Comptia

CS0-003 Free Practice Questions — Page 16

Question 151

A security analyst must assist the IT department with creating a phased plan for vulnerability patching that meets established SLAs. Which of the following vulnerability management elements will best assist with prioritizing a successful plan?

A. Affected hosts
B. Risk score
C. Mitigation strategy
D. Annual recurrence
Show Answer
Correct Answer: B
Explanation:
Risk score is the primary element used to prioritize vulnerability remediation because it reflects the severity and likelihood/impact of exploitation, enabling phased patching that aligns with remediation SLAs. Affected hosts provide scope but not priority on their own, mitigation strategy is determined after prioritization, and annual recurrence is not a standard prioritization factor.

Question 152

An organization’s threat intelligence team notes a recent trend in adversary privilege escalation procedures. Multiple threat groups have been observed utilizing native Windows tools to bypass system controls and execute commands with privileged credentials. Which of the following controls would be most effective to reduce the rate of success of such attempts?

A. Disable administrative accounts for any operations.
B. Implement MFA requirements for all internal resources.
C. Harden systems by disabling or removing unnecessary services.
D. Implement controls to block execution of untrusted applications.
Show Answer
Correct Answer: C
Explanation:
The scenario describes attackers abusing native Windows tools (living-off-the-land techniques) for privilege escalation. Blocking untrusted applications (D) is less effective because native Windows binaries are already trusted. Hardening systems by disabling or removing unnecessary services and components reduces the available attack surface and limits abuse of built-in functionality. MFA (B) does not directly prevent local privilege escalation, and disabling administrative accounts entirely (A) is generally impractical and does not address the technique.

Question 153

An analyst produces a weekly endpoint status report for the management team. The report Includes specific details for each endpoint in relation to organizational baselines. Which of the following best describes the report type?

A. Forensics
B. Mitigation
C. Vulnerability
D. Compliance
Show Answer
Correct Answer: D
Explanation:
A compliance report compares systems or endpoints against established organizational baselines, policies, or regulatory requirements to determine adherence. A weekly endpoint status report detailing each endpoint's status relative to organizational baselines is therefore a compliance report. Forensics focuses on investigations after incidents, mitigation on reducing risk or remediating issues, and vulnerability reports identify security weaknesses rather than overall baseline adherence.

Question 154

A security analyst observes a high volume of SYN flags from an unexpected source toward a web application server within one hour. The traffic is not flagging for any exploit signatures. Which of the following scenarios best describes this activity?

A. A legitimate connection is continuously attempting to establish a connection with a downed web server.
B. A script kiddie is attempting to execute a DDoS through a ping flood attack.
C. An attacker is executing reconnaissance activities by mapping which ports are open and closed.
D. A web exploit attempt is likely occurring and the security analyst is not seeing it.
Show Answer
Correct Answer: C
Explanation:
A high volume of SYN packets without exploit signatures is most consistent with a TCP SYN scan, a reconnaissance technique used to identify open, closed, or filtered ports. A legitimate client repeatedly trying to connect to a down server would typically target a known service rather than broadly probing, a ping flood uses ICMP rather than TCP SYN flags, and the lack of exploit signatures points away from an active web exploit attempt.

Question 155

Based on an internal assessment, a vulnerability management team wants to proactively identify risks to the infrastructure prior to production deployments. Which of the following best supports this approach?

A. Threat modeling
B. Penetration testing
C. Bug bounty
D. SDLC training
Show Answer
Correct Answer: A
Explanation:
Threat modeling is the proactive practice of identifying potential threats, attack paths, and design risks during planning and development, enabling mitigation before production deployment. Penetration testing and bug bounties are typically performed against implemented systems, while SDLC training improves awareness but does not directly identify infrastructure risks prior to deployment.

Question 156

A security analyst runs tcpdump on the 10.203.10.22 machine and observes thousands of packets as shown below: Which of the following activities explains the tcpdump output?

A. Incoming nmap -sA scan
B. hping3 --udp scan over the network
C. C2 communications leaving the network
D. Malware beaconing
Show Answer
Correct Answer: A
Explanation:
The described tcpdump pattern is consistent with an Nmap ACK scan (-sA), which sends TCP packets with only the ACK flag set to many destination ports to determine whether ports are filtered by a firewall. It is not a UDP scan, and it does not match typical C2 or malware beaconing traffic, which would show repeated communications to specific endpoints rather than thousands of ACK probes across ports.

Question 157

A company was able to reduce triage time by focusing on historical trend analysis. The business partnered with the security team to achieve a 50% reduction in phishing attempts year over year. Which of the following action plans led to this reduced triage time?

A. Patching
B. Configuration management
C. Awareness, education, and training
D. Threat modeling
Show Answer
Correct Answer: C
Explanation:
Historical trend analysis can identify phishing patterns and common user behaviors, allowing the organization to target awareness, education, and training where it is most effective. Improving user recognition and reporting of phishing emails reduces successful phishing attempts and the volume of incidents requiring triage, leading to faster triage overall. Patching, configuration management, and threat modeling do not directly explain a year-over-year reduction in phishing attempts through a business-security partnership focused on user behavior.

Question 158

After an upgrade to a new EDR, a security analyst received reports that several endpoints were not communicating with the SaaS provider to receive critical threat signatures. To comply with the incident response playbook, the security analyst was required to validate connectivity to ensure communications. The security analyst ran a command that provided the following: ComputerName: comptia007 - RemotePort: 443 - InterfaceAlias: Ethernet 3 - TopTestSucceeded: False - Which of the following did the analyst use to ensure connectivity?

A. nmap
B. tnc
C. ping
D. tracert
Show Answer
Correct Answer: B
Explanation:
The output fields shown (ComputerName, RemotePort, InterfaceAlias, and the intended TcpTestSucceeded field, despite the apparent typo 'TopTestSucceeded') match the PowerShell Test-NetConnection cmdlet, commonly invoked via the alias 'tnc'. It is used to verify TCP connectivity to a remote host and port such as HTTPS on port 443.

Question 159

A Chief Information Security Officer (CISO) has decided the cost to protect an asset is greater than the cost of losing the asset. Which of the following risk management principles is the CISO following?

A. Accept
B. Avoid
C. Transfer
D. Mitigate
Show Answer
Correct Answer: A
Explanation:
The correct answer is Accept. Risk acceptance is chosen when the cost of implementing controls exceeds the expected loss or impact from the risk, so the organization consciously decides to tolerate the risk rather than spend more to protect the asset.

Question 160

Which of the following best describe the external requirements that are imposed for incident management communication? (Choose two).

A. Law enforcement involvement
B. Compliance with regulatory requirements
C. Transparency to stockholders
D. Defined SLAs regarding services
E. Industry advocacy group participation
F. Framework guidelines
Show Answer
Correct Answer: B, D
Explanation:
External requirements for incident management communication commonly include regulatory obligations (such as mandatory breach reporting) and contractual obligations defined in service level agreements (SLAs), which specify communication and notification expectations with customers. Law enforcement involvement is situational rather than a general communication requirement, while framework guidelines and industry groups are generally voluntary, and transparency to stockholders is not a universal incident communication requirement. Sources: https://www.hklaw.com/en/insights/publications/2023/07/sec-finalizes-cybersecurity-incident-and-governance-disclosure

$19

Get all 534 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.