CompTIA Cybersecurity Analyst CySA+ V4 (New Version) Questions and Answers
A vulnerability analyst conducts a web application scan on an asset sitting behind a load balancer configured as a pass through:
The analyst launches the Zed Attack Proxy (ZAP) utility, conducts a scan, and receives the following alert:

Which of the following should the analyst propose as a remediation to the finding while keeping the site operational?
An incident response team investigates a possible data leak. Various IT systems collect evidence.
Which of the following processes is required to ensure that evidentiary artifacts are properly recorded?
An analyst reviews a summarized vulnerability report through a governance, risk, and compliance (GRC) reporting tool.
The following report correlates asset information from the configuration management database (CMDB) against detected vulnerabilities:

Which of the following servers should the analyst prioritize based on the target value, the risk, and the likelihood of exploitation?
Which of the following occurs during the analysis phase of the incident response process?
An analyst prepares an after action report following an incident in which multiple systems were compromised over several days.
The analyst provides raw event logs from each compromised system in the report and determines that a patient-zero system cannot be found.
Which of the following should the analyst do to determine the patient-zero system?
Which of the following is the main concept behind the use of an attack methodology framework?
A cybersecurity analyst requests a paid subscription to a threat intelligence feed relevant to a company's industry.
Which of the following best describes this type of feed?
A security operations center (SOC) analyst investigates the results of a password spray test conducted by the vulnerability management team.
The analyst must:

Identify Linux systems that have successful and unsuccessful logins with username "User1".
Create an output report named "linux-events" of all the events to a flat file.
The analyst issues the following console command:
ls /var/log/
The shortened output of the command is below:
Which of the following commands should the analyst use to meet the report output requirements?
A public threat intelligence report includes indicators of compromise (IoCs) for threat actors. The threat actors are exploiting a zero-day vulnerability that the vendor has not fixed.
Which of the following techniques should be used until a patch is available?
An analyst receives an alert that a user clicked on a malicious link. The analyst verifies that the link is malicious and was intended to capture credentials. The analyst verifies that the user visited the website, but no evidence indicates that the credentials were used. The analyst recommends that the user take remedial training and closes the case.
Which of the following steps in the incident response process did the analyst neglect?
Which of the following best describes why operational technology (OT) devices use compensating controls?
A security analyst responds to an alert regarding identity and access management activity within the cloud environment. The attacker is currently trying to gain access from one isolated cloud subscription to another via a compromised user role.
Which of the following aspects of the MITRE ATT & CK framework is the attacker trying to perform?
Which of the following is the most likely reason an organization might implement compensating controls?
A security operations center manager is concerned that after action reporting is not being completed in a timely manner.
Which of the following will allow the manager to quantify this concern?
The Chief Information Security Officer wants to improve internal security measures by continuously validating and verifying access to the production environment.
Which of the following concepts best describes this practice?
A binary file that might contain malicious code is hosted on an isolated machine. An analyst wants to quickly detect the malicious code.
Which of the following should the analyst use?
Which of the following allows an organization to leverage AI in various forms while protecting business objectives and data?
A security analyst must identify documents that contain encoded ActiveMime payloads in a directory containing thousands of files. The analyst runs the following command: grep -rail ActiveMime *
The command returns no output.
Which of the following Yet Another Recursive Acronym (YARA) rules should the analyst use to find the suspicious files?
A)

B)

C)

D)

An analyst reviews the following system logs from a recent breach attempt:

Which of the following techniques did the attacker attempt to use?
Which of the following describes the main benefits of MITRE ATT & CK Navigator?
A security analyst receives a notice about a possible data breach. The report identifies unapproved, current access dates for files found in the following personnel archives:

Which of the following actions should the analyst take first?
Which of the following is the best reason to heavily segment business-critical assets from within the network?
A security analyst reruns infrastructure as code (IaC) to tear down and rebuild a new environment after a ransomware attack.
Which of the following describes this phase?
A security operations center (SOC) manager reviews a document signed by the Chief Financial Officer (CFO), the sales director, and a customer to decide whether a contract breach occurred.
Which of the following best describes the document that includes key performance indicators (KPIs)?