Comptia

CS0-003 Free Practice Questions — Page 13

Question 76

A security analyst receives an alert with the following packet capture attached: Which of the following has occurred?

A. sslscan reconnaissance
B. A password stuffing attack
C. An Nmap scan
D. An nc reverse shell
Show Answer
Correct Answer: C
Explanation:
The packet capture shows a completed TCP three-way handshake (SYN, SYN-ACK, ACK) to a service port followed immediately by a RST, with no application data exchanged. This pattern is characteristic of an Nmap TCP connect scan (-sT), which establishes a connection to confirm an open port and then resets it. The behavior does not match sslscan (which performs TLS handshakes), password stuffing (repeated authentication attempts), or a netcat reverse shell (persistent data exchange).

Question 77

An organization is preparing for a disaster recovery exercise. Which of the following actions should be implemented first?

A. Gather all internal stakeholders and review the actions according to the defined incident playbook.
B. Coordinate the supporting staff for the recovery process to ensure availability at the recovery site.
C. Ensure that the vendor for the disaster recovery site is scheduled to support the recovery.
D. Identify a business-critical system and test by failing over to the disaster recovery location.
Show Answer
Correct Answer: A
Explanation:
The first step in a disaster recovery exercise is to align all internal stakeholders on roles, communication paths, and procedures by reviewing the incident/disaster recovery playbook. This ensures the exercise is coordinated and controlled before engaging vendors, scheduling recovery sites, or performing technical failover testing, which come later in the exercise lifecycle.

Question 78

A security analyst is developing a script to filter firewall vulnerabilities. The script will impact the integrity of data hosted on devices connected to networks. Which of the following is a CVSS v4.0 that the analyst can use to test a true positive for the script?

A. AV:L/AC:H/AT:N/PR:L/VI:H/VC:H/VA:H/SC:N/SI:N/SA:N
B. AV:N/AC:L/AT:N/PR:N/VI:N/VC:N/VA:N/SC:N/SI:H/SA:L
C. AV:P/AC:L/AT:N/PR:H/VI:L/VC:L/VA:L/SC:N/SI:N/SA:N
D. AV:A/AC:L/AT:N/PR:H/VI:N/VC:L/VA:L/SC:N/SI:N/SA:H
Show Answer
Correct Answer: B
Explanation:
The question specifies that the script targets firewall vulnerabilities and will impact the integrity of data hosted on devices connected to networks. In CVSS v4.0, impacts to other network-connected devices are represented by the Subsequent System Impact metrics, not the Vulnerable System metrics. Option B is the only vector with a Network attack vector (AV:N), appropriate for firewall vulnerabilities, and with Subsequent System Integrity (SI:H), directly matching the requirement that data integrity on connected devices is impacted. The other options either lack network-based exploitation or only describe impacts limited to the vulnerable system itself.

Question 79

A security analyst provides the management team with an after action report for a security incident. Which of the following is the management team most likely to review in order to correct validated issues with the incident response processes?

A. Tabletop exercise
B. Lessons learned
C. Root cause analysis
D. Forensic analysis
Show Answer
Correct Answer: B
Explanation:
Management reviews the lessons learned section of an after-action report to identify validated gaps and improvements in the incident response process. Lessons learned directly inform process corrections, whereas root cause analysis focuses on why the incident occurred, forensic analysis focuses on technical evidence, and tabletop exercises are pre-incident activities.

Question 80

Which of the following risk management decisions should be considered after evaluating all other options?

A. Transfer
B. Acceptance
C. Mitigation
D. Avoidance
Show Answer
Correct Answer: B
Explanation:
In standard risk management, acceptance is chosen only after other responses—avoidance, mitigation, or transfer—are deemed impractical or too costly relative to the risk. Acceptance means consciously acknowledging and tolerating the residual risk.

Question 81

A user is suspected of violating policy by logging in to a Linux VM during non-business hours. Which of the following system files is the best way to track the user’s activities?

A. /var/log/secure
B. /etc/motd
C. /var/log/messages
D. /etc/passwd
Show Answer
Correct Answer: A
Explanation:
/var/log/secure records authentication and authorization events on many Linux distributions, including SSH logins, login attempts, and sudo usage. Reviewing this file allows administrators to see when a user logged in and what actions required authentication, making it the best source for investigating off-hours or unauthorized access.

Question 82

A junior security analyst opened ports on the company’s firewall, and the company experienced a data breach. Which of the following most likely caused the data breach?

A. Environmental hacktivist
B. Accidental insider threat
C. Nation-state
D. Organized crime group
Show Answer
Correct Answer: B
Explanation:
The breach was caused by the junior security analyst mistakenly opening firewall ports. This is an unintentional action by an internal employee, which fits the definition of an accidental insider threat. The other options describe external threat actors who might exploit a vulnerability, not the party that caused it.

Question 83

A security analyst needs to block vulnerable ports and disable legacy protocols. The analyst has ensured NetBIOS trio, Telnet, SMB, and TFTP are blocked and/or disabled. Which of the following additional protocols should the analyst block next?

A. LDAPS v3
B. SNMP v1
C. TLS 1.3
D. Kerberos v5
Show Answer
Correct Answer: B
Explanation:
SNMP v1 is a legacy, insecure protocol that lacks strong authentication and encryption, making it appropriate to block when hardening a network. The other options listed (LDAPS v3, TLS 1.3, and Kerberos v5) are modern, secure protocols that should generally remain enabled rather than disabled.

Question 84

A network security analyst for a large company noticed unusual network activity on a critical system. Which of the following tools should the analyst use to analyze network traffic to search for malicious activity?

A. WAF
B. Wireshark
C. EDR
D. Nmap
Show Answer
Correct Answer: B
Explanation:
Wireshark is a packet capture and analysis tool that allows detailed inspection of network traffic to identify suspicious or malicious activity. A WAF protects web applications, EDR focuses on endpoint behavior, and Nmap is used for network scanning and discovery rather than traffic analysis.

Question 85

HOTSPOT - A systems administrator is reviewing the output of a vulnerability scan. INSTRUCTIONS - Review the information in each tab. Based on the organization’s environment architecture and remediation standards, select the server to be patched within 14 days and select the appropriate technique and mitigation. If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

Illustration for CS0-003 question 85 Illustration for CS0-003 question 85 Illustration for CS0-003 question 85
Show Answer
Correct Answer: 192.168.60.5 Patch; upload signed certificate from trusted third-party provider
Explanation:
The CVSS 8.1 vulnerability requires remediation within 14 days only for the production environment. Among affected assets, 192.168.60.5 is the sole production server with this finding. The issue is an untrusted SSL/TLS X.509 certificate, which is resolved by installing a certificate signed by a trusted third-party CA.

$19

Get all 528 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.