Comptia

CS0-003 Free Practice Questions — Page 7

Question 61

An e-commerce organization recently experienced a cyberattack. During a lessons learned meeting, a cybersecurity analyst requests that the RTO is prioritized. Which of the following is the greatest concern?

A. Integrity
B. Availability
C. Non-repudiation
D. Confidentiality
Show Answer
Correct Answer: B
Explanation:
Recovery Time Objective (RTO) is the maximum acceptable downtime after a disruption before business impact becomes unacceptable. Prioritizing RTO means the primary concern is restoring services quickly, which directly addresses the availability of systems and services. Integrity, confidentiality, and non-repudiation are different security objectives and are not what RTO primarily measures.

Question 62

A security analyst is assessing the security of a cloud environment. The following output is generated when the assessment runs: Authentication error - Instance not found on preset location Which of the following should the analyst use to fix the issue?

A. run module_name and exec
B. --session and --module-args=" "
C. set_regions and set_key
D. --whoami and --data
Show Answer
Correct Answer: C
Explanation:
The error combines an authentication problem with an inability to locate the instance in the configured location. Configuring the correct cloud region and the appropriate authentication key addresses both issues. The other options are generic execution or query flags that do not resolve region and credential configuration.

Question 63

A security analyst is looking for information that would serve as an indicator that a given IP address is Involved in other attacks. Which of the following sources of information should the analyst use to achieve this objective?

A. AbuseIPDB
B. Autonomous System Number
C. Whois
D. Cuckoo Sandbox
Show Answer
Correct Answer: A
Explanation:
AbuseIPDB is a threat intelligence and reputation service that aggregates reports of malicious activity associated with IP addresses, making it an appropriate source to determine whether an IP has been involved in other attacks. An Autonomous System Number identifies the network operator, Whois provides registration information, and Cuckoo Sandbox is used for malware analysis rather than IP reputation.

Question 64

Which of the following is the best technical method to protect sensitive data at an organizational level?

A. Deny all traffic on port 8080 with sensitive information on the VLAN.
B. Develop a Python script to review email traffic for PII.
C. Employ a restrictive policy for the use and distribution of sensitive information.
D. Implement a DLP for all egress and ingress of sensitive information on the network.
Show Answer
Correct Answer: D
Explanation:
A Data Loss Prevention (DLP) solution is the best technical control at an organizational level for protecting sensitive data because it identifies, monitors, and enforces policies for sensitive information in transit, at rest, and often in use. Blocking a single port is too narrow, a custom Python script is limited and not comprehensive, and a restrictive policy is an administrative rather than a technical control.

Question 65

A DevOps analyst implements a webhook to trigger code vulnerability scanning for submissions to the repository. Which of the following is the primary benefit of this enhancement?

A. To increase coverage by making the process occur automatically with uploads
B. To create a single pane of glass dashboard for the vulnerability management process
C. To include a threat feed component into the software development life cycle
D. To employ data enrichment for new code commits to enhance project documentation
Show Answer
Correct Answer: A
Explanation:
A webhook automatically triggers an action when a repository event such as a code submission or commit occurs. Using a webhook to initiate vulnerability scanning ensures scans happen automatically for new uploads, increasing consistency and coverage within the development workflow. The other options describe capabilities unrelated to the primary purpose of a webhook-triggered scan.

Question 66

A company wants to grant access to identity administrators who are completing similar tasks. Which of the following access control models should the company use?

A. Mandatory access
B. Role-based access
C. Attribute-based access
D. Discretionary access
Show Answer
Correct Answer: B
Explanation:
Role-based access control (RBAC) assigns permissions based on job roles. When multiple identity administrators perform similar tasks, granting permissions through a shared role simplifies administration, ensures consistent access, and scales efficiently. Mandatory access is centrally enforced by security labels, attribute-based access uses attributes and policies, and discretionary access lets resource owners grant permissions.

Question 67

A SOC manager is looking for a solution that can improve the response time and execute predetermined instructions. Which of the following is the best solution based on these requirements?

A. XDR
B. SIEM
C. CASB
D. SOAR
Show Answer
Correct Answer: D
Explanation:
SOAR (Security Orchestration, Automation, and Response) is designed to automate incident response using predefined playbooks and orchestrate actions across security tools, improving response times and reducing manual effort. SIEM focuses on log collection and correlation, XDR improves detection and response across endpoints and other layers but is not primarily centered on automated playbook orchestration, and CASB secures cloud service usage.

Question 68

The DevSecOps team is remediating an SSRF issue on the company's public-facing website. Which of the following is the best mitigation technique to address this issue?

A. Place a WAF in front of the web server.
B. Install a CASB in front of the web server
C. Put a forward proxy in front of the web server.
D. Implement MFA in front of the web server
Show Answer
Correct Answer: A
Explanation:
A Web Application Firewall (WAF) is the best choice among the options because it can inspect and block malicious HTTP requests, including many SSRF attack patterns, reducing exploitability of public-facing web applications. A CASB governs cloud service access, a forward proxy is for client outbound traffic rather than protecting an Internet-facing web server, and MFA addresses authentication rather than SSRF.

Question 69

A security analyst wants to implement new monitoring controls in order to find abnormal account activity for traveling employees. Which of the following techniques would deliver the expected results?

A. Malicious command interpretation
B. Network monitoring
C. User behavior analysis
D. SSL inspection
Show Answer
Correct Answer: C
Explanation:
User behavior analysis (UBA/UEBA) establishes a baseline of normal user activity and detects anomalies such as impossible travel, unusual login locations, devices, access times, or resource usage. This is the appropriate technique for identifying abnormal account activity among traveling employees. Network monitoring, SSL inspection, and malicious command interpretation do not specifically detect deviations in user account behavior.

Question 70

A security administrator is tasked with modifying the vulnerability scan process to reduce the network traffic but maintain thorough checks. Which of the following scanning approaches should be implemented?

A. Credentialed scans
B. Individual scans
C. Security baseline scans
D. Agent-based scans
Show Answer
Correct Answer: D
Explanation:
Agent-based scans perform most vulnerability assessment locally on the endpoint and send back results, significantly reducing network scanning traffic while still providing thorough visibility into system configuration, installed software, and patch status. Credentialed scans improve scan depth but still require network connectivity and do not primarily reduce network traffic. Individual scans and security baseline scans do not address the stated goal.

$19

Get all 534 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.