Comptia

CS0-003 Free Practice Questions — Page 6

Question 26

The most recent vulnerability scan results show the following: The vulnerability team learned the following from the asset owners: • Server HQFIN01 is a financial transaction database server used in the company's largest business unit. • Server HQADMIN02 is utilized by an end user with administrator privileges to several critical applications. • No compensating controls exist for either issue. Which of the following would the vulnerability team most likely do to determine remediation prioritization?

A. Review the BCP and prioritize the remediation of the asset that would take more time to bring online for operational use.
B. Contact the network and desktop engineering teams to discuss prioritizing the asset that is faster to remediate.
C. Reference the BIA to determine the value designation and prioritize vulnerability remediation of the more critical asset.
D. Identify the network placement and configuration of each asset, then prioritize the asset with the least recent backups.
Show Answer
Correct Answer: C
Explanation:
Remediation prioritization should be based on business impact and asset criticality, not recovery logistics or speed of fixing. A Business Impact Analysis (BIA) identifies the value and operational importance of assets to the organization. Since one server supports financial transactions in the largest business unit, referencing the BIA allows the vulnerability team to prioritize remediation of the more critical asset appropriately.

Question 26

A company reports that user plain text credentials have been disclosed from their network. A security analyst is identifying the vulnerability and runs a scan to receive the following: Which of the following computers is the source of the leaked credentials?

A. 10.205.8.14
B. 10.205.8.15
C. 10.205.8.16
D. 10.205.8.17
Show Answer
Correct Answer: D
Explanation:
Plain-text credential leakage commonly occurs with protocols that do not encrypt authentication data. FTP (TCP port 21) transmits usernames and passwords in clear text. The scan indicates that 10.205.8.17 has port 21/tcp open, making it the most likely source of the leaked credentials.

Question 27

A finance department employee opens an unsolicited email that contains a malicious payload. The payload quickly spreads through the finance department, but does not affect other departments. Which of the following best explains why the payload does not affect all departments?

A. OS version
B. Offline computers
C. Firewall configuration
D. Network segmentation
Show Answer
Correct Answer: D
Explanation:
The malware spreads within the finance department but cannot reach other departments because network segmentation separates departments into different network segments or VLANs with restricted traffic between them. This containment limits lateral movement of the payload beyond the finance network.

Question 27

A company wants to implement protection mechanisms after an incident in which customer information was sent to a third party. Which of the following tools should the company implement?

A. SIEM
B. EDR
C. CASB
D. DLP
Show Answer
Correct Answer: D
Explanation:
The incident involved customer information being sent to an unauthorized third party. Data Loss Prevention (DLP) tools are specifically designed to detect, monitor, and block sensitive data from leaving the organization through email, cloud services, endpoints, or networks. SIEM focuses on log aggregation and alerting, EDR on endpoint threat detection, and CASB on controlling cloud app usage, but DLP directly addresses preventing data exfiltration.

Question 28

Which of the following explains why a company would consider enriching data before sending it to the SIEM?

A. To prevent injection attacks against the log management system
B. To reduce the amount and cost of data storage for security incidents
C. To provide more information to SOC analysts when analyzing events
D. To normalize the data before saving it to the database tables
Show Answer
Correct Answer: C
Explanation:
Data enrichment adds contextual information (e.g., asset details, user identity, geolocation, threat intel) to raw logs before ingestion, which helps SOC analysts better understand, correlate, and investigate security events. It is not primarily for preventing injection attacks (A), reducing storage costs (B)—enrichment often increases data size—or basic normalization (D), which is a separate preprocessing step.

Question 28

A security analyst investigates a malware alert from a critical system. The following information is present in the ticket: Which of the following should the analyst do first?

A. Block the suspicious IP address 128.210.175.23.
B. Determine whether sssh is a malicious program.
C. Delete the suspicious files.
D. Review the Apache logs.
Show Answer
Correct Answer: B
Explanation:
The first step in incident response is identification and validation. Before taking containment actions like blocking an IP or deleting files, the analyst must confirm whether the observed artifact is actually malicious. The process name "sssh" suggests possible masquerading, but this must be verified to avoid disrupting a critical system with false positives. Therefore, determining whether sssh is a malicious program should be done first.

Question 29

A security analyst is performing a malware analysis on a device and receives the following instructions: • Reduce the blast radius of the potential threat. • Preserve forensic data for post-incident analysis. • If securely possible, preserve connectivity for live analysis. Which of the following will best help the analyst during the investigation?

A. Configure an EDR agent to isolate the network with authorized exceptions to the NOC VLAN.
B. Execute a SOAR playbook to trigger a malware scan on the company's assets.
C. Use file integrity monitoring to determine if the suspicious file was modified.
D. Collect the suspicious file using SFTP and reimage the device.
Show Answer
Correct Answer: A
Explanation:
Configuring an EDR agent to isolate the host limits lateral movement and reduces the blast radius while keeping the system powered on and intact, preserving forensic evidence. Allowing authorized network exceptions (such as to a NOC or security VLAN) maintains controlled connectivity so analysts can perform live investigation and monitoring. The other options either do not contain the threat, do not preserve live analysis capability, or destroy forensic data.

Question 29

Which of the following best explains the importance of utilizing an incident response playbook?

A. It prioritizes the business-critical assets for data recovery.
B. It establishes actions to execute when inputs trigger an event.
C. It documents the organization asset management and configuration.
D. It defines how many disaster recovery sites should be staged.
Show Answer
Correct Answer: B
Explanation:
An incident response playbook provides predefined, repeatable actions to take when specific triggers or indicators occur, ensuring a coordinated and efficient response. The other options describe asset recovery prioritization, asset management documentation, or disaster recovery planning, which are separate from an incident response playbook’s purpose.

Question 30

A security analyst is responding to an incident that is related to an unauthorized communication between systems. While triaging the event, the analyst obtains the following outputs: Which of the following commands should the analyst use to terminate the malicious session?

A. kill -9 4347
B. kill -9 6015
C. kill -9 701
D. kill -9 5996
Show Answer
Correct Answer: D
Explanation:
The malicious activity is the Python process that establishes an unauthorized socket connection to 10.203.10.22:1234. That process has PID 5996, so terminating it with `kill -9 5996` will stop the malicious session. The other PIDs correspond to legitimate or benign processes (pipewire, a bash shell, and the `top` command).

Question 30

Which of the following best describes root cause analysis?

A. It describes the tactics, techniques, and procedures used in an incident.
B. It provides a detailed path outlining the origin of an issue and how to eliminate it permanently.
C. It outlines the who-what-when-where-why, which is often used in conjunction with legal proceedings.
D. It generates a report of ongoing activities, including what was done, what is being done, and what will be done next.
Show Answer
Correct Answer: B
Explanation:
Root cause analysis focuses on identifying the fundamental underlying cause of a problem and mapping how it originated, with the goal of implementing corrective actions that prevent recurrence. Option B accurately captures both tracing the origin of the issue and eliminating it permanently, which are the core objectives of RCA. The other options describe incident tactics, legal-style reporting, or status reporting, not root cause analysis.

$19

Get all 528 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.