| Exam Code/Number: | CS0-004Join the discussion |
| Exam Name: | CompTIA Cybersecurity Analyst (CySA+) Certification Exam |
| Certification: | Curam Software |
| Question Number: | 190 |
| Publish Date: | Sep 05, 2026 |
|
Rating
100%
|
|
During a routine review of DNS logs, a security analyst observes that Host X has been making frequent DNS requests to domains with random alphanumeric strings (e.g.. atd8ekthj.xyz). IPS anomaly rules are blocking these domains. This behavior started shortly after a new software Installation on the host. Which of the following should the analyst do first to determine whether Host X has been compromised?
An incident response team investigates a possible data leak. Various IT systems collect evidence. Which of the following processes is required to ensure that evidentiary artifacts are properly recorded?
A security operations center (SOC) manager reviews a document signed by the Chief Financial Officer (CFO), the sales director, and a customer to decide whether a contract breach occurred.
Which of the following best describes the document that includes key performance indicators (KPIs)?
Which of the following tools provides logs that show user access to prohibited cloud storage, identifying whether a file was downloaded to a personal device?
Given the following report:
Which of the following vulnerabilities should be prioritized for immediate remediation?