CS0-001 CompTIA CSA+ Certification Exam

Loading demo links...

Showing 1–3 of 20 questions

Question 1

HOTSPOT

A security analyst performs various types of vulnerability scans.

Review the vulnerability scan results to determine the type of scan that was executed and if a false positive occurred for each device.

Instructions:

Select the Results Generated drop-down option to determine if the results were generated from a credentialed scan, non-credentialed scan, or a compliance scan.

For ONLY the credentialed and non-credentialed scans, evaluate the results for false positives and check the findings that display false positives. NOTE: If you would like to uncheck an option that is currently selected, click on the option a second time.

Lastly, based on the vulnerability scan results, identify the type of Server by dragging the Server to the results. The Linux Web Server, File-Print Server and Directory Server are draggable.

If at any time you would like to bring back the initial state of the simulation, please select the Reset All button. When you have completed the simulation, please select the Done button to submit. Once the simulation is submitted, please select the Next button to continue.

Hot Area:

Answer is in the explanation below.

Question 2

As part of an upcoming engagement for a client, an analyst is configuring a penetration testing application to ensure the scan complies with information defined in the SOW. Which of the following types of information should be considered based on information traditionally found in the SOW? (Choose two.)

Select all that apply, then click Submit answer.

  • Timing of the scan

  • Contents of the executive summary report

  • Excluded hosts

  • Maintenance windows

  • IPS configuration

  • Incident response policies

Question 3

Considering confidentiality and integrity, which of the following make servers more secure than desktops? (Choose three.)

Select all that apply, then click Submit answer.

  • VLANs

  • OS

  • Trained operators

  • Physical access restriction

  • Processing power

  • Hard drive capacity