Comptia

CS0-003 Free Practice Questions — Page 16

Question 106

A company was able to reduce triage time by focusing on historical trend analysis. The business partnered with the security team to achieve a 50% reduction in phishing attempts year over year. Which of the following action plans led to this reduced triage time?

A. Patching
B. Configuration management
C. Awareness, education, and training
D. Threat modeling
Show Answer
Correct Answer: C
Explanation:
Reducing triage time and phishing volume by 50% through historical trend analysis and collaboration with the security team points to improving the human layer of security. Awareness, education, and training programs use past phishing trends to tailor user training, resulting in fewer reported phishing attempts and faster triage. Patching, configuration management, and threat modeling do not directly reduce phishing reports through user behavior changes.

Question 107

After an upgrade to a new EDR, a security analyst received reports that several endpoints were not communicating with the SaaS provider to receive critical threat signatures. To comply with the incident response playbook, the security analyst was required to validate connectivity to ensure communications. The security analyst ran a command that provided the following: ComputerName: comptia007 - RemotePort: 443 - InterfaceAlias: Ethernet 3 - TopTestSucceeded: False - Which of the following did the analyst use to ensure connectivity?

A. nmap
B. tnc
C. ping
D. tracert
Show Answer
Correct Answer: B
Explanation:
The output fields shown (ComputerName, RemotePort: 443, InterfaceAlias, and TcpTestSucceeded/TopTestSucceeded) match the PowerShell Test-NetConnection (tnc) cmdlet. This command is commonly used to validate network connectivity and port reachability (such as HTTPS on port 443) to a remote service, which fits the requirement to ensure EDR SaaS communication.

Question 108

A Chief Information Security Officer (CISO) has decided the cost to protect an asset is greater than the cost of losing the asset. Which of the following risk management principles is the CISO following?

A. Accept
B. Avoid
C. Transfer
D. Mitigate
Show Answer
Correct Answer: A
Explanation:
Choosing not to implement controls because their cost exceeds the potential loss means the organization knowingly tolerates the risk. This is the definition of risk acceptance, rather than avoiding, transferring, or mitigating the risk.

Question 109

Which of the following best describe the external requirements that are imposed for incident management communication? (Choose two).

A. Law enforcement involvement
B. Compliance with regulatory requirements
C. Transparency to stockholders
D. Defined SLAs regarding services
E. Industry advocacy group participation
F. Framework guidelines
Show Answer
Correct Answer: A, B
Explanation:
External requirements are those imposed by parties outside the organization with legal or enforcement authority. Law enforcement involvement can mandate what information may or must be communicated during an incident, especially when criminal activity is involved. Compliance with regulatory requirements (e.g., GDPR, HIPAA, breach notification laws) explicitly dictates incident reporting and communication obligations. The other options are either internal/contractual (SLAs), voluntary or best‑practice (frameworks, advocacy groups), or governance expectations rather than imposed incident‑communication requirements.

Question 110

A systems administrator needs to gather security events with repeatable patterns from Linux log files. Which of the following would the administrator most likely use for this task?

A. A regular expression in Bash
B. Filters in the vi editor
C. Variables in a PowerShell script
D. A playbook in a SOAR tool
Show Answer
Correct Answer: A
Explanation:
Regular expressions are designed to match repeatable text patterns and are commonly used in Bash with tools like grep, awk, or sed to search and extract specific security events from Linux log files. The other options are either less suited to pattern matching in Linux logs or are unrelated to log parsing.

Question 111

A security analyst is conducting a vulnerability assessment of a company’s online store. The analyst discovers a critical vulnerability in the payment processing system that could be exploited, allowing attackers to steal customer payment information. Which of the following should the analyst do next?

A. Leave the vulnerability unpatched until the next scheduled maintenance window to avoid potential disruption to business.
B. Perform a risk assessment to evaluate the potential impact of the vulnerability and determine whether additional security measures are needed.
C. Ignore the vulnerability since the company recently passed a payment system compliance audit.
D. Patch the vulnerability as soon as possible to ensure customer payment information is secure.
Show Answer
Correct Answer: D
Explanation:
The vulnerability is described as critical and directly enables theft of customer payment data. Once identified, the appropriate next step is immediate remediation to reduce risk, which means patching or otherwise fixing the vulnerability as soon as possible. Performing further risk assessment would unnecessarily delay mitigation, and compliance audits or maintenance windows do not justify leaving a known critical flaw unaddressed.

Question 112

Numerous emails were sent to a company’s customer distribution list. The customers reported that the emails contained a suspicious link. The company’s SOC determined the links were malicious. Which of the following is the best way to decrease these emails?

A. DMARC
B. DKIM
C. SPF
D. SMTP
Show Answer
Correct Answer: A
Explanation:
DMARC is the best control to decrease malicious emails sent to customers because it enforces domain-level email authentication and policy. DMARC builds on SPF and DKIM and allows the domain owner to specify how receiving mail servers should handle messages that fail authentication (e.g., reject or quarantine). This directly reduces spoofed or fraudulent emails using the company’s domain, whereas SPF and DKIM alone do not provide enforcement, and SMTP is merely a mail transport protocol.

Question 113

Which of the following choices is most likely to cause obstacles in vulnerability remediation?

A. Not meeting an SLA
B. Patch prioritization
C. Organizational governance
D. Proprietary systems
Show Answer
Correct Answer: D
Explanation:
Proprietary systems often lack vendor support, standardized patching mechanisms, or timely updates, which directly hinders the ability to remediate vulnerabilities. In contrast, not meeting an SLA is an outcome rather than a root obstacle, patch prioritization is a normal part of remediation workflows, and organizational governance can either hinder or help depending on maturity. Proprietary systems are most consistently an obstacle.

Question 114

A cybersecurity analyst is recommending a solution to ensure emails that contain links or attachments are tested before they reach a mail server. Which of the following will the analyst most likely recommend?

A. Sandboxing
B. MFA
C. DKIM
D. Vulnerability scan
Show Answer
Correct Answer: A
Explanation:
Sandboxing executes email attachments or follows embedded links in an isolated environment before delivery, allowing detection of malicious behavior without risking the mail server or users. MFA, DKIM, and vulnerability scans do not test email content prior to delivery.

Question 115

During a training exercise, a security analyst must determine the vulnerabilities to prioritize. The analyst reviews the following vulnerability scan output: Which of the following issues should the analyst address first?

A. Allows anonymous read access to /etc/passwd
B. Allows anonymous read access via any FTP connection
C. Microsoft Defender security definition updates disabled
D. less command allows for escape exploit via terminal
Show Answer
Correct Answer: A
Explanation:
Anonymous read access to /etc/passwd on a critical system (e.g., a VPN or corporate server) represents the highest priority risk. While modern Linux stores password hashes in /etc/shadow, /etc/passwd still exposes valid usernames, account structure, and system information that can be leveraged for reconnaissance, password spraying, phishing, and chained attacks. Given the asset’s sensitivity and exposure, this issue outweighs anonymous FTP on a less critical host, disabled Defender updates, or a local terminal escape requiring prior access.

$19

Get all 528 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.