Comptia

CS0-003 Free Practice Questions — Page 20

Question 191

An incident responder was able to recover a binary file through the network traffic. The binary file was also found in some machines with anomalous behavior. Which of the following processes most likely can be performed to understand the purpose of the binary file?

A. File debugging
B. Traffic analysis
C. Reverse engineering
D. Machine isolation
Show Answer
Correct Answer: C
Explanation:
Reverse engineering is the appropriate process for determining the purpose and behavior of a recovered binary. It includes static and dynamic analysis, disassembly, and decompilation to understand functionality or malicious capabilities. Traffic analysis examines network communications rather than the binary itself, machine isolation is a containment action, and debugging is primarily for diagnosing software execution issues rather than analyzing an unknown binary's purpose.

Question 192

A SOC analyst wants to improve the proactive detection of malicious emails before they are delivered to the destination inbox. Which of the following is the best approach the SOC analyst can recommend?

A. Install UEBA software on the network.
B. Validate and quarantine emails with invalid DKIM and SPF headers.
C. Implement an EDR system on each endpoint.
D. Deploy a DLP platform to block unauthorized and suspicious content.
Show Answer
Correct Answer: B
Explanation:
Validating sender authentication using SPF and DKIM and quarantining messages that fail these checks helps detect and stop spoofed or malicious emails before they reach users' inboxes. UEBA and EDR focus on user/endpoint behavior after delivery, while DLP is intended to prevent unauthorized data exfiltration rather than identify inbound malicious email.

Question 193

Which of the following documents sets requirements and metrics for a third-party response during an event?

A. BIA
B. DRP
C. SLA
D. MOU
Show Answer
Correct Answer: C
Explanation:
A Service Level Agreement (SLA) defines the expected service performance, response times, availability, and measurable metrics that a third-party provider must meet, including during incident or event response. A BIA identifies business impacts, a DRP outlines disaster recovery procedures, and an MOU expresses a general understanding between parties but typically does not establish enforceable service metrics.

Question 194

During a tabletop exercise, engineers discovered that an ICS could not be updated due to hardware versioning incompatibility. Which of the following is the most likely cause of this issue?

A. Legacy system
B. Business process interruption
C. Degrading functionality
D. Configuration management
Show Answer
Correct Answer: A
Explanation:
An ICS that cannot be updated because of hardware versioning incompatibility is most characteristic of a legacy system. Older industrial control hardware often lacks compatibility with newer firmware or software updates, making patching impossible without replacing the hardware. The other options describe operational impacts or administrative processes rather than the underlying cause.

Question 195

Which of the following most accurately describes the Cyber Kill Chain methodology?

A. It is used to correlate events to ascertain the TTPs of an attacker.
B. It is used to ascertain lateral movements of an attacker, enabling the process to be stopped.
C. It provides a clear model of how an attacker generally operates during an intrusion and the actions to take at each stage.
D. It outlines a clear path for determining the relationships between the attacker, the technology used, and the target.
Show Answer
Correct Answer: C
Explanation:
The Cyber Kill Chain, developed by Lockheed Martin, models the typical stages of a cyber intrusion (such as reconnaissance, weaponization, delivery, exploitation, installation, command and control, and actions on objectives) and helps defenders identify opportunities to detect and disrupt attacks at each stage. Option A better aligns with MITRE ATT&CK usage, B focuses narrowly on lateral movement, and D describes the Diamond Model of Intrusion Analysis.

Question 196

Following an attack, an analyst needs to provide a summary of the event to the Chief Information Security Officer. The summary needs to include the who-what-when information and evaluate the effectiveness of the plans in place. Which of the following incident management life cycle processes does this describe?

A. Business continuity plan
B. Lessons learned
C. Forensic analysis
D. Incident response plan
Show Answer
Correct Answer: B
Explanation:
The described activity matches the post-incident 'lessons learned' phase of the incident management lifecycle. In this phase, the team prepares a summary of the incident (who, what, when), reports to leadership, reviews the response, and evaluates the effectiveness of incident response plans and related procedures to identify improvements.

Question 197

A new SOC manager reviewed findings regarding the strengths and weaknesses of the last tabletop exercise in order to make improvements. Which of the following should the SOC manager utilize to improve the process?

A. The most recent audit report
B. The incident response playbook
C. The incident response plan
D. The lessons-learned register
Show Answer
Correct Answer: D
Explanation:
A lessons-learned register captures findings, strengths, weaknesses, and improvement actions from tabletop exercises and real incidents. Reviewing and using it is the appropriate way to improve the incident response process. An audit report assesses compliance, the incident response plan defines the overall approach, and the playbook contains operational procedures, but the lessons-learned register is specifically intended to drive process improvements after exercises.

Question 198

A security analyst needs to identify services in a small, critical infrastructure ICS network. Many components in the network are likely to break if they receive malformed or unusually large requests. Which of the following is the safest method to use when identifying service versions?

A. Use nmap -sV to identify all assets on the network.
B. Use Burp Suite to conduct service identification.
C. Use nc to manually perform banner grabbing.
D. Use Nessus with restricted concurrent connections.
Show Answer
Correct Answer: C
Explanation:
In a fragile ICS environment, the safest approach is the least intrusive one. Manual banner grabbing with netcat (nc) allows the analyst to send minimal, controlled requests to elicit service banners without the broad or potentially disruptive probes used by automated scanners. Nmap service detection (-sV) and Nessus both perform active probing that can trigger issues on sensitive ICS devices, even if scan rates are throttled. Burp Suite is intended for web application testing rather than general network service identification.

Question 199

A user’s computer is performing slower than the day before, and unexpected windows continually open and close. The user did not install any new programs, and after the user restarted the desktop, the issue was not resolved. Which of the following incident response actions should be taken next?

A. Restart in safe mode and start a virus scan.
B. Disconnect from the network and leave the PC turned on.
C. Contain the device and implement a legal hold.
D. Reformat and reimage the OS.
Show Answer
Correct Answer: B
Explanation:
The next incident response action is containment: disconnect the suspected compromised system from the network to prevent malware spread or data exfiltration while leaving it powered on to preserve volatile evidence for potential forensic analysis. Restarting into safe mode or scanning could alter evidence, a legal hold is not indicated based on the scenario, and reimaging is a later recovery step after investigation and containment.

Question 200

Which of following attack methodology frameworks should a cybersecurity analyst use to identify similar TTPs utilized by nation-state actors?

A. Cyber kill chains
B. Diamond Model of Intrusion Analysis
C. OWASP Testing Guide
D. MITRE ATT&CK matrix
Show Answer
Correct Answer: D
Explanation:
MITRE ATT&CK is a knowledge base organized around adversary Tactics, Techniques, and Procedures (TTPs) and is specifically used to analyze and compare behaviors used by threat actors, including nation-state groups. The Cyber Kill Chain describes attack phases, the Diamond Model focuses on intrusion event relationships, and the OWASP Testing Guide is for web application security testing.

$19

Get all 534 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.