Comptia

CS0-003 Free Practice Questions — Page 2

Question 6

When undertaking a cloud migration of multiple SaaS applications, an organization's systems administrators struggled with the complexity of extending identity and access management to cloud-based assets. Which of the following service models would have reduced the complexity of this project?

A. RADIUS
B. SDN
C. ZTNA
D. SWG
Show Answer
Correct Answer: C
Explanation:
ZTNA (Zero Trust Network Access) is an identity-centric access model designed for cloud and SaaS environments. It integrates with IAM/SSO/MFA to grant application-level access based on user identity and context, avoiding complex network extensions or VPNs. This significantly reduces the complexity of extending identity and access management to cloud-based assets compared to the other options.

Question 6

A systems administrator is concerned after reviewing the results of a vulnerability scan: Which of the following mitigation strategies best addresses the risk?

A. Create an exception.
B. Wait for a patch release.
C. Apply compensating controls.
D. Disable the affected application.
Show Answer
Correct Answer: C
Explanation:
The vulnerability described (e.g., a protocol-level issue like SSH Terrapin) may not have an immediate or unilateral patch available and cannot be fully mitigated by simple updates. Creating an exception accepts risk, waiting for a patch leaves the system exposed, and disabling the application may be impractical. Applying compensating controls (such as configuration hardening, restricting access, monitoring, or disabling vulnerable features) best reduces risk until a full fix is available.

Question 7

An organization's Chief Information Security Officer (CISO) is organizing a tabletop drill. The CISO has included several other executives in the meeting invitation for the drill, as required. Which of the following is the best reason for including the Chief Communications Officer?

A. Deciding when and how to issue press releases regarding incidents can minimize damage to the organization's brand reputation.
B. All of the organization's high-level executives should know about the IT department's incident response plan.
C. All parties must be able to communicate clearly. concisely, and consistently during incident response.
D. The CISO would like to increase the security department's visibility to senior executives.
Show Answer
Correct Answer: A
Explanation:
The Chief Communications Officer is responsible for external and internal messaging, especially during crises. In an incident response tabletop drill, their key role is to plan when and how to communicate with the public, customers, regulators, and the media. Effective, well-timed press releases and messaging can significantly reduce reputational harm and prevent misinformation, making this the best reason for their inclusion.

Question 7

Which of the following is the term for a predefined set of automated actions that incident responders and SOC analysts can use to enhance operations?

A. Threat modeling
B. Detection set
C. CVSS
D. Playbooks
Show Answer
Correct Answer: D
Explanation:
The term for a predefined set of automated or documented actions used by incident responders and SOC analysts to standardize and enhance operations is a playbook. Playbooks provide step-by-step procedures for detecting, responding to, and remediating specific types of incidents.

Question 8

An analyst reviews the following web server log entries: %2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/etc/passwd No attacks or malicious attempts have been discovered. Which of the following most likely describes what took place?

A. A SQL injection query took place to gather information from a sensitive file.
B. A PHP injection was leveraged to ensure that the sensitive file could be accessed.
C. Base64 was used to prevent the IPS from detecting the fully encoded string.
D. Directory traversal was performed to obtain a sensitive file for further reconnaissance.
Show Answer
Correct Answer: D
Explanation:
The encoded sequence %2E%2E translates to "..", and repeated "../" patterns indicate directory traversal. The target "/etc/passwd" is a sensitive file on Unix-like systems, commonly probed via traversal for reconnaissance. This is not SQL/PHP injection, and it is URL encoding, not Base64.

Question 8

Which of the following best explains the importance of security orchestration, automation, and response for security operation activities?

A. Implementing infrastructure as code in the organization
B. Supporting the team's management of remediation tasks
C. Deploying general scripts for automating security engineering operations
D. Collecting threat intelligence feeds for improved threat response
Show Answer
Correct Answer: B
Explanation:
SOAR’s core importance in security operations is orchestrating tools and automating workflows to streamline incident response and remediation. It helps teams manage and execute remediation tasks efficiently by coordinating actions across systems, reducing manual effort and response time.

Question 9

A SOC manager who recently switched companies notices that their new company's SOC analysts have significantly poorer operational metrics compared to their previous company, without any major difference in alert volume or team size. Which of the following are most likely to be the cause? (Choose two.)

A. Use of OSSTMM
B. Integration of webhooks
C. Lack of SOAR implementation
D. Absence of single pane of glass
E. Morale issues among SOC staff
F. Usage of API gateways
Show Answer
Correct Answer: C, D
Explanation:
Given similar alert volume and team size, a significant drop in SOC operational metrics is most plausibly explained by inefficiencies in tooling and workflows rather than personnel factors. A lack of SOAR implementation removes automation for triage and response, increasing manual workload and slowing MTTR. Likewise, the absence of a single pane of glass forces analysts to pivot between multiple tools for context, increasing investigation time and degrading metrics. There is no evidence in the scenario to support morale or cultural issues.

Question 9

An analyst uses an AI platform to help correlate events. The AI output contains events that did not happen. This results in inaccurate correlations. Which of the following best describes what has occurred?

A. Hallucinations
B. Data exposure
C. Malicious prompts
D. Model poisoning
Show Answer
Correct Answer: A
Explanation:
The AI generated events that never occurred, leading to false correlations. This behavior is characteristic of hallucinations, where a model produces plausible-sounding but factually incorrect or ungrounded information. The other options involve data leakage, adversarial input, or corrupted training, none of which are described.

Question 10

A company received a shipment of new network switches. Immediately after installing the switches, a security analyst notices suspicious traffic coming from one of the new switches. Which of the following best describes the threat actor?

A. Insider threat
B. Supply chain
C. Nation-state
D. Organized crime
Show Answer
Correct Answer: B
Explanation:
The suspicious traffic appears immediately after installing newly received hardware, indicating the compromise was introduced before deployment. This aligns with a supply chain threat, where malicious components or firmware are implanted during manufacturing or distribution rather than by an internal user, nation-state activity specifically, or organized crime after installation.

Question 10

An analyst reviews code for a sensitive application for their company and uploads it to an AI platform. This application is critical to the company's business operations. Which of the following risks is most important for the analyst to consider?

A. Hallucinations
B. Malicious prompts
C. Data exposure
D. Model poisoning
Show Answer
Correct Answer: C
Explanation:
Uploading sensitive, business‑critical source code to an AI platform creates a significant risk that proprietary data or intellectual property could be exposed, retained, or used beyond the company’s control. Compared to hallucinations, malicious prompts, or model poisoning, the immediate and most impactful concern in this scenario is unauthorized disclosure or misuse of confidential code.

$19

Get all 528 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.