Comptia

CS0-003 Free Practice Questions — Page 14

Question 86

A security manager is looking at a third-party vulnerability metric (SMITTEN) to improve upon the company’s current method that relies on CVSSv3. Given the following: Which of the following vulnerabilities should be prioritized?

A. Vulnerability 1
B. Vulnerability 2
C. Vulnerability 3
D. Vulnerability 4
Show Answer
Correct Answer: B
Explanation:
SMITTEN-style prioritization emphasizes real-world exploitation, exposure, and threat activity over theoretical severity alone. Vulnerability 2 is actively exploited and on an external-facing system, which makes it a higher immediate risk than vulnerabilities with higher base severity but no active exploitation. Therefore, it should be prioritized first.

Question 87

A security analyst needs to support an organization’s legal case against a threat actor. Which of the following processes provides the best way to assist in the prosecution of the case?

A. Chain of custody
B. Evidence gathering
C. Securing the scene
D. Forensic analysis
Show Answer
Correct Answer: A
Explanation:
To support a legal case, the most critical process is maintaining a proper chain of custody. Chain of custody documents how evidence is collected, handled, transferred, stored, and analyzed, ensuring its integrity and authenticity. Without a documented chain of custody, evidence—regardless of how well it was gathered or analyzed—can be challenged or deemed inadmissible in court. While evidence gathering, securing the scene, and forensic analysis are all important investigative steps, chain of custody is what directly enables successful prosecution.

Question 88

A user clicks on a malicious adware link, and the malware successfully downloads to the machine. The malware has a script that invokes command-and-control activity. Which of the following actions is the best way to contain the incident without any additional impact?

A. Disable the user account until the malware investigation is complete.
B. Review EDR information to determine whether the file was detected and quarantined locally.
C. Block the server on the proxy and firewall.
D. Submit a recategorization update to the vendor.
Show Answer
Correct Answer: C
Explanation:
Blocking the command-and-control server at the proxy and firewall immediately contains the incident by stopping outbound communication from the infected host, preventing further attacker control or data exfiltration, while minimizing impact on the user or environment. Other options are either investigative, delayed, or unnecessarily disruptive.

Question 89

Which of the following should be performed first when creating a BCP to ensure that all critical functions and financial implications have been considered?

A. Failover test
B. Tabletop exercise
C. Security policies
D. Business impact analysis
Show Answer
Correct Answer: D
Explanation:
A Business Impact Analysis (BIA) is performed first when creating a BCP because it identifies critical business functions, dependencies, acceptable downtime, and financial/operational impacts of disruptions. This information is required before selecting controls, testing methods, or recovery strategies.

Question 90

Which of the following responsibilities does the legal team have during an incident management event? (Choose two).

A. Coordinate additional or temporary staffing for recovery efforts.
B. Review and approve new contracts acquired as a result of an event.
C. Advise the incident response team on matters related to regulatory reporting.
D. Ensure all system security devices and procedures are in place.
E. Conduct computer and network damage assessments for insurance.
F. Verify that all security personnel have the appropriate clearances.
Show Answer
Correct Answer: B, C
Explanation:
During an incident management event, the legal team’s core responsibilities relate to legal, contractual, and regulatory obligations. Advising the incident response team on regulatory reporting requirements is a primary legal function, as failures can lead to fines or liability. Reviewing and approving new or modified contracts that arise due to the incident (such as emergency vendors or services) also falls under legal oversight. The other options are operational, technical, security, or HR responsibilities rather than legal.

Question 91

In the last hour, a high volume of failed RDP authentication attempts has been logged on a critical server. All of the authentication attempts originated from the same remote IP address and made use of a single valid domain user account. Which of the following mitigating controls would be most effective to reduce the rate of success of this brute-force attack? (Choose two.)

A. Increase the granularity of log-on event auditing on all devices.
B. Enable host firewall rules to block all outbound traffic to TCP port 3389.
C. Configure user account lockout after a limited number of failed attempts.
D. Implement a firewall block for the IP address of the remote system.
E. Install a third-party remote access tool and disable RDP on all devices.
F. Block inbound to TCP port 3389 from untrusted remote IP addresses at the perimeter firewall.
Show Answer
Correct Answer: C, F
Explanation:
Account lockout policies directly limit the number of password guesses, sharply reducing the likelihood of a successful brute-force attack. Restricting inbound RDP (TCP 3389) at the perimeter to only trusted IP addresses reduces the attack surface and prevents unauthorized sources from attempting authentication. Other options focus on monitoring, are misapplied (outbound blocking), or are less effective or impractical as mitigations.

Question 92

An analyst is reviewing a dashboard from the company’s SIEM and finds that an IP address known to be malicious can be tracked to numerous high-priority events in the last two hours. The dashboard indicates that these events relate to TTPs. Which of the following is the analyst most likely using?

A. MITRE ATT&CK
B. OSSTMM
C. Diamond Model of Intrusion Analysis
D. OWASP
Show Answer
Correct Answer: A
Explanation:
The dashboard correlates events to adversary tactics, techniques, and procedures (TTPs). The MITRE ATT&CK framework is specifically designed to map and analyze observed activity using TTPs, making it the most likely reference used by the SIEM. The other options are testing or modeling frameworks not centered on TTP-based event mapping.

Question 93

A company has recently experienced a security breach via a public-facing service. Analysis of the event on the server was traced back to the following piece of code: SELECT * From user_data WHERE Username = 0 and userid= 1 or 1=1;-- Which of the following controls would be best to implement?

A. Deploy a wireless application protocol.
B. Remove the end-of-life component.
C. Implement proper access control.
D. Validate user input.
Show Answer
Correct Answer: D
Explanation:
The query shows a classic SQL injection attack using `OR 1=1;--` to bypass authentication logic. The most effective control to prevent this is validating and sanitizing user input (ideally with parameterized queries), which blocks malicious input from being interpreted as SQL. Other options do not directly address SQL injection.

Question 94

An organization wants to establish a disaster recovery plan for critical applications that are hosted on premises. Which of the following is the first step to prepare for supporting this new requirement?

A. Choose a vendor to utilize for the disaster recovery location.
B. Establish prioritization of continuity from data and business owners.
C. Negotiate vendor agreements to support disaster recovery capabilities.
D. Advise the leadership team that a geographical area for recovery must be defined.
Show Answer
Correct Answer: B
Explanation:
The first step in creating a disaster recovery plan is to identify and prioritize what must be recovered. Establishing prioritization with data and business owners determines which applications and data are critical, along with their recovery objectives. Only after this analysis can decisions about vendors, locations, and contracts be made.

Question 95

A security analyst working for an airline is prioritizing vulnerabilities found on a system. The system has the following requirements: • Can store periodically audited documents required for takeoffs and landings • Can keep critical records regarding the company’s operations • Data can be made public upon request and authorization Which of the following vulnerabilities should be remediated first?

A. A broken access control vulnerability impacting data integrity
B. A heap overflow vulnerability impacting the system’s usability
C. A DoS vulnerability impacting the system’s availability
D. A zero-day vulnerability impacting the system’s confidentiality
Show Answer
Correct Answer: A
Explanation:
The system stores audited, safety-critical operational documents. For such systems, data integrity is paramount: unauthorized modification could directly affect takeoff and landing operations. Broken access control that impacts integrity poses the highest risk compared to availability, usability, or confidentiality issues, especially since data may be made public with authorization.

$19

Get all 528 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.