πŸ”

CS0-003 β€” all questions

10 practice questions with answers and explanations.

Topic 1 Β· Question 1

An analyst finds that an IP address outside of the company network that is being used to run network and vulnerability scans across external-facing assets. Which of the following steps of an attack framework is the analyst witnessing?

  • AExploitation
  • BReconnaissance (correct answer)
  • CCommand and control
  • DActions on objectives
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Reconnaissance

Topic 1 Β· Question 2

An analyst wants to ensure that users only leverage web-based software that has been pre-approved by the organization. Which of the following should be deployed?

  • ABlocklisting
  • BAllowlisting (correct answer)
  • CGraylisting
  • DWebhooks
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Allowlisting

Topic 1 Β· Question 3

During a cybersecurity incident, one of the web servers at the perimeter network was affected by ransomware. Which of the following actions should be performed immediately?

  • AShut down the server.
  • BReimage the server.
  • CQuarantine the server. (correct answer)
  • DUpdate the OS to latest version.
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Quarantine the server. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 4

An organization recently changed its BC and DR plans. Which of the following would best allow for the incident response team to test the changes without any impact to the business?

  • APerform a tabletop drill based on previously identified incident scenarios. (correct answer)
  • BSimulate an incident by shutting down power to the primary data center.
  • CMigrate active workloads from the primary data center to the secondary location.
  • DCompare the current plan to lessons learned from previous incidents.
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Perform a tabletop drill based on previously identified incident scenarios.

Topic 1 Β· Question 5

Security analysts review logs on multiple servers on a daily basis. Which of the following implementations will give the best central visibility into the events occurring throughout the corporate environment without logging in to the servers individually?

  • ADeploy a database to aggregate the logging
  • BConfigure the servers to forward logs to a SIEM (correct answer)
  • CShare the log directory on each server to allow local access.
  • DAutomate the emailing of logs to the analysts.
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Configure the servers to forward logs to a SIEM

Explanation

A SIEM centralizes and correlates security events to support detection, investigation, and reporting. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 6

A web application team notifies a SOC analyst that there are thousands of HTTP/404 events on the public-facing web server. Which of the following is the next step for the analyst to take?

  • AInstruct the firewall engineer that a rule needs to be added to block this external server
  • BEscalate the event to an incident and notify the SOC manager of the activity
  • CNotify the incident response team that there is a DDoS attack occurring
  • DIdentify the IP/hostname for the requests and look at the related activity (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Identify the IP/hostname for the requests and look at the related activity

Topic 1 Β· Question 7

Which of the following best describes the reporting metric that should be utilized when measuring the degree to which a system application, or user base is affected by an uptime availability outage?

  • ATimeline
  • BEvidence
  • CImpact (correct answer)
  • DScope
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Impact

Topic 1 Β· Question 8

A security analyst needs to provide evidence of regular vulnerability scanning on the company's network for an auditing process. Which of the following is an example of a tool that can produce such evidence?

  • AOpenVAS (correct answer)
  • BBurp Suite
  • CNmap
  • DWireshark
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: OpenVAS This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 9

A security analyst performs a vulnerability scan. Based on the metrics from the scan results, the analyst must prioritize which hosts to patch. The analyst runs the tool and receives the following output: Which of the following hosts should be patched first, based on the metrics?

Exhibit 1 for question 9
  • Ahost01
  • Bhost02
  • Chost03 (correct answer)
  • Dhost04
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: host03 This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 10

An organization receives a legal hold request from an attorney. The request pertains to emails related to a disputed vendor contract. Which of the following is the best step for the security team to take to ensure compliance with the request?

  • APublicly disclose the request to other vendors
  • BNotify the departments involved to preserve potentially relevant information (correct answer)
  • CEstablish a chain of custody starting with the attorney's request
  • DBack up the mailboxes on the server and provide the attorney with a copy
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Notify the departments involved to preserve potentially relevant information This option keeps traffic private / properly secured as required.

Showing questions 1–10 of 10 Β· Page 1 of 1