CompTIA CS0-001 Actual Free Exam Questions & Community Discussion

  • Exam Code/Number: CS0-001
  • Exam Name/Title: CompTIA Cybersecurity Analyst (CySA+) Certification Exam
  • Certification Provider: CompTIA
  • Corresponding Certification: CSA+
  • Exam Questions: 458
  • Updated On: Jul 24, 2026
A security analyst is reviewing the following log after enabling key-based authentication.

Given the above information, which of the following steps should be performed NEXT to secure the system?
Correct Answer: B Vote an answer
A penetration test for the Internal DNS service of a company is scheduled, and the security analyst uses the ccpdump udp port S3 -1 ech0 command to get a packet capture from the DNS server that will be used to confirm any findings During the daily report meeting the penetration tester reports a zone transfer vulnerability using the dig -axfr command against the server The analyst opens the packet capture from the day before, but there are no traces of the transfer. Which of the following is the MOST likely cause of this issue?
Correct Answer: B Vote an answer
A security administrator recently deployed a virtual honeynet. The honeynet is not protected by the company's firewall, while all production networks are protected by a stateful firewall. Which of the following would BEST allow an external penetration tester to determine which one is the honeynet's network?
Correct Answer: D Vote an answer
The software development team pushed a new web application into production for the accounting department. Shortly after the application was published, the head of the accounting department informed IT operations that the application was not performing as intended. Which of the following SDLC best practices was missed?
Correct Answer: E Vote an answer
A Chief Executive Officer (CEO) wants to implement BYOD in the environment. Which of the following options should the security analyst suggest to protect corporate data on these devices? (Choose two.)
Correct Answer: B,F Vote an answer
A company that is hiring a penetration tester wants to exclude social engineering from the list of authorized activities. Which of the following documents should include these details?
Correct Answer: B Vote an answer
An organization has recently found some of its sensitive information posted to a social media site. An investigation has identified large volumes of data leaving the network with the source traced back to host 192.168.1.13. An analyst performed a targeted Nmap scan of this host with the results shown below:

Subsequent investigation has allowed the organization to conclude that all of the well-known, standard ports are secure. Which of the following services is the problem?
Correct Answer: A Vote an answer
The security operations team underwent an audit and found that meeting full compliance Is causing severe Impact to critical systems. Which of the following should the security analyst recommend?
Correct Answer: D Vote an answer
An insurance company employs quick-response team drivers that carry corporate-issued mobile devices with the insurance company's app installed on them. Devices are configuration-hardened by an MDM and kept up to date. The employees use the app to collect insurance claim information and process payments. Recently, a number of customers have filed complaints of credit card fraud against the insurance company, which occurred shortly after their payments were processed via the mobile app. The cyber-incident response team has been asked to investigate. Which of the following is MOST likely the cause?
Correct Answer: B Vote an answer
Company A's security policy states that only PKI authentication should be used for all SSH accounts. A security analyst from Company A is reviewing the following auth.log and configuration settings:

Which of the following changes should be made to the following sshd_config file to establish compliance with the policy?
Correct Answer: A Vote an answer
Which of the following is a vulnerability that is specific to hypervisors?
Correct Answer: C Vote an answer
0
0
0
10