{"id":14079,"date":"2026-09-16T12:47:53","date_gmt":"2026-09-16T12:47:53","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=14079"},"modified":"2026-09-16T12:47:53","modified_gmt":"2026-09-16T12:47:53","slug":"comptia-cysa-cs0-003-practice-test-questions-and-exam-dumps-part2-q21-40","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-cysa-cs0-003-practice-test-questions-and-exam-dumps-part2-q21-40\/","title":{"rendered":"CompTIA CYSA+ CS0-003 Practice Test Questions and Exam Dumps Part2 Q21-40"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cs0-003-exam-dumps\"><b>CompTIA CS0-003 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 21<\/b><\/h3>\n<p><b>Which security tool is primarily used to collect and correlate logs from multiple sources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Proxy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAC<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Security Information and Event Management system, or SIEM, collects security logs and events from multiple sources and correlates them for centralized analysis. Sources can include firewalls, servers, endpoints, authentication systems, cloud services, and applications. Correlation helps analysts identify relationships between events that may appear unrelated when viewed separately. SIEM platforms can also provide alerting, dashboards, search capabilities, and reporting. Effective implementation requires appropriate log collection and normalization so analysts can investigate suspicious activity efficiently and distinguish meaningful security events from routine system activity.<\/span><\/p>\n<h3><b>Question 22<\/b><\/h3>\n<p><b>What is the primary purpose of threat hunting?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configure firewalls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Proactively search for threats<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Install operating systems<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Create user accounts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Threat hunting is a proactive security activity in which analysts search through systems, networks, logs, and other data sources for signs of malicious activity that automated security controls may have missed. Instead of waiting for an alert, threat hunters develop hypotheses based on known attacker behaviors, threat intelligence, and unusual activity. They may investigate indicators such as suspicious processes, unexpected authentication, unusual network connections, or persistence mechanisms. Effective threat hunting can uncover stealthy threats and improve detection rules by identifying previously overlooked patterns.<\/span><\/p>\n<h3><b>Question 23<\/b><\/h3>\n<p><b>Which vulnerability is caused by inserting malicious commands into an application&#8217;s database query?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">XSS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CSRF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DDoS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">SQL injection occurs when an application improperly handles untrusted input that becomes part of a database query. An attacker may manipulate that input to alter the intended query and potentially access, modify, or delete unauthorized information. Parameterized queries and prepared statements are among the primary defenses against SQL injection. Security analysts should also consider input validation, secure coding practices, and database account privileges. During vulnerability assessment, applications that dynamically construct SQL statements from user-controlled input should receive particular attention because improper handling can create significant security exposure.<\/span><\/p>\n<h3><b>Question 24<\/b><\/h3>\n<p><b>Which authentication method requires more than one type of verification?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single sign-on<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Multifactor authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password hashing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Account federation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Multifactor authentication, or MFA, requires users to provide multiple authentication factors from different categories. These categories generally include something the user knows, something the user has, and something the user is. For example, a password combined with a hardware token or authenticator application provides stronger protection than a password alone. MFA can significantly reduce the impact of stolen passwords because an attacker also needs the additional factor. Security teams should still monitor authentication activity because attackers may attempt methods such as phishing or session theft to bypass MFA.<\/span><\/p>\n<h3><b>Question 25<\/b><\/h3>\n<p><b>An analyst notices a workstation making connections to an unfamiliar external domain every five minutes. What should be investigated?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Possible command-and-control activity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Printer configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Screen resolution<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Local disk capacity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Regular connections to an unfamiliar external domain can be a potential indicator of command-and-control activity. Malware may periodically contact attacker-controlled infrastructure to receive instructions, send information, or maintain communication. Analysts should investigate the destination domain, DNS history, associated IP addresses, process responsible for the connection, timestamps, and network traffic. The behavior does not automatically prove compromise because legitimate applications can also communicate periodically with external services. Correlating endpoint telemetry, DNS records, proxy logs, and threat intelligence can help determine whether the connection is suspicious.<\/span><\/p>\n<h3><b>Question 26<\/b><\/h3>\n<p><b>Which security assessment actively attempts to exploit identified vulnerabilities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability scan<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Penetration test<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log review<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configuration audit<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A penetration test actively attempts to exploit vulnerabilities in a controlled and authorized manner to determine whether weaknesses can actually be used to compromise systems or achieve specific objectives. This differs from a vulnerability scan, which primarily identifies potential weaknesses without necessarily exploiting them. Penetration testing can provide information about attack paths, security-control effectiveness, and potential business impact. Because exploitation can affect systems and data, penetration tests should have clearly defined scope, authorization, rules of engagement, and safety procedures before testing begins.<\/span><\/p>\n<h3><b>Question 27<\/b><\/h3>\n<p><b>Which attack uses previously leaked username and password combinations against multiple websites?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential stuffing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Brute force<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Phishing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privilege escalation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Credential stuffing uses previously compromised username and password combinations to attempt access to other services. It relies on password reuse rather than guessing passwords from scratch. Attackers may automate large numbers of login attempts against online services using credentials obtained from previous breaches. Multifactor authentication, unique passwords, breached-password detection, rate limiting, and monitoring can reduce the effectiveness of credential-stuffing attacks. Analysts should investigate unusual authentication patterns, especially when the same accounts show login attempts from unfamiliar locations, devices, or addresses.<\/span><\/p>\n<h3><b>Question 28<\/b><\/h3>\n<p><b>Which control can prevent unauthorized devices from connecting to a corporate network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Honeypot<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network Access Control, or NAC, can enforce policies that determine whether devices are allowed to connect to a network. NAC solutions may evaluate characteristics such as device identity, authentication status, security configuration, or compliance state before granting access. Organizations can use NAC to restrict unmanaged or noncompliant devices and place them into appropriate network segments. This provides an additional layer of protection against unauthorized network access. NAC is different from SIEM, which focuses on collecting and analyzing security events rather than directly controlling network admission.<\/span><\/p>\n<h3><b>Question 29<\/b><\/h3>\n<p><b>What does a CVSS score help security teams determine?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User password age<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability severity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network bandwidth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backup duration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Common Vulnerability Scoring System, or CVSS, provides a standardized method for expressing the severity of vulnerabilities. Its scoring framework considers characteristics related to exploitability and impact, helping organizations compare vulnerabilities and prioritize remediation. A CVSS score should not be treated as the only factor in deciding remediation priority. Organizations should also consider asset criticality, exposure, available exploits, business impact, and compensating controls. Using CVSS alongside organizational context helps security teams determine which vulnerabilities require immediate attention and which can be addressed through normal remediation cycles.<\/span><\/p>\n<h3><b>Question 30<\/b><\/h3>\n<p><b>Which log would provide information about connections allowed or blocked by a firewall?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application log<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall log<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Database log<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authentication log<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Firewall logs record network traffic that the firewall permits, blocks, or otherwise processes according to configured security rules. These logs can include source and destination addresses, ports, protocols, timestamps, and action results. Analysts can use firewall logs to investigate suspicious connections, policy violations, scanning activity, and attempted access to restricted services. When investigating an incident, firewall data can be correlated with endpoint, DNS, authentication, and application logs to build a broader timeline. Proper log retention and filtering are important for effective network-security investigations.<\/span><\/p>\n<h3><b>Question 31<\/b><\/h3>\n<p><b>Which security control is designed to prevent sensitive information from leaving an organization?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data Loss Prevention, or DLP, is designed to identify and prevent unauthorized transmission or exposure of sensitive information. DLP controls can inspect data in locations such as endpoints, email, cloud services, and network channels. Policies may identify sensitive information using content patterns, classifications, labels, or other indicators. Depending on configuration, DLP can alert security teams, block transfers, or require additional authorization. Effective DLP requires carefully designed policies because overly broad rules can generate excessive alerts and interfere with legitimate business activities.<\/span><\/p>\n<h3><b>Question 32<\/b><\/h3>\n<p><b>What is the purpose of a honeypot?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Store production backups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Attract and monitor attackers<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encrypt databases<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manage software licenses<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A honeypot is a deliberately designed system or service intended to attract and observe unauthorized activity. Because legitimate users generally have no reason to interact with it, activity against a honeypot can be a useful indicator of reconnaissance, exploitation, or attempted compromise. Security teams can analyze the activity to learn about attacker techniques and improve detection capabilities. Honeypots should be carefully isolated from production systems so that an attacker cannot use them as a pathway into important resources. They are primarily detection and intelligence tools.<\/span><\/p>\n<h3><b>Question 33<\/b><\/h3>\n<p><b>Which technique involves trying common passwords against many different accounts?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential stuffing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password spraying<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hashing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Password spraying involves trying a small number of commonly used passwords against many accounts rather than attempting many passwords against a single account. Attackers use this technique to avoid triggering account lockout thresholds that might be activated by repeated failures against one user. Analysts can detect password spraying by looking for similar failed authentication attempts across multiple accounts, particularly when they originate from the same source or occur within a short timeframe. Multifactor authentication, strong password policies, monitoring, and rate limiting can help reduce this threat.<\/span><\/p>\n<h3><b>Question 34<\/b><\/h3>\n<p><b>Which activity examines systems to determine whether their configurations comply with security requirements?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configuration assessment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data recovery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Threat hunting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet capture<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A configuration assessment examines systems against defined security requirements, benchmarks, policies, or recommended configurations. It can identify issues such as unnecessary services, weak security settings, excessive permissions, or missing protective controls. Security teams can use configuration assessments to identify deviations from approved baselines and determine which systems require corrective action. Regular assessments are especially useful because configurations can change over time due to software updates, administrative actions, or application requirements. Findings should be documented, prioritized, remediated, and validated after changes are implemented.<\/span><\/p>\n<h3><b>Question 35<\/b><\/h3>\n<p><b>Which incident response activity focuses on determining what happened and how the attacker gained access?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Recovery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Forensic investigation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User provisioning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Patch management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Forensic investigation focuses on collecting and analyzing evidence to determine what happened during a security incident. Analysts may examine endpoint artifacts, logs, network traffic, memory, files, authentication records, and other sources to reconstruct an attack timeline. The investigation can help identify the initial access method, attacker actions, affected systems, and persistence mechanisms. Evidence should be handled carefully to preserve its integrity and support accurate conclusions. Findings from forensic analysis can also help organizations improve security controls and prevent similar incidents from recurring.<\/span><\/p>\n<h3><b>Question 36<\/b><\/h3>\n<p><b>Which type of malware disguises itself as legitimate software?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Worm<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Trojan<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ransomware<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rootkit<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Trojan is malware that disguises itself as legitimate or useful software to persuade users or systems to execute it. Once installed, it may perform malicious activities such as stealing information, downloading additional malware, establishing persistence, or providing unauthorized access. Unlike worms, Trojans generally do not rely on self-replication as their primary propagation mechanism. Security teams can reduce Trojan infections through application controls, endpoint protection, user awareness, software verification, and monitoring for unusual processes or network connections following software installation.<\/span><\/p>\n<h3><b>Question 37<\/b><\/h3>\n<p><b>What is the primary purpose of a security baseline?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Define an approved configuration standard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increase internet speed<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace vulnerability scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Store incident reports<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A security baseline defines an approved configuration or minimum security standard for systems and devices. It can specify requirements for settings such as services, authentication, logging, encryption, software, and access controls. Comparing systems against a baseline helps organizations identify configuration drift and security weaknesses. Baselines should reflect organizational requirements and applicable security standards rather than being treated as permanent configurations. As technologies and threats change, security teams should review and update baselines. Automated compliance tools can help identify systems that no longer meet the required configuration.<\/span><\/p>\n<h3><b>Question 38<\/b><\/h3>\n<p><b>Which technology can block malicious network traffic based on configured security rules?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IDS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Scanner<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Intrusion Prevention System, or IPS, monitors network traffic and can automatically block or prevent activity identified as malicious according to configured detection and prevention rules. This distinguishes an IPS from a traditional IDS, which primarily detects suspicious activity and generates alerts. IPS technologies can use signatures, behavioral indicators, protocol analysis, or other detection mechanisms. Security teams must tune IPS rules carefully because overly aggressive controls can block legitimate traffic. Analysts should also investigate prevention events to determine whether they indicate an attempted attack or a false positive.<\/span><\/p>\n<h3><b>Question 39<\/b><\/h3>\n<p><b>Which practice helps determine whether a security alert is a false positive?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ignoring the alert<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Correlating additional evidence<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling all logging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Removing the affected user<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Correlating additional evidence helps analysts determine whether a security alert represents a genuine threat or a false positive. An analyst may compare the alert with endpoint activity, authentication logs, network traffic, DNS requests, user behavior, and threat intelligence. For example, an unusual login may initially appear suspicious but become explainable after confirming that the user was traveling or using an approved VPN. Analysts should avoid dismissing alerts without investigation. Proper alert validation improves detection accuracy and helps security teams focus their resources on meaningful threats.<\/span><\/p>\n<h3><b>Question 40<\/b><\/h3>\n<p><b>Which action should occur before performing an authorized penetration test?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Delete security logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Establish rules of engagement<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable all backups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove network segmentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Rules of engagement define how an authorized penetration test will be conducted. They can specify the testing scope, systems and applications included, permitted techniques, testing windows, communication procedures, emergency contacts, and actions that are prohibited. Establishing these rules helps prevent accidental disruption and ensures that testers and system owners understand their responsibilities. Formal authorization should also be obtained before testing begins. Clear rules protect both the organization and the testing team while providing boundaries for safely evaluating the effectiveness of security controls.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CompTIA CS0-003 Exam Dumps and Practice Test Dumps. &nbsp; Question 21 Which security tool is primarily used to collect and correlate logs from multiple sources? SIEM VPN Proxy NAC Correct Answer: 1 Explanation A Security Information and Event Management system, or SIEM, collects security logs and events from multiple sources and correlates them [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14079"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=14079"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14079\/revisions"}],"predecessor-version":[{"id":14158,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14079\/revisions\/14158"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=14079"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=14079"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=14079"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}