Comptia

CS0-003 Free Practice Questions — Page 10

Question 46

While performing a dynamic analysis of a malicious file, a security analyst notices the memory address changes every time the process runs. Which of the following controls is most likely preventing the analyst from finding the proper memory address of the piece of malicious code?

A. Address space layout randomization
B. Data execution prevention
C. Stack canary
D. Code obfuscation
Show Answer
Correct Answer: A
Explanation:
The behavior described—memory addresses changing each time the process runs—is characteristic of Address Space Layout Randomization (ASLR). ASLR randomizes the locations of code, stack, heap, and libraries in memory on each execution, making it difficult to reliably identify or predict the address of malicious code during dynamic analysis. The other options do not affect address randomization.

Question 47

An IDS is triggered during after-hours operations. The indicator records an abnormal amount of SYN requests being sent to port 21 from numerous external systems. A security analyst reports this information to the IR team for further investigation. Which of the following best describes this incident?

A. A sniff attack through the DNS port
B. A buffer overflow attack through the Telnet port
C. A reconnaissance attack through the SSH port
D. A DDoS attack through the FTP port
Show Answer
Correct Answer: D
Explanation:
The IDS reports an abnormal volume of SYN requests, which is characteristic of a SYN flood. The traffic originates from numerous external systems, indicating a distributed attack. The target is port 21, which corresponds to FTP. Together, this describes a DDoS attack against the FTP service.

Question 48

After a series of UEBA alerts, a company’s SOC observes an extended period of suspicious outbound traffic all with the same destination. Which of the following steps of the cyber kill chain has this attack completed?

A. Weaponization
B. Command and control
C. Reconnaissance
D. Exploitation
Show Answer
Correct Answer: B
Explanation:
An extended period of suspicious outbound traffic all going to the same destination is characteristic of an infected host communicating with an external command server. This indicates the Command and Control phase of the cyber kill chain, where the attacker maintains communication with compromised systems to issue commands or exfiltrate data.

Question 49

Which of the following best describes the benefit of implementing a PAM solution?

A. Measuring and validating the integrity of the database
B. Controlling and monitoring the use of administrative accounts
C. Storing and protecting PKI certificate private keys
D. Configuring and enforcing password complexity requirements
Show Answer
Correct Answer: B
Explanation:
Privileged Access Management (PAM) focuses on securing, controlling, and monitoring privileged (administrative) accounts to reduce the risk of misuse or compromise. The other options describe functions of database integrity tools, PKI/HSM solutions, or general password policy mechanisms rather than PAM’s core purpose.

Question 50

The SOC team reestablishes user access after a threat actor successfully performed a business account compromise in which the attacker revoked the legitimate user's access. The following logs are provided to a SOC analyst: Which of the following did the threat actor most likely use during the compromise?

A. Brute-force password attack
B. A valid, leaked credential
C. Command-and-control traffic
D. Introduction of a new account
Show Answer
Correct Answer: B
Explanation:
In a business account compromise where the attacker successfully logs in, revokes the legitimate user’s access, removes MFA, and changes credentials without generating excessive failed-login events, the most likely method is the use of valid, leaked credentials. A brute-force attack would produce many failed authentication logs, command-and-control traffic is not directly related to initial account takeover, and introducing a new account would not require revoking the original user’s access.

Question 51

Several users received a phishing email containing a malicious file that bypassed the organization’s email security tool. Based on the SIEM logs, users did not open the file within the environment. In which of the following phases of the MITRE ATT&CK framework was the attack stopped?

A. Lateral movement
B. Execution
C. Initial access
D. Discovery
Show Answer
Correct Answer: B
Explanation:
The phishing email was delivered, but users did not open or run the malicious file. That means the payload was never executed. In MITRE ATT&CK terms, the attack was stopped at the Execution phase, which was prevented. Initial Access was attempted via phishing, but execution never occurred, and later phases (discovery, lateral movement) were not reached.

Question 52

A vulnerability scan shows the following vulnerabilities in the environment: At the same time, the following security advisory was released: "A zero-day vulnerability with a CVSS score of 10 may be affecting your web server. The vendor is working on a patch or workaround." Which of the following actions should the security analyst take first?

A. Contact the web systems administrator and request that they shut down the asset.
B. Monitor the patch releases for all items and escalate patching to the appropriate team.
C. Run the vulnerability scan again to verify the presence of the critical finding and the zero-day vulnerability in the environment.
D. Forward the advisory to the web security team and initiate the prioritization strategy for the other vulnerabilities.
Show Answer
Correct Answer: D
Explanation:
A zero-day with CVSS 10 has no patch or workaround yet, so the first priority is communication and coordination rather than remediation. Immediately forwarding the advisory to the web/security team ensures awareness and enables monitoring, compensating controls, and risk assessment. At the same time, initiating prioritization for other known vulnerabilities allows remediation of issues that can be fixed now, reducing overall risk. Shutting down the asset is premature, rescanning won’t reliably detect a zero-day, and monitoring patches alone delays necessary coordination.

Question 53

Executives want to compare certain metrics from the most recent and last reporting periods to determine whether the metrics are increasing or decreasing. Which of the following would provide the necessary information to satisfy this request?

A. Count level
B. Trending analysis
C. Impact assessment
D. Severity score
Show Answer
Correct Answer: B
Explanation:
The request is to compare metrics between the most recent and prior reporting periods to see whether they are increasing or decreasing. Trending analysis is specifically designed to compare data over time and identify upward or downward patterns, making it the correct choice.

Question 54

Alerts from the security dashboard are reporting a cloud-based host is suspected to be corrupt. The OS is not loading. The initial investigation concludes that the OS files were modified. Which of the following security controls provided the report?

A. FIM
B. DLP
C. NIDS
D. API gateway
Show Answer
Correct Answer: A
Explanation:
File Integrity Monitoring (FIM) detects unauthorized or unexpected changes to critical system files, including OS files. Since the alert reports that OS files were modified and the system will not load, FIM is the control that would identify and report such corruption. DLP focuses on data exfiltration, NIDS monitors network traffic, and an API gateway manages API access, none of which directly detect OS file modification.

Question 55

A SOC manager reviews metrics from the last four weeks to investigate a recurring availability issue. The manager finds similar events correlating to the times of the reported issues. Which of the following methods would the manager most likely use to resolve the issue?

A. Vulnerability assessment
B. Root cause analysis
C. Recurrence reports
D. Lessons learned
Show Answer
Correct Answer: B
Explanation:
The manager is correlating repeated availability issues over time to identify why they keep occurring. Root cause analysis focuses on examining patterns, events, and contributing factors to determine the underlying cause of a recurring problem so it can be permanently resolved. The other options either identify weaknesses (vulnerability assessment), document recurrence (recurrence reports), or capture post-incident takeaways (lessons learned) rather than directly resolving the root issue.

$19

Get all 528 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.