exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 211 discussion

Actual exam question from CompTIA's CS0-002
Question #: 211
Topic #: 1
[All CS0-002 Questions]

A company recently experienced financial fraud, which included shared passwords being compromised and improper levels of access being granted.

The company has asked a security analyst to help improve its controls. Which of the following will MOST likely help the security analyst develop better controls?

  • A. An evidence summarization
  • B. An incident response plan
  • C. A lessons-learned report
  • D. An indicator of compromise
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Comptia_Secret_Service
Highly Voted 2 years, 4 months ago
Selected Answer: C
I expected there to be a "principle of least privilege" as a choice lol. But i think C is the answer here. the incident has happened, there has to be a lessons learned report, you want to learn from the incident and apply the lessons in developing security controls. Absolutely not D lol, but i see why people answered it, still a dumbass question anyway.
upvoted 5 times
2Fish
2 years, 1 month ago
Agree. C is the best answer here. We need to see a bigger picture other than a single IOC.
upvoted 1 times
...
...
kiduuu
Most Recent 2 years ago
Selected Answer: C
A lessons-learned report is a comprehensive analysis of an incident, detailing what happened, how it happened, and what could have been done to prevent it. It provides insights into the incident and identifies areas of improvement to prevent similar incidents from happening in the future. By reviewing the lessons-learned report, the security analyst can identify gaps in the company's controls that contributed to the fraud and suggest measures to strengthen them. An incident response plan (Option B) outlines the procedures for responding to security incidents. While it is a crucial document, it is not the best option for helping the security analyst develop better controls to prevent financial fraud.
upvoted 2 times
...
Brian93
2 years, 1 month ago
Selected Answer: B
B is the answer
upvoted 2 times
...
Frog_Man
2 years, 5 months ago
D - would cover the present and future, whereas D describes the past. Lessons learned is information about what happened and not necessarily a solution.
upvoted 2 times
...
abrilo
2 years, 5 months ago
Indicators of compromise (IOCs) serve as forensic evidence of potential intrusions on a host system or network. These artifacts enable information security (InfoSec) professionals and system administrators to detect intrusion attempts or other malicious activities. Security researchers use IOCs to better analyze a particular malware’s techniques and behaviors. IOCs also provides actionable threat intelligence that can be shared within the community to further improve an organization’s incident response and remediation strategies.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago