Comptia

CS0-003 Free Practice Questions — Page 17

Question 161

A systems administrator needs to gather security events with repeatable patterns from Linux log files. Which of the following would the administrator most likely use for this task?

A. A regular expression in Bash
B. Filters in the vi editor
C. Variables in a PowerShell script
D. A playbook in a SOAR tool
Show Answer
Correct Answer: A
Explanation:
Regular expressions used with Bash tools such as grep, sed, or awk are the standard way to search Linux log files for repeatable text patterns, making them well suited for identifying recurring security events. vi filters are for interactive editing, PowerShell variables are unrelated to Linux log pattern matching, and SOAR playbooks orchestrate automated response workflows rather than performing basic pattern matching in log files.

Question 162

A security analyst is conducting a vulnerability assessment of a company’s online store. The analyst discovers a critical vulnerability in the payment processing system that could be exploited, allowing attackers to steal customer payment information. Which of the following should the analyst do next?

A. Leave the vulnerability unpatched until the next scheduled maintenance window to avoid potential disruption to business.
B. Perform a risk assessment to evaluate the potential impact of the vulnerability and determine whether additional security measures are needed.
C. Ignore the vulnerability since the company recently passed a payment system compliance audit.
D. Patch the vulnerability as soon as possible to ensure customer payment information is secure.
Show Answer
Correct Answer: B
Explanation:
The analyst's role during a vulnerability assessment is to identify and assess vulnerabilities, communicate risk, and recommend remediation. The next step after discovering a critical vulnerability is to perform a risk assessment to evaluate business impact, prioritize remediation, and determine any compensating controls. Implementing patches is typically handled through the organization's change management and operations processes, not unilaterally by the analyst. Delaying until a maintenance window (A) or ignoring the issue due to compliance (C) are inappropriate.

Question 163

Numerous emails were sent to a company’s customer distribution list. The customers reported that the emails contained a suspicious link. The company’s SOC determined the links were malicious. Which of the following is the best way to decrease these emails?

A. DMARC
B. DKIM
C. SPF
D. SMTP
Show Answer
Correct Answer: A
Explanation:
DMARC is the best choice because it builds on SPF and DKIM to authenticate email and, importantly, enforces a policy (reject/quarantine) for messages that fail authentication, significantly reducing successful spoofed emails sent using the company's domain. SPF and DKIM alone provide authentication mechanisms but do not specify enforcement. SMTP is simply the mail transfer protocol and does not prevent spoofing.

Question 164

Which of the following choices is most likely to cause obstacles in vulnerability remediation?

A. Not meeting an SLA
B. Patch prioritization
C. Organizational governance
D. Proprietary systems
Show Answer
Correct Answer: D
Explanation:
Proprietary systems commonly impede vulnerability remediation because patches may only be available from the vendor, support may be limited, updates may lag, or modifications may be restricted. The other options are related to remediation management or outcomes rather than being inherent obstacles to performing remediation.

Question 165

A cybersecurity analyst is recommending a solution to ensure emails that contain links or attachments are tested before they reach a mail server. Which of the following will the analyst most likely recommend?

A. Sandboxing
B. MFA
C. DKIM
D. Vulnerability scan
Show Answer
Correct Answer: A
Explanation:
Sandboxing executes email attachments and follows links in an isolated environment to detect malicious behavior before delivery. MFA is for authentication, DKIM validates email authenticity, and vulnerability scanning assesses systems rather than testing inbound email content.

Question 166

During a training exercise, a security analyst must determine the vulnerabilities to prioritize. The analyst reviews the following vulnerability scan output: Which of the following issues should the analyst address first?

A. Allows anonymous read access to /etc/passwd
B. Allows anonymous read access via any FTP connection
C. Microsoft Defender security definition updates disabled
D. less command allows for escape exploit via terminal
Show Answer
Correct Answer: A
Explanation:
Prioritize the vulnerability with the greatest organizational risk by considering both severity and asset criticality. Anonymous read access to /etc/passwd on a critical Linux system such as a VPN server enables attacker reconnaissance (user enumeration) that can facilitate password spraying and follow-on attacks against a high-value asset. Anonymous FTP access on a less critical, segmented guest-network host is a concern but is generally lower priority in this context. Disabled Defender updates and a local less escape are also lower priority than exposure of a critical authentication-facing server.

Question 167

Which of the following is a circumstance in which a security operations manager would most likely consider using automation?

A. The generation of NIDS rules based on received STIX messages
B. The fulfillment of privileged access requests to enterprise domain controllers.
C. The verification of employee identities prior to initial PKI enrollment
D. The analysis of suspected malware binaries captured by an email gateway
Show Answer
Correct Answer: A
Explanation:
Automation is most appropriate for repetitive, structured tasks that can be driven by machine-readable threat intelligence. STIX provides standardized indicators of compromise that can be translated into NIDS signatures or rules. The other options involve high-risk privileged access decisions, identity proofing, or malware analysis, which typically require significant human oversight or expertise.

Question 168

A threat intelligence analyst is updating a document according to the MITRE ATT&CK framework. The analyst detects the following behavior from a malicious actor: “The malicious actor will attempt to achieve unauthorized access to the vulnerable system.” In which of the following phases should the analyst include the detection?

A. Procedures
B. Techniques
C. Tactics
D. Subtechniques
Show Answer
Correct Answer: C
Explanation:
The described behavior expresses the adversary's objective—achieving unauthorized access—rather than the specific method used. In the MITRE ATT&CK framework, tactics represent the adversary's tactical goals (such as Initial Access), while techniques and sub-techniques describe how those goals are accomplished, and procedures are implementation details used by a specific threat actor.

Question 169

Which of the following is the best framework for assessing how attackers use techniques over an infrastructure to exploit a target’s information assets?

A. Structured Threat Information Expression
B. OWASP Testing Guide
C. Open Source Security Testing Methodology Manual
D. Diamond Model of Intrusion Analysis
Show Answer
Correct Answer: D
Explanation:
The Diamond Model of Intrusion Analysis is specifically designed to analyze intrusions by modeling the relationships among the adversary, infrastructure, capability, and victim (target), making it well suited for assessing how attackers use techniques over infrastructure to exploit information assets. STIX is a threat intelligence representation format, while the OWASP Testing Guide and OSSTMM are security testing methodologies rather than intrusion analysis frameworks.

Question 170

A company classifies security groups by risk level. Any group with a high-risk classification requires multiple levels of approval for member or owner changes. Which of the following inhibitors to remediation is the company utilizing?

A. Organizational governance
B. MOU
C. SLA
D. Business process interruption
Show Answer
Correct Answer: A
Explanation:
Requiring multiple levels of approval for changes to high-risk security groups is an example of organizational governance. Governance policies and approval workflows are designed to reduce risk but can slow or inhibit remediation efforts by adding administrative controls. An MOU defines inter-organizational understanding, an SLA defines service expectations, and business process interruption refers to operational disruption rather than approval requirements.

$19

Get all 534 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.