This is the free Comptia CS0-003 practice question bank —
270 of 528 total questions, each with a full explanation, free to
read with no signup required. Updated 2026-04-24.
Every answer is verified against official Comptia documentation —
see our methodology.
Question 1
A security analyst is testing a web application for vulnerabilities using Burp Suite. During the assessment, a capture of the following HTTP request and response is shown in the command-line interface:
After inspecting the request, the security analyst notices that it does not include any additional protections or validation mechanisms. Which of the following vulnerabilities is most likely present in the web application?
A. IDOR
B. CSRF
C. SQLi
D. XSS
Show Answer
Correct Answer: B
Explanation: An HTTP request that performs an action but lacks additional protections or validation mechanisms—such as anti-CSRF tokens, custom headers, or origin/referrer checks—most strongly indicates a Cross-Site Request Forgery (CSRF) vulnerability. The absence of these safeguards allows an attacker to trick a victim’s browser into submitting unintended requests. IDOR would require evidence of predictable object identifiers, while SQLi and XSS would require observable input handling or output rendering issues, which are not implied here.
Question 1
A security operations (SOC) manager develops response mechanisms as part of playbook development efforts. The SOC manager needs to accomplish the following:
• Document adversarial activities.
• Map adversarial activities to a linear progression of sequential phases.
• Provide broad coverage of threat actions without addressing specific tactics, techniques, and procedures (TTPs).
Which of the following is the most reliable source for this information?
A. MITRE ATT&CK
B. Cyber COBRA
C. Diamond Model of Intrusion Analysis
D. Cyber Kill Chain
Show Answer
Correct Answer: D
Explanation: The requirements describe a model that documents adversarial activity, represents it as a linear sequence of phases, and provides high-level coverage without detailing specific tactics, techniques, and procedures. The Cyber Kill Chain meets these criteria by outlining a sequential, phase-based view of attacks (reconnaissance through actions on objectives) at a broad, conceptual level. MITRE ATT&CK is explicitly TTP-focused, the Diamond Model is analytical rather than linear, and Cyber COBRA is not a standard framework for this purpose.
Question 2
The architecture team has been given a mandate to reduce the triage time of phishing incidents by 20%. Which of the following solutions will most likely help with this effort?
A. Integrate a SOAR platform.
B. Increase the budget to the security awareness program.
C. Implement an EDR tool.
D. Create new correlation rules for the SIEM.
Show Answer
Correct Answer: A
Explanation: Integrating a SOAR platform automates phishing triage steps (enrichment, reputation checks, sandboxing, user/context lookups, and response actions), significantly reducing manual analyst effort and time per incident. This directly targets triage time reduction. The other options improve prevention or detection but do not most directly accelerate triage workflows.
Question 2
A managed service provider manages servers in customer-assigned Internet Protocol spaces. The provider discovers that these servers are not included in scheduled network scans, but the provider cannot scan the servers without the customers' explicit permission. Which of the following scanning methods should the provider use to scan these individual servers?
A. Agent-based scans
B. System baseline scans
C. External network scans
D. Device fingerprinting
Show Answer
Correct Answer: A
Explanation: Agent-based scans run locally on the individual servers using an installed agent, so they do not require network-wide scanning permissions. This allows the provider to assess servers in customer-assigned IP spaces with explicit host-level permission, avoiding unauthorized network scans. The other options either are not true scanning methods for this scenario or require network probing that is not permitted.
Question 3
A security analyst is investigating an unusually high volume of requests received on a web server. Based on the following command and output:
Which of the following best describes the activity that the analyst will confirm?
A. SQL injection
B. Directory brute force
C. Remote command execution
D. Cross-site scripting
Show Answer
Correct Answer: B
Explanation: An unusually high volume of HTTP requests targeting many different paths or filenames on a web server is characteristic of directory or file brute forcing. This activity involves systematically probing common directories and files to discover hidden or unprotected resources, which fits better than SQL injection, remote command execution, or cross-site scripting, all of which rely on specific payloads rather than broad path enumeration.
Question 3
A spillage incident results in the access of controlled information across multiple unauthorized business units. Which of the following response techniques should be implemented first?
A. Analysis and triage
B. Containment and isolation
C. Evidence and legal hold
D. Escalation and monitoring
Show Answer
Correct Answer: B
Explanation: In an active data spillage involving unauthorized access, the first priority is to immediately stop further exposure. Containment and isolation prevent additional spread or access before conducting analysis, evidence preservation, or escalation.
Question 4
A security analyst discovers that, over three months, an attacker has slowly created multiple accounts on a web server while avoiding detection. Which of the following best describes this threat actor?
A. Script kiddie threat actor
B. Advanced persistent threat actor
C. Insider threat actor
D. Hacktivist threat actor
Show Answer
Correct Answer: B
Explanation: The attacker operated slowly over several months and deliberately avoided detection while establishing persistence by creating multiple accounts. This long-term, stealthy behavior is characteristic of an Advanced Persistent Threat (APT), not a script kiddie (noisy, unsophisticated), insider (would already have access), or hacktivist (typically goal-driven and overt).
Question 4
Which of the following are characteristics of Zero Trust Network Access?
A. Application programming interface security and continuous monitoring
B. A gateway controller and agent flows
C. Virtualization and data protection
D. An attack surface and a protect surface
Show Answer
Correct Answer: D
Explanation: Zero Trust Network Access is built around identifying a limited protect surface (critical data, applications, assets, and services) and designing controls to minimize and defend against the broader attack surface. This protect-surface–centric model is a defining characteristic of Zero Trust frameworks, unlike the other options which describe unrelated or partial security concepts.
Question 5
An organization wants to implement an identity and access management technology that is resistant to phishing attacks. Which of the following is the best technology to implement?
A. Federation
B. Privileged access management
C. Passwordless authentication
D. Single sign-on
Show Answer
Correct Answer: C
Explanation: Passwordless authentication is specifically designed to be resistant to phishing because it removes shared secrets like passwords that attackers can steal. Modern passwordless methods (for example, FIDO2/WebAuthn, smart cards, or certificate-based authentication) rely on public-key cryptography and domain binding, so credentials cannot be replayed on fake websites. The other options (federation, PAM, and SSO) can still rely on passwords and are not inherently phishing-resistant.
Question 5
Which of the following should a cybersecurity analyst utilize when a notification is inaccurate?
A. Data enrichment
B. Dashboard creation
C. Threat hunting
D. Alert tuning
Show Answer
Correct Answer: D
Explanation: When a notification is inaccurate (e.g., a false positive), the appropriate action is to adjust the rules and thresholds that generate it. Alert tuning directly refines detection logic to reduce noise and improve accuracy. Data enrichment adds context after alerts fire, dashboards visualize data, and threat hunting is proactive investigation—not fixes for inaccurate alerts.
$19
Get all 528 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.