Practice Free CS0-003 Exam Online Questions
You are a cybersecurity analyst tasked with interpreting scan data from Company As servers. You must verify the requirements are being met for all of the servers and recommend changes if you find they are not
The company’s hardening guidelines indicate the following
• TLS 1 2 is the only version of TLS running.
• Apache 2.4.18 or greater should be used.
• Only default ports should be used.
INSTRUCTIONS
using the supplied data. record the status of compliance With the company’s guidelines for each server.
The question contains two parts: make sure you complete Part 1 and Part 2. Make recommendations for Issues based ONLY on the hardening guidelines provided.
Part 1:
AppServ1:

AppServ2:

AppServ3:

AppServ4:


Part 2:


A security alert was triggered when an end user tried to access a website that is not allowed per organizational policy. Since the action is considered a terminable offense, the SOC analyst collects the authentication logs, web logs, and temporary files, reflecting the web searches from the user’s workstation, to build the case for the investigation.
Which of the following is the best way to ensure that the investigation complies with HR or privacy policies?
- A . Create a timeline of events detailinq the date stamps, user account hostname and IP information associated with the activities
- B . Ensure that the case details do not reflect any user-identifiable information Password protect the evidence and restrict access to personnel related to the investigation
- C . Create a code name for the investigation in the ticketing system so that all personnel with access will not be able to easily identity the case as an HR-related investigation
- D . Notify the SOC manager for awareness after confirmation that the activity was intentional
An analyst is examining events in multiple systems but is having difficulty correlating data points.
Which of the following is most likely the issue with the system?
- A . Access rights
- B . Network segmentation
- C . Time synchronization
- D . Invalid playbook
An analyst is examining events in multiple systems but is having difficulty correlating data points.
Which of the following is most likely the issue with the system?
- A . Access rights
- B . Network segmentation
- C . Time synchronization
- D . Invalid playbook
A security analyst who works in the SOC receives a new requirement to monitor for indicators of
compromise.
Which of the following is the first action the analyst should take in this situation?
- A . Develop a dashboard to track the indicators of compromise.
- B . Develop a query to search for the indicators of compromise.
- C . Develop a new signature to alert on the indicators of compromise.
- D . Develop a new signature to block the indicators of compromise.
A Chief Information Security Officer (CISO) has determined through lessons learned and an
associated after-action report that staff members who use legacy applications do not adequately understand how to differentiate between non-malicious emails and phishing emails.
Which of the following should the CISO include in an action plan to remediate this issue?
- A . Awareness training and education
- B . Replacement of legacy applications
- C . Organizational governance
- D . Multifactor authentication on all systems
A forensic analyst is conducting an investigation on a compromised server
Which of the following should the analyst do first to preserve evidence”
- A . Restore damaged data from the backup media
- B . Create a system timeline
- C . Monitor user access to compromised systems
- D . Back up all log files and audit trails
An organization is conducting a pilot deployment of an e-commerce application. The application’s source code is not available.
Which of the following strategies should an analyst recommend to evaluate the security of the software?
- A . Static testing
- B . Vulnerability testing
- C . Dynamic testing
- D . Penetration testing
A cybersecurity analyst has recovered a recently compromised server to its previous state.
Which of the following should the analyst perform next?
- A . Eradication
- B . Isolation
- C . Reporting
- D . Forensic analysis
Which of the following is often used to keep the number of alerts to a manageable level when establishing a process to track and analyze violations?
- A . Log retention
- B . Log rotation
- C . Maximum log size
- D . Threshold value

