B.4 CompTIA CySA+ CS0-002 Certification
Practice Exam with verified solutions
Some Remote Access Trojans (RATs) install a web server to allow access to the infected
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
machine. Others use a custom application that is run on the remote machine, such as ProRAT. |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
Once infected with this custom application, which other types of infections are possible with
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
this tool installed? (Select two.)
|||||| |||||| |||||| ||||||
Answer
Rootkit
Network enumeration ||||||
DDoS attack ||||||
Ransomware
SYN attack - ...,.🔹VERIFIED ANSWER **✔✔Rootkit
|||||| |||||| |||||| |||||| ||||||
Ransomware
Which of the following BEST describes a phishing attack? |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
Answer
This attack is used to intercept communications between an authorized user and the web
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
server.
A user is tricked into believing that a legitimate website is requesting their login information.
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
An attacker alters the XSS to run a Trojan horse with the victim's web browser.
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
In this attack, attackers use various weaknesses to hack into seemingly secure passwords. -
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
...,.🔹VERIFIED ANSWER **✔✔A user is tricked into believing that a legitimate website is |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
requesting their login information. |||||| |||||| ||||||
,Tom, a security analyst, is notified by Karen, an employee, that her work iPad has some setting
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
changes and a new app that she didn't download. What is the first step Tom should take? |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
Answer
Look through the event log for suspicious events.
|||||| |||||| |||||| |||||| |||||| |||||| ||||||
Ask Karen to turn off the device.
|||||| |||||| |||||| |||||| |||||| ||||||
Search online for any new known malware threats that match the indicators of compromise
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
(IOCs).
Run an antivirus software scan on Karen's device and scan the entire network. -
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
...,.🔹VERIFIED ANSWER **✔✔Run an antivirus software scan on Karen's device and scan |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
the entire network.
|||||| ||||||
Which of the following tools can be used to create botnets? |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
Answer
Shark, PlugBot, and Poison Ivy |||||| |||||| |||||| ||||||
Poison Ivy, Targa, and LOIC |||||| |||||| |||||| ||||||
Trin00, Targa, and Jolt2 |||||| |||||| ||||||
Jolt2, PlugBot, and Shark - ...,.🔹VERIFIED ANSWER **✔✔Shark, PlugBot, and Poison Ivy
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
You have configured your pfsense firewall to block URLs using DNS. You have selected the
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
block lists that work best for your company's needs. You have tested on your machine and
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
traffic to those sites in the list are blocked as expected. As you walk through your office several
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
months later, you notice that a user is on a site that is supposed to be blocked. |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
What might explain this? |||||| |||||| ||||||
Answer
The DNS cache on the user's local machine contains the information for that site.
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
The service has stopped and is no longer functioning.
|||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
Your firewall allows DNS requests to outside DNS servers.
|||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
, The user has hacked your firewall to allow their traffic through. - ...,.🔹VERIFIED ANSWER
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
**✔✔Your firewall allows DNS requests to outside DNS servers. |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
Which of the following is the process of obfuscating data by changing it into random
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
characters?
Answer
Data privacy ||||||
Data masking ||||||
Encryption
Tokenization - ...,.🔹VERIFIED ANSWER **✔✔Data masking |||||| |||||| |||||| |||||| ||||||
Which type of breach happens when an attacker removes or transfers data from your system to
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
another?
||||||
Answer
Insider data breach |||||| ||||||
Data integrity and availability
|||||| |||||| ||||||
Data exfiltration ||||||
Accidental data breach - ...,.🔹VERIFIED ANSWER **✔✔Data exfiltration |||||| |||||| |||||| |||||| |||||| |||||| ||||||
You have been asked to perform a penetration test for a company to see if any sensitive
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
information can be captured by a potential hacker. You have used Wireshark to capture a |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
series of packets. Using the tcp contains Invoice filter, you have found one packet. Using the
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
captured information shown, which of the following is the name of the company requesting
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
payment?
Answer
Lowes
Wood Specialist ||||||
ACME, Inc. ||||||
Practice Exam with verified solutions
Some Remote Access Trojans (RATs) install a web server to allow access to the infected
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
machine. Others use a custom application that is run on the remote machine, such as ProRAT. |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
Once infected with this custom application, which other types of infections are possible with
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
this tool installed? (Select two.)
|||||| |||||| |||||| ||||||
Answer
Rootkit
Network enumeration ||||||
DDoS attack ||||||
Ransomware
SYN attack - ...,.🔹VERIFIED ANSWER **✔✔Rootkit
|||||| |||||| |||||| |||||| ||||||
Ransomware
Which of the following BEST describes a phishing attack? |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
Answer
This attack is used to intercept communications between an authorized user and the web
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
server.
A user is tricked into believing that a legitimate website is requesting their login information.
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
An attacker alters the XSS to run a Trojan horse with the victim's web browser.
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
In this attack, attackers use various weaknesses to hack into seemingly secure passwords. -
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
...,.🔹VERIFIED ANSWER **✔✔A user is tricked into believing that a legitimate website is |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
requesting their login information. |||||| |||||| ||||||
,Tom, a security analyst, is notified by Karen, an employee, that her work iPad has some setting
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
changes and a new app that she didn't download. What is the first step Tom should take? |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
Answer
Look through the event log for suspicious events.
|||||| |||||| |||||| |||||| |||||| |||||| ||||||
Ask Karen to turn off the device.
|||||| |||||| |||||| |||||| |||||| ||||||
Search online for any new known malware threats that match the indicators of compromise
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
(IOCs).
Run an antivirus software scan on Karen's device and scan the entire network. -
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
...,.🔹VERIFIED ANSWER **✔✔Run an antivirus software scan on Karen's device and scan |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
the entire network.
|||||| ||||||
Which of the following tools can be used to create botnets? |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
Answer
Shark, PlugBot, and Poison Ivy |||||| |||||| |||||| ||||||
Poison Ivy, Targa, and LOIC |||||| |||||| |||||| ||||||
Trin00, Targa, and Jolt2 |||||| |||||| ||||||
Jolt2, PlugBot, and Shark - ...,.🔹VERIFIED ANSWER **✔✔Shark, PlugBot, and Poison Ivy
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
You have configured your pfsense firewall to block URLs using DNS. You have selected the
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
block lists that work best for your company's needs. You have tested on your machine and
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
traffic to those sites in the list are blocked as expected. As you walk through your office several
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
months later, you notice that a user is on a site that is supposed to be blocked. |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
What might explain this? |||||| |||||| ||||||
Answer
The DNS cache on the user's local machine contains the information for that site.
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
The service has stopped and is no longer functioning.
|||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
Your firewall allows DNS requests to outside DNS servers.
|||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
, The user has hacked your firewall to allow their traffic through. - ...,.🔹VERIFIED ANSWER
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
**✔✔Your firewall allows DNS requests to outside DNS servers. |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
Which of the following is the process of obfuscating data by changing it into random
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
characters?
Answer
Data privacy ||||||
Data masking ||||||
Encryption
Tokenization - ...,.🔹VERIFIED ANSWER **✔✔Data masking |||||| |||||| |||||| |||||| ||||||
Which type of breach happens when an attacker removes or transfers data from your system to
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
another?
||||||
Answer
Insider data breach |||||| ||||||
Data integrity and availability
|||||| |||||| ||||||
Data exfiltration ||||||
Accidental data breach - ...,.🔹VERIFIED ANSWER **✔✔Data exfiltration |||||| |||||| |||||| |||||| |||||| |||||| ||||||
You have been asked to perform a penetration test for a company to see if any sensitive
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
information can be captured by a potential hacker. You have used Wireshark to capture a |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
series of packets. Using the tcp contains Invoice filter, you have found one packet. Using the
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
captured information shown, which of the following is the name of the company requesting
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
payment?
Answer
Lowes
Wood Specialist ||||||
ACME, Inc. ||||||