This is the free Comptia CS0-003 practice question bank —
270 of 534 total questions, each with a full explanation, free to
read with no signup required. Updated 2026-08-06.
Every answer is verified against official Comptia documentation —
see our methodology.
Question 1
An analyst receives the following summary report for vulnerabilities on multiple hosts:
Which of the following servers should the analyst remediate first?
A. COMPTIA-WEB01
B. COMPTIA-APP01
C. COMPTIA-FS01
D. COMPTIA-DC01
Show Answer
Correct Answer: D
Explanation: Based on typical vulnerability prioritization, a domain controller is a critical asset whose compromise can affect the entire environment. When choosing which server to remediate first, asset criticality generally outweighs raw vulnerability counts if critical vulnerabilities are present. Therefore, the domain controller should be prioritized.
Question 2
A security analyst discovers several vulnerabilities on a critical legacy system. The analyst must recommend a solution with the following limitations:
• No downtime is permitted due to criticality.
• Patches for the vulnerabilities do not exist.
• No redundancy systems are in place.
Which of the following is the best risk management strategy to implement?
A. Transference
B. Mitigation
C. Avoidance
D. Acceptance
Show Answer
Correct Answer: D
Explanation: With no downtime allowed, no vendor patches available, and no redundant systems to enable replacement or maintenance, the organization cannot realistically avoid or remediate the risk through the listed strategies. Transference shifts financial impact but does not reduce the technical risk. Acceptance is the most appropriate risk management decision until a viable remediation becomes available.
Sources:
https://www.cyberprotex.com/uploads/2/4/5/3/24530641/cas-004-qs-and-as-testking_1.pdf
Question 3
A security analyst is scanning an ICS host (192.168.1.5) in an industrial plant for insecure ports while minimizing the impact to uptime or performance. Which of following commands should the analyst use to perform the task?
A. nmap 192.168.1.5 -Т1 -P 21
B. nmap 192.168.1.5 -T2 -P 3389
C. nmap 192.168.1.5 -T3 -P 22
D. nmap 192.168.1.5 -T5 -P 80
Show Answer
Correct Answer: A
Explanation: For an ICS/OT system, minimizing impact is the priority. Nmap timing template -T1 (sneaky) sends probes very slowly to reduce load on the target, making it the safest choice among the options. Although the options use '-P' where modern Nmap uses '-p' to specify ports, the distinguishing factor is the timing template: -T1 is the lowest-impact scan compared with -T2, -T3, or -T5.
Question 4
A Chief Information Security Officer wants to map all of the attack vectors that the company faces each day. Which of the following recommendations should the company align its security controls around?
A. OSSTMM
B. Diamond Model of Intrusion Analysis
C. ОWASP
D. MITRE ATT&CK
Show Answer
Correct Answer: D
Explanation: MITRE ATT&CK is a knowledge base of adversary tactics, techniques, and procedures (TTPs) used to map likely attack vectors and align detection and defensive security controls. OSSTMM is a security testing methodology, the Diamond Model is an intrusion analysis framework, and OWASP primarily focuses on web application security.
Question 5
A new policy prohibits external access to database servers. A recent external port scan identified the following open Transmission Control Protocol (TCP) ports:
• 21
• 25
• 68
• 80
• 389
• 443
• 587
• 1514
• 3306
• 3389
• 8080
Which of the ports must be closed to be compliant with the new policy? (Choose two.)
A. 25
B. 587
C. 1514
D. 3306
E. 3389
F. 8080
Show Answer
Correct Answer: D, E
Explanation: The policy prohibits external access to database servers. TCP 3306 is the default MySQL database service port and must not be externally accessible. TCP 3389 is Remote Desktop Protocol (RDP), which provides remote administrative access to the server and also must be closed to prevent external access. The other listed ports correspond to services that may be used by other systems and are not inherently database access ports in this context.
Question 6
A security operations (SOC) manager develops response mechanisms as part of playbook development efforts. The SOC manager needs to accomplish the following:
• Document adversarial activities.
• Map adversarial activities to a linear progression of sequential phases.
• Provide broad coverage of threat actions without addressing specific tactics, techniques, and procedures (TTPs).
Which of the following is the most reliable source for this information?
A. MITRE ATT&CK
B. Cyber COBRA
C. Diamond Model of Intrusion Analysis
D. Cyber Kill Chain
Show Answer
Correct Answer: D
Explanation: The Cyber Kill Chain documents adversarial activity as a linear sequence of attack phases (reconnaissance through actions on objectives). It provides broad coverage of attack progression without cataloging detailed tactics, techniques, and procedures. MITRE ATT&CK is centered on TTPs rather than a strictly linear model; the Diamond Model focuses on relationships among adversary, capability, infrastructure, and victim rather than sequential phases; Cyber COBRA is not the standard framework for this purpose.
Question 7
A managed service provider manages servers in customer-assigned Internet Protocol spaces. The provider discovers that these servers are not included in scheduled network scans, but the provider cannot scan the servers without the customers' explicit permission. Which of the following scanning methods should the provider use to scan these individual servers?
A. Agent-based scans
B. System baseline scans
C. External network scans
D. Device fingerprinting
Show Answer
Correct Answer: A
Explanation: Agent-based scans install a local agent on the individual server to perform vulnerability assessment without requiring broad network scanning of the customer's IP space. This fits the requirement to scan specific servers while respecting restrictions on network scans. System baseline scans measure configuration state rather than perform this type of vulnerability scanning, external network scans would still require scanning the customer's network space, and device fingerprinting is an identification technique, not the appropriate scanning method.
Question 8
A spillage incident results in the access of controlled information across multiple unauthorized business units. Which of the following response techniques should be implemented first?
A. Analysis and triage
B. Containment and isolation
C. Evidence and legal hold
D. Escalation and monitoring
Show Answer
Correct Answer: B
Explanation: In an active data spillage incident, the first priority is to contain the incident and isolate affected systems or access paths to prevent further unauthorized exposure. Analysis, evidence preservation, and escalation follow once the spread has been stopped.
Question 9
Which of the following are characteristics of Zero Trust Network Access?
A. Application programming interface security and continuous monitoring
B. A gateway controller and agent flows
C. Virtualization and data protection
D. An attack surface and a protect surface
Show Answer
Correct Answer: D
Explanation: Zero Trust Network Access is built around minimizing the attack surface by defining and securing the protect surface, applying least-privilege access and continuous verification. The other options describe related security concepts or components but are not the defining paired characteristics of ZTNA.
Question 10
Which of the following should a cybersecurity analyst utilize when a notification is inaccurate?
A. Data enrichment
B. Dashboard creation
C. Threat hunting
D. Alert tuning
Show Answer
Correct Answer: D
Explanation: Alert tuning is used to refine detection rules, thresholds, and conditions when notifications are inaccurate or produce false positives/false negatives. Data enrichment adds context after an alert is generated, dashboards visualize information, and threat hunting is a proactive search for threats rather than correcting alert accuracy.
$19
Get all 534 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.