Comptia

CS0-003 Free Practice Questions — Page 22

Question 211

A security audit for unsecured network services was conducted, and the following output was generated: Which of the following services should the security team investigate further? (Choose two.)

A. 21
B. 22
C. 23
D. 636
E. 1723
F. 3389
Show Answer
Correct Answer: C, E
Explanation:
Port 23 is Telnet, which transmits credentials and data in plaintext and is considered an unsecured network service. Port 1723 is PPTP, an outdated VPN protocol with known cryptographic weaknesses (including reliance on MS-CHAPv2), and should also be investigated. The other listed ports correspond to services that can be secure when properly configured (FTP on 21 is insecure unless FTPS is used, but the classic audit focus here is Telnet and PPTP; SSH 22, LDAPS 636, and RDP 3389 are encrypted protocols).

Question 212

An organization identifies a method to detect unexpected behavior, crashes, or resource leaks in a system by feeding invalid, unexpected, or random data to stress the application. Which of the following best describes this testing methodology?

A. Reverse engineering
B. Static
C. Fuzzing
D. Debugging
Show Answer
Correct Answer: C
Explanation:
Fuzzing is a dynamic testing methodology that feeds invalid, unexpected, malformed, or random inputs into an application to uncover crashes, unexpected behavior, memory/resource leaks, and security vulnerabilities. Reverse engineering analyzes existing software, static testing examines code without execution, and debugging is the process of finding and fixing identified defects.

Question 213

An analyst is trying to capture anomalous traffic from a compromised host. Which of the following are the best tools for achieving this objective? (Choose two.)

A. tcpdump
B. SIEM
C. Vulnerability scanner
D. Wireshark
E. Nmap
F. SOAR
Show Answer
Correct Answer: A, D
Explanation:
tcpdump and Wireshark are packet capture and network traffic analysis tools used to capture and inspect anomalous traffic from a compromised host. A SIEM aggregates and analyzes logs, a vulnerability scanner identifies weaknesses, Nmap performs network discovery, and SOAR automates security workflows rather than capturing packets.

Question 214

The SOC receives a number of complaints regarding a recent uptick in desktop error messages that are associated with workstation access to an internal web application. An analyst, identifying a recently modified XML file on the web server, retrieves a copy of this file for review, which contains the following code: Which of the following XML schema constraints would stop these desktop error messages from appearing?

A.
B.
C.
D.
Show Answer
Correct Answer: B
Explanation:
The prompt appears to be missing the XML snippet and the answer option contents, so a definitive determination is not possible. Based on the available context, the most likely intended answer is B, which is described as applying a restrictive pattern constraint that limits input to alphanumeric characters, preventing injection of script content that could trigger client-side errors.

Question 215

Which of the following is most appropriate to use with SOAR when the security team would like to automate actions across different vendor platforms?

A. STIX/TAXII
B. APIs
C. Data enrichment
D. Threat feed
Show Answer
Correct Answer: B
Explanation:
SOAR automates workflows by integrating with security products from multiple vendors through their APIs. APIs allow the SOAR platform to execute actions such as blocking IPs, isolating endpoints, creating tickets, or disabling accounts across disparate systems. STIX/TAXII are standards for sharing threat intelligence, while data enrichment and threat feeds provide information rather than cross-platform action automation.

Question 216

An analyst is creating the final vulnerability report for one of the company’s customers. The customer asks for a scanning profile with a CVSS score of 7 or higher. The analyst has confirmed there is no finding for missing database patches, even if false positives have been eliminated by manual checks. Which of the following is the most probable reason for the missing scan result?

A. The server was offline at the moment of the scan.
B. The system was not patched appropriately before the scan.
C. The scan finding does not match the requirement.
D. The output of the scan is corrupted.
Show Answer
Correct Answer: C
Explanation:
The customer requested a scanning profile that reports vulnerabilities with a CVSS score of 7 or higher. If missing database patches do not appear in the report despite validation that there are no false positives, the most likely explanation is that the finding did not meet the reporting threshold or otherwise did not match the selected scan/report profile requirements. If the server were offline, there would typically be scan errors or missing host data rather than only an absent database-patch finding. An unpatched system would tend to produce findings, not suppress them, and corrupted output is less probable than a filtering/profile mismatch.

Question 217

A Chief Finance Officer receives an email from someone who is possibly impersonating the company’s Chief Executive Officer and requesting a financial operation. Which of the following should an analyst use to verify whether the email is an impersonation attempt?

A. PKI
B. MFA
C. SMTP
D. DKIM
Show Answer
Correct Answer: D
Explanation:
DKIM (DomainKeys Identified Mail) uses a cryptographic signature in email headers that recipients can verify using the sending domain's public key. This helps determine whether the message genuinely originated from the claimed domain and whether it was altered in transit, making it the appropriate mechanism to verify a potential CEO email impersonation attempt. PKI is a broader trust framework, MFA protects account access rather than verifying an email, and SMTP is simply the mail transport protocol.

Question 218

SIMULATION - An organization’s website was maliciously altered. INSTRUCTIONS - Review information in each tab to select the source IP the analyst should be concerned about, the indicator of compromise, and the two appropriate corrective actions. If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

Illustration for CS0-003 question 218 Illustration for CS0-003 question 218 Illustration for CS0-003 question 218 Illustration for CS0-003 question 218
Show Answer
Correct Answer: Source IP: 41.21.18.102 Indicator of compromise: Modified index.html file Corrective actions: - Change the password on the sjames account - Block external SFTP access
Explanation:
The SFTP log shows the external IP 41.21.18.102 successfully authenticating and writing index.html, matching the website defacement. Reset the compromised credentials and prevent further external SFTP access.

Question 219

A newly hired security manager in a SOC wants to improve efficiency by automating routine tasks. Which of the following SOC tasks is most suitable for automation?

A. Conducting security assessments and audits of IT systems
B. Investigating security incidents and determining the root causes
C. Reviewing logs and alerts to identify security threats and anomalies
D. Generating incident reports and notifying the appropriate stakeholders
Show Answer
Correct Answer: C
Explanation:
Reviewing logs and alerts is the SOC task most commonly and effectively automated using SIEM/SOAR platforms, which ingest, correlate, and analyze large volumes of telemetry to identify potential threats and anomalies. Security assessments and root-cause investigations require significant human judgment, while incident reporting can be partially automated but often needs analyst review and contextualization.

Question 220

A Chief Information Security Officer wants to lock down the users’ ability to change applications that are installed on their Windows systems. Which of the following is the best enterprise-level solution?

A. HIPS
B. GPO
C. Registry
D. DLP
Show Answer
Correct Answer: B
Explanation:
Group Policy Objects (GPOs) provide centralized, enterprise-scale management of Windows system settings, including software installation restrictions, application control policies, and user permissions. HIPS protects hosts from attacks, the Registry is not an enterprise management solution, and DLP focuses on preventing data exfiltration rather than controlling installed applications.

$19

Get all 534 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.