CS0-001 CompTIA CSA+ Certification Exam

Loading demo links...

Showing 7–9 of 20 questions

Question 7

A red team actor observes it is common practice to allow cell phones to charge on company computers, but access to the memory storage is blocked. Which of the following are common attack techniques that take advantage of this practice? (Choose two.)

Select all that apply, then click Submit answer.

  • A USB attack that tricks the computer into thinking the connected device is a keyboard, and then sends characters one at a time as a keyboard to launch the attack (a prerecorded series of keystrokes)

  • A USB attack that turns the connected device into a rogue access point that spoofs the configured wireless SSIDs

  • A Bluetooth attack that modifies the device registry (Windows PCs only) to allow the flash drive to mount, and then launches a Java applet attack

  • A Bluetooth peering attack called “Snarfing” that allows Bluetooth connections on blocked device types if physically connected to a USB port

  • A USB attack that tricks the system into thinking it is a network adapter, then runs a user password hash gathering utility for offline password cracking

Question 8

An analyst was tasked with providing recommendations of technologies that are PKI X.509 compliant for a variety of secure functions. Which of the following technologies meet the compatibility requirement? (Choose three.)

Select all that apply, then click Submit answer.

  • 3DES

  • AES

  • IDEA

  • PKCS

  • PGP

  • SSL/TLS

  • TEMPEST

Question 9

Creating a lessons learned report following an incident will help an analyst to communicate which of the following information? (Choose two.)

Select all that apply, then click Submit answer.

  • Root cause analysis of the incident and the impact it had on the organization

  • Outline of the detailed reverse engineering steps for management to review

  • Performance data from the impacted servers and endpoints to report to management

  • Enhancements to the policies and practices that will improve business responses

  • List of IP addresses, applications, and assets