detection and monitoring
- Alfonzo is an IT professional at a Portuguese university who is creating a cloud environment for use only by other Portuguese universities. What type of cloud deployment model is he using?
- Public cloud
- Private cloud
- Hybrid cloud
- Community cloud
- As a member of a blue team, Lukas observed the following behavior during an external penetration test. What should he report to his managers at the conclusion of the test?
- A significant increase in latency.
- A significant increase in packet loss.
- Latency and packet loss both increased.
- No significant issues were observed.
- The company that Maria works for is making significant investments in infrastructure-as-a-service hosting to replace its traditional datacenter. Members of her organization's management have Maria's concerns about data remanence when Lauren's team moves from one virtual host to another in their cloud service provider's environment. What should she instruct her team to do to avoid this concern?
- Zero-wipe drives before moving systems.
- Use full-disk encryption.
- Use data masking.
- Span multiple virtual disks to fragment data.
- Geoff is reviewing logs and sees a large number of attempts to authenticate to his VPN server using many different username and password combinations. The same usernames are attempted several hundred times before moving on to the next one. What type of attack is most likely taking place?
- Credential stuffing
- Password spraying
- Brute-force
- Rainbow table
- Kaiden is configuring a SIEM service in his IaaS cloud environment that will receive all of the log entries generated by other devices in that environment. Which one of the following risks is greatest with this approach in the event of a DoS attack or other outage?
- Inability to access logs
- Insufficient logging
- Insufficient monitoring
- Insecure API
- Azra believes that one of her users may be taking malicious action on the systems she has access to. When she walks past the user's desktop, she sees the following command on the screen:
user12@workstation:/home/user12# ./john -wordfile:/home/user12/mylist.txt -format:lm hash.txtWhat is the user attempting to do?
- They are attempting to hash a file.
- They are attempting to crack hashed passwords.
- They are attempting to crack encrypted passwords.
- They are attempting a pass-the-hash attack.
- Lucas believes that an attacker has successfully compromised his web server. Using the following output of
ps, identify the process ID he should focus on:root 507 0.0 0.1 258268 3288 ? Ssl 15:52 0:00 /usr/sbin/rsyslogd -nmessage+ 508 0.0 0.2 44176 5160 ? Ss 15:52 0:00 /usr/bin/dbusdaemon --system --address=systemd: --nofork --nopidfile --systemd-activaroot 523 0.0 0.3 281092 6312 ? Ssl 15:52 0:00 /usr/lib/accountsservice/accounts-daemonroot 524 0.0 0.7 389760 15956 ? Ssl 15:52 0:00 /usr/sbin/NetworkManager --no-daemonroot 527 0.0 0.1 28432 2992 ? Ss 15:52 0:00 /lib/systemd/systemd-logindapache 714 0.0 0.1 27416 2748 ? ...
System requirements
File format: ePUB
Copy protection: Adobe-DRM (Digital Rights Management)
System requirements:
- Computer (Windows; MacOS X; Linux): Install the free reader Adobe Digital Editions prior to download (see eBook Help).
- Tablet/smartphone (Android; iOS): Install the free app Adobe Digital Editions or the app PocketBook before downloading (see eBook Help).
- E-reader: Bookeen, Kobo, Pocketbook, Sony, Tolino and many more (not Kindle).
The file format ePub works well for novels and non-fiction books – i.e., „flowing” text without complex layout. On an e-reader or smartphone, line and page breaks automatically adjust to fit the small displays.
This eBook uses Adobe-DRM, a „hard” copy protection. If the necessary requirements are not met, unfortunately you will not be able to open the eBook. You will therefore need to prepare your reading hardware before downloading.
Please note: We strongly recommend that you authorise using your personal Adobe ID after installation of any reading software.
For more information, see our ebook Help page.