Comptia

CS0-003 Free Practice Questions — Page 15

Question 96

A security analyst is improving an organization’s vulnerability management program. The analyst cross-checks the current reports with the system’s infrastructure teams, but the reports do not accurately reflect the current patching levels. Which of the following will most likely correct the report errors?

A. Updating the engine of the vulnerability scanning tool
B. Installing patches through a centralized system
C. Configuring vulnerability scans to be credentialed
D. Resetting the scanning tool’s plug-ins to default
Show Answer
Correct Answer: C
Explanation:
The reports are inaccurate because unauthenticated scans cannot reliably determine installed patches and OS-level details. Configuring credentialed scans allows the scanner to log into systems and directly verify patch levels, greatly improving accuracy. Updating engines or resetting plug-ins does not address visibility limitations, and centralized patching does not fix reporting errors.

Question 97

A security analyst is reviewing a recent vulnerability scan report for a new server infrastructure. The analyst would like to make the best use of time by resolving the most critical vulnerability first. The following information is provided: Which of the following should the analyst concentrate remediation efforts on first?

A. SVR01
B. SVR02
C. SVR03
D. SVR04
Show Answer
Correct Answer: B
Explanation:
Remediation should prioritize vulnerabilities that are both exploitable and have the highest severity. Although another server may have a higher raw score, non‑exploitable findings pose less immediate risk. SVR02 represents an exploitable vulnerability with a higher severity than the other exploitable options, making it the most critical to address first.

Question 98

Several incidents have occurred with a legacy web application that has had little development work completed. Which of the following is the most likely cause of the incidents?

A. Misconfigured web application firewall
B. Data integrity failure
C. Outdated libraries
D. Insufficient logging
Show Answer
Correct Answer: C
Explanation:
Legacy web applications with little recent development commonly depend on outdated frameworks and third‑party libraries. These components often contain known, unpatched vulnerabilities that attackers can exploit, making outdated libraries the most likely cause of repeated incidents compared to configuration or monitoring issues.

Question 99

Results of a SOC customer service evaluation indicate high levels of dissatisfaction with the inconsistent services provided after regular work hours. To address this, the SOC lead drafts a document establishing customer expectations regarding the SOC’s performance and quality of services. Which of the following documents most likely fits this description?

A. Risk management plan
B. Vendor agreement
C. Incident response plan
D. Service-level agreement
Show Answer
Correct Answer: D
Explanation:
A Service-level agreement (SLA) defines customer expectations for service performance, quality, availability, and support hours. It is the appropriate document to address inconsistent after-hours SOC services by clearly setting measurable service standards.

Question 100

A security analyst must assist the IT department with creating a phased plan for vulnerability patching that meets established SLAs. Which of the following vulnerability management elements will best assist with prioritizing a successful plan?

A. Affected hosts
B. Risk score
C. Mitigation strategy
D. Annual recurrence
Show Answer
Correct Answer: B
Explanation:
A risk score aggregates factors such as severity, exploitability, and potential business impact, allowing vulnerabilities to be ranked against SLAs and patched in phases. This directly supports prioritization, whereas affected hosts, mitigation strategy, and annual recurrence are secondary or contextual inputs rather than primary prioritization mechanisms.

Question 101

An organization’s threat intelligence team notes a recent trend in adversary privilege escalation procedures. Multiple threat groups have been observed utilizing native Windows tools to bypass system controls and execute commands with privileged credentials. Which of the following controls would be most effective to reduce the rate of success of such attempts?

A. Disable administrative accounts for any operations.
B. Implement MFA requirements for all internal resources.
C. Harden systems by disabling or removing unnecessary services.
D. Implement controls to block execution of untrusted applications.
Show Answer
Correct Answer: C
Explanation:
The scenario describes adversaries performing privilege escalation using native Windows tools (living-off-the-land techniques). Controls that rely on identifying untrusted or external applications are less effective because these binaries are already trusted by the operating system. Hardening systems by disabling or removing unnecessary services and built-in tools reduces the available attack surface and directly limits which native components attackers can abuse, making privilege escalation attempts less likely to succeed.

Question 102

An analyst produces a weekly endpoint status report for the management team. The report Includes specific details for each endpoint in relation to organizational baselines. Which of the following best describes the report type?

A. Forensics
B. Mitigation
C. Vulnerability
D. Compliance
Show Answer
Correct Answer: D
Explanation:
The report compares each endpoint’s status against defined organizational baselines. Reporting adherence to established standards or baselines is characteristic of a compliance report, not forensics (incident investigation), mitigation (remediation actions), or vulnerability reporting (identified weaknesses).

Question 103

A security analyst observes a high volume of SYN flags from an unexpected source toward a web application server within one hour. The traffic is not flagging for any exploit signatures. Which of the following scenarios best describes this activity?

A. A legitimate connection is continuously attempting to establish a connection with a downed web server.
B. A script kiddie is attempting to execute a DDoS through a ping flood attack.
C. An attacker is executing reconnaissance activities by mapping which ports are open and closed.
D. A web exploit attempt is likely occurring and the security analyst is not seeing it.
Show Answer
Correct Answer: C
Explanation:
A high volume of SYN packets without corresponding exploit signatures is characteristic of a SYN scan used for reconnaissance. Attackers send SYNs to identify which ports respond (open/closed/filtered) without completing full TCP handshakes. This aligns with port mapping activity rather than a ping flood, a hidden web exploit, or a legitimate client retrying a downed server.

Question 104

Based on an internal assessment, a vulnerability management team wants to proactively identify risks to the infrastructure prior to production deployments. Which of the following best supports this approach?

A. Threat modeling
B. Penetration testing
C. Bug bounty
D. SDLC training
Show Answer
Correct Answer: A
Explanation:
Threat modeling proactively identifies threats, attack vectors, and design weaknesses early—before production deployment—allowing teams to mitigate risks during design and development. Penetration testing and bug bounties are typically reactive and occur later, while SDLC training is supportive but does not directly identify specific infrastructure risks.

Question 105

A security analyst runs tcpdump on the 10.203.10.22 machine and observes thousands of packets as shown below: Which of the following activities explains the tcpdump output?

A. Incoming nmap -sA scan
B. hping3 --udp scan over the network
C. C2 communications leaving the network
D. Malware beaconing
Show Answer
Correct Answer: A
Explanation:
The tcpdump pattern described (large volumes of TCP packets with the ACK flag set, sent to many different destination ports without completing handshakes) is characteristic of an Nmap ACK scan (-sA). An ACK scan sends bare ACK packets to probe firewall rules and determine whether ports are filtered or unfiltered, rather than to establish connections. This behavior does not match UDP scanning, C2 traffic, or malware beaconing, which would show different protocols, payloads, or periodic communication patterns.

$19

Get all 528 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.