Comptia

CS0-003 Free Practice Questions — Page 27

Question 261

An analyst is suddenly unable to enrich data from the firewall. However, the other open intelligence feeds continue to work. Which of the following is the most likely reason in the firewall feed stopped working?

A. The firewall service account was locked out.
B. The firewall was using a paid feed.
C. The firewall certificate expired.
D. The firewall failed open.
Show Answer
Correct Answer: A
Explanation:
The scenario indicates only the firewall integration stopped while other threat intelligence feeds continue to function. That points to a problem specific to the firewall integration rather than a global enrichment issue. A locked service account would prevent the SIEM/SOAR from authenticating to the firewall and retrieving data. A paid feed (B) is unsupported by the scenario, an expired certificate (C) is possible but less directly indicated, and a firewall failing open (D) affects traffic handling, not enrichment connectivity.

Question 262

After an incident, a security analyst needs to perform a forensic analysis to report complete information to a company stakeholder. Which of the following is most likely the goal of the forensic analysis in this case?

A. Provide a full picture of the existing risks.
B. Notify law enforcement of the incident.
C. Further contain the incident.
D. Determine root cause information.
Show Answer
Correct Answer: D
Explanation:
The primary goal of forensic analysis after an incident is to reconstruct what happened and determine the root cause, including the attack vector, affected systems, and timeline, so accurate findings can be reported to stakeholders and used to improve future defenses. Providing a full picture of existing risks is a broader risk assessment activity, notifying law enforcement is situational rather than the goal of forensic analysis, and containment occurs during incident response rather than forensic reporting.

Question 263

An organization has a critical financial application hosted online that does not allow event logging to send to the corporate SIEM. Which of the following is the best option for the security analyst to configure to improve the efficiency of security operations?

A. Configure a new SIEM specific to the management of the hosted environment.
B. Subscribe to a threat feed related to the vendor's application.
C. Use a vendor-provided API to automate pulling the logs in real time.
D. Download and manually import the logs outside of business hours.
Show Answer
Correct Answer: C
Explanation:
Using a vendor-provided API to pull logs in real time enables automated ingestion into the existing security monitoring workflow despite the application not being able to send logs directly to the corporate SIEM. This improves visibility and operational efficiency without deploying a separate SIEM or relying on manual imports. A separate SIEM increases complexity, a threat feed does not solve the logging gap, and manual downloads are inefficient and delay detection.

Question 264

Which of the following would most likely be used to update a dashboard that integrates with multiple vendor tools?

A. Webhooks
B. Extensible Markup Language
C. Threat feed combination
D. JavaScript Object Notation
Show Answer
Correct Answer: A
Explanation:
Webhooks are the mechanism commonly used to push event-driven updates from multiple vendor tools to a central dashboard in near real time. XML and JSON are data serialization formats rather than update mechanisms, and 'threat feed combination' is not an integration method.

Question 265

Which of the following best explains the importance of communicating with staff regarding the official public communication plan related to incidents impacting the organization?

A. To establish what information is allowed to be released by designated employees
B. To designate an external public relations firm to represent the organization
C. To ensure that all news media outlets are informed at the same lime
D. To define how each employee will be contacted after an event occurs
Show Answer
Correct Answer: A
Explanation:
Communicating the organization's official public communication plan ensures staff understand who is authorized to communicate externally and what information may be released. This prevents inconsistent or unauthorized messaging during an incident and helps maintain accuracy, legal compliance, and organizational trust.

Question 266

Which of the following would eliminate the need for different passwords for a variety of internal applications?

A. CASB
B. SSO
C. PAM
D. MFA
Show Answer
Correct Answer: B
Explanation:
Single Sign-On (SSO) allows a user to authenticate once and access multiple internal applications without maintaining or entering separate passwords for each application. CASB secures cloud service usage, PAM manages privileged accounts, and MFA adds authentication factors but does not eliminate the need for multiple passwords by itself.

Question 267

An organization is conducting a pilot deployment of an e-commerce application. The application’s source code is not available. Which of the following strategies should an analyst recommend to evaluate the security of the software?

A. Static testing
B. Vulnerability testing
C. Dynamic testing
D. Penetration testing
Show Answer
Correct Answer: C
Explanation:
Dynamic testing is the best choice because the application's source code is unavailable, making static testing inappropriate. Dynamic testing evaluates the running application (black-box testing) to identify security weaknesses through its runtime behavior. Vulnerability testing does not require source code but is narrower in scope, typically identifying known weaknesses or misconfigurations. Penetration testing is a more targeted exercise to exploit vulnerabilities and usually follows or builds upon broader security assessment activities. Since the question asks for a strategy to evaluate the security of the software during a pilot deployment, dynamic testing is the most appropriate answer.

Question 268

Which of the following entities should an incident manager work with to ensure correct processes are adhered to when communicating incident reporting to the general public, as a best practice? (Choose two.)

A. Law enforcement
B. Governance
C. Legal
D. Manager
E. Public relations
F. Human resources
Show Answer
Correct Answer: C, E
Explanation:
Best practice is to coordinate public incident communications with Legal to ensure compliance with laws, regulatory obligations, and liability considerations, and with Public Relations to manage accurate, consistent messaging to the public and media. Law enforcement may be involved in some incidents but is not the primary authority for organizational public communications. Sources: https://www.hklaw.com/en/insights/publications/2023/07/sec-finalizes-cybersecurity-incident-and-governance-disclosure https://isp.illinois.gov/StaticFiles/docs/DepartmentDirectives/ADM-015%20DIR.pdf

Question 269

An organization has establish a formal change management process after experiencing several critical system failures over the past year. Which of the following are key factors that the change management process will include in order to reduce the impact of system failures? (Choose two.)

A. Ensure users the document system recovery plan prior to deployment.
B. Perform a full system-level backup following the change.
C. Leverage an audit tool to identify changes that are being made.
D. Identify assets with dependence that could be impacted by the change.
E. Require diagrams to be completed for all critical systems.
F. Ensure that all assets are properly listed in the inventory management system.
Show Answer
Correct Answer: A, D
Explanation:
Formal change management focuses on planning, impact analysis, and rollback/recovery. Identifying dependent assets reduces unintended outages, and ensuring a documented system recovery/rollback plan before deployment minimizes the impact if a change fails. Performing backups after a change is too late, audit tools support monitoring rather than core change planning, and diagrams/inventory are useful but not the key controls asked here. Sources: https://www.atlassian.com/blog/innovation/change-management-steps

Question 270

A cybersecurity analyst has been assigned to the threat-hunting team to create a dynamic detection strategy based on behavioral analysis and attack patterns. Which of the following best describes what the analyst will be creating?

A. Bots
B. IoCs
C. TTPs
D. Signatures
Show Answer
Correct Answer: C
Explanation:
The analyst is creating a detection strategy based on behavioral analysis and attack patterns, which aligns with Tactics, Techniques, and Procedures (TTPs). TTP-based detection focuses on how adversaries operate rather than relying on static indicators. IoCs are specific artifacts of compromise, signatures are pattern-based detections, and bots are automated programs, not a detection methodology.

$19

Get all 534 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.