Comptia

CS0-003 Free Practice Questions — Page 11

Question 101

The SOC team reestablishes user access after a threat actor successfully performed a business account compromise in which the attacker revoked the legitimate user's access. The following logs are provided to a SOC analyst: Which of the following did the threat actor most likely use during the compromise?

A. Brute-force password attack
B. A valid, leaked credential
C. Command-and-control traffic
D. Introduction of a new account
Show Answer
Correct Answer: B
Explanation:
A business account compromise where the attacker revokes the legitimate user's access is most consistent with the attacker authenticating using already-valid credentials, then changing account settings (such as password or MFA) to lock out the user. A brute-force attack would typically leave evidence of repeated failed logins, command-and-control traffic is not the authentication method, and creating a new account does not explain taking over the existing business account.

Question 102

Several users received a phishing email containing a malicious file that bypassed the organization’s email security tool. Based on the SIEM logs, users did not open the file within the environment. In which of the following phases of the MITRE ATT&CK framework was the attack stopped?

A. Lateral movement
B. Execution
C. Initial access
D. Discovery
Show Answer
Correct Answer: B
Explanation:
A phishing email with a malicious attachment was delivered, so the delivery/initial access attempt reached the user. However, because the attachment was never opened, the malicious code was never executed. The attack was therefore stopped at the Execution phase, before any discovery or lateral movement could occur.

Question 103

A vulnerability scan shows the following vulnerabilities in the environment: At the same time, the following security advisory was released: "A zero-day vulnerability with a CVSS score of 10 may be affecting your web server. The vendor is working on a patch or workaround." Which of the following actions should the security analyst take first?

A. Contact the web systems administrator and request that they shut down the asset.
B. Monitor the patch releases for all items and escalate patching to the appropriate team.
C. Run the vulnerability scan again to verify the presence of the critical finding and the zero-day vulnerability in the environment.
D. Forward the advisory to the web security team and initiate the prioritization strategy for the other vulnerabilities.
Show Answer
Correct Answer: D
Explanation:
A newly disclosed zero-day has no vendor patch yet, so the immediate response is to notify the responsible web security team so they can assess exposure, implement any available mitigations or monitoring, and incorporate the issue into risk prioritization. Re-running a vulnerability scan is unlikely to reliably detect a new zero-day, monitoring for patches alone delays immediate coordination, and shutting down the server without a risk-based decision is premature.

Question 104

Executives want to compare certain metrics from the most recent and last reporting periods to determine whether the metrics are increasing or decreasing. Which of the following would provide the necessary information to satisfy this request?

A. Count level
B. Trending analysis
C. Impact assessment
D. Severity score
Show Answer
Correct Answer: B
Explanation:
Trending analysis compares metrics across reporting periods to identify patterns and direction of change, such as whether values are increasing or decreasing. Count level is a point-in-time measure, impact assessment evaluates consequences, and severity score rates the seriousness of findings rather than showing changes over time.

Question 105

Alerts from the security dashboard are reporting a cloud-based host is suspected to be corrupt. The OS is not loading. The initial investigation concludes that the OS files were modified. Which of the following security controls provided the report?

A. FIM
B. DLP
C. NIDS
D. API gateway
Show Answer
Correct Answer: A
Explanation:
File Integrity Monitoring (FIM) detects unauthorized changes to critical system and operating system files. Since the investigation found that OS files were modified and the host is suspected to be compromised, FIM is the security control that would generate such an alert. DLP focuses on data exfiltration, NIDS monitors network traffic, and an API gateway manages and secures API access rather than monitoring OS file integrity.

Question 106

A SOC manager reviews metrics from the last four weeks to investigate a recurring availability issue. The manager finds similar events correlating to the times of the reported issues. Which of the following methods would the manager most likely use to resolve the issue?

A. Vulnerability assessment
B. Root cause analysis
C. Recurrence reports
D. Lessons learned
Show Answer
Correct Answer: B
Explanation:
Reviewing several weeks of metrics to correlate recurring availability events is part of identifying the underlying cause of a repeated problem. Root cause analysis is the method used to determine why the incidents keep occurring and to implement a lasting fix. Vulnerability assessments identify security weaknesses, recurrence reports summarize repeated incidents, and lessons learned are conducted after an incident to improve future response.

Question 107

The security team reviews a web server for XSS and runs the following Nmap scan: Which of the following most accurately describes the result of the scan?

A. An output of characters > and " as the parameters used in the attempt
B. The vulnerable parameter ID and unfiltered characters returned
C. The vulnerable parameter ID and unfiltered or encoded characters passed > and " as unsafe
D. The vulnerable parameter ID with a SQL Injection attempt
Show Answer
Correct Answer: B
Explanation:
Typical Nmap http-xssed/http-dombased-xss or XSS scripts report the vulnerable parameter and indicate which characters are reflected without filtering. The wording about 'encoded characters passed > and " as unsafe' is overly specific and not what such scan output generally describes. There is no indication of SQL injection.

Question 108

Which of the following threat-hunting concepts is most concerned with identifying the behaviors of the bad actor?

A. Threat intelligence sharing
B. Indicators of compromise
C. Insider threat analysis
D. Tactics, techniques, and procedures
Show Answer
Correct Answer: D
Explanation:
Tactics, techniques, and procedures (TTPs) describe how threat actors operate—their behaviors, methods, and patterns of attack. Threat hunting focused on identifying adversary behavior relies heavily on TTPs rather than simple artifacts. Indicators of compromise (IOCs) are evidence of an intrusion, threat intelligence sharing is the exchange of threat information, and insider threat analysis focuses specifically on risks from trusted insiders.

Question 109

Which of the following is the best authentication method to secure access to sensitive data?

A. An assigned device that generates a randomized code for log-in
B. Biometrics and a device with a personalized code for log-in
C. Alphanumeric/special character username and passphrase for log-in
D. A one-time code received by email and push authorization for log-in
Show Answer
Correct Answer: B
Explanation:
The strongest option is multi-factor authentication combining two independent factors: something you are (biometrics) and something you have (a device that provides a personalized code). This provides stronger protection than a password alone, a hardware token alone, or email-based one-time codes, which are generally less secure.

Question 110

Which of the following best explains the importance of the implementation of a secure software development life cycle in a company with an internal development team?

A. Increases the product price by using the implementation as a piece of marketing
B. Decreases the risks of the software usage and complies with regulatory requirements
C. Improves the agile process and decreases the amount of tests before the final deployment
D. Transfers the responsibility for security flaws to the vulnerability management team
Show Answer
Correct Answer: B
Explanation:
A secure software development life cycle (SSDLC) integrates security throughout development to reduce vulnerabilities and overall software risk while helping organizations meet regulatory and compliance requirements. It does not primarily increase product price, reduce testing, or transfer responsibility for security flaws.

$19

Get all 534 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.