{"id":14082,"date":"2026-09-16T12:47:14","date_gmt":"2026-09-16T12:47:14","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=14082"},"modified":"2026-09-16T12:47:14","modified_gmt":"2026-09-16T12:47:14","slug":"comptia-cysa-cs0-003-practice-test-questions-and-exam-dumps-part5-q81-100","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-cysa-cs0-003-practice-test-questions-and-exam-dumps-part5-q81-100\/","title":{"rendered":"CompTIA CYSA+ CS0-003 Practice Test Questions and Exam Dumps Part5 Q81-100"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cs0-003-exam-dumps\"><b>CompTIA CS0-003 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 81<\/b><\/h3>\n<p><b>Which technology can automatically isolate a compromised endpoint from the network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SOAR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EDR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint Detection and Response (EDR) solutions provide visibility into endpoint activity and can support response actions such as isolating a compromised device from the network. Isolation helps contain threats by limiting communication between the affected endpoint and other systems. Analysts can then investigate processes, files, network connections, and other endpoint telemetry. EDR is particularly useful during incidents involving malware, suspicious scripts, credential theft, or unauthorized processes. Automated isolation should be configured carefully because incorrectly triggered containment could interrupt legitimate business activity.<\/span><\/p>\n<h3><b>Question 82<\/b><\/h3>\n<p><b>Which framework is commonly used to describe adversary tactics and techniques?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CVSS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MITRE ATT&amp;CK<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">PCI DSS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NIST CSF<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">MITRE ATT&amp;CK is a knowledge base that documents adversary tactics, techniques, and procedures based on observed real-world behavior. Security teams can use it to understand how attackers operate and to map detection capabilities against specific techniques. Analysts may reference ATT&amp;CK when performing threat hunting, developing detection rules, assessing security gaps, or documenting incidents. It is different from vulnerability-scoring frameworks such as CVSS. ATT&amp;CK focuses primarily on adversary behavior rather than assigning a numerical severity score to individual software vulnerabilities.<\/span><\/p>\n<h3><b>Question 83<\/b><\/h3>\n<p><b>Which attack exploits a memory boundary error to execute unintended code?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Phishing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Buffer overflow<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential stuffing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS tunneling<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A buffer overflow occurs when a program writes more data to a memory buffer than the allocated space can safely contain. Depending on the vulnerability and system architecture, an attacker may be able to overwrite adjacent memory, crash the application, or potentially execute unauthorized code. Secure programming practices, memory protections, input validation, compiler security features, and timely patching can reduce the risk. During vulnerability assessments, analysts should pay attention to outdated software and applications that process untrusted input because memory-handling vulnerabilities can have serious consequences.<\/span><\/p>\n<h3><b>Question 84<\/b><\/h3>\n<p><b>Which security control helps prevent unauthorized data from being copied to external storage?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data Loss Prevention (DLP) controls can help prevent sensitive information from being copied to unauthorized destinations, including removable storage devices. Policies can inspect data based on classifications, patterns, labels, file types, or other organizational requirements. Depending on the configuration, DLP may block the transfer, generate an alert, or require additional authorization. Security teams should define policies according to business needs and regularly review exceptions. Effective DLP requires accurate identification of sensitive data and appropriate integration with endpoints, applications, and communication channels.<\/span><\/p>\n<h3><b>Question 85<\/b><\/h3>\n<p><b>What is the primary purpose of vulnerability remediation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increase network speed<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Eliminate or reduce identified security weaknesses<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Create user accounts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace security monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Vulnerability remediation involves taking action to eliminate or reduce identified security weaknesses. Common remediation activities include installing patches, changing insecure configurations, upgrading software, removing unnecessary services, or replacing vulnerable components. Security teams should prioritize remediation based on risk rather than treating every finding equally. After remediation, the affected asset should be rescanned or otherwise validated to confirm that the weakness has been addressed. Proper remediation reduces the likelihood that attackers can exploit known vulnerabilities and helps maintain a stronger overall security posture.<\/span><\/p>\n<h3><b>Question 86<\/b><\/h3>\n<p><b>Which method attempts to identify unusual patterns in large volumes of security data?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anomaly detection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data deletion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password rotation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disk formatting<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Anomaly detection identifies activity that differs significantly from established normal patterns. Security teams can use it to identify unusual login behavior, network traffic, data transfers, process execution, or other events. This approach can help detect previously unknown threats because it does not necessarily depend on a known attack signature. However, unusual behavior is not always malicious, so analysts must investigate anomalies using additional context. Establishing accurate baselines and tuning detection thresholds can reduce false positives and help analysts focus on meaningful deviations.<\/span><\/p>\n<h3><b>Question 87<\/b><\/h3>\n<p><b>Which protocol is commonly associated with secure web communication?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HTTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HTTPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Telnet<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">HTTPS uses HTTP over a secure TLS connection to protect web communications. TLS provides encryption and helps authenticate the server through digital certificates, reducing the risk of attackers intercepting or modifying transmitted information. Security analysts should still verify that TLS is configured correctly because simply using HTTPS does not guarantee that an application is completely secure. Weak protocols, invalid certificates, vulnerable applications, and poor authentication can create additional risks. HTTPS is especially important when users transmit credentials, personal information, payment information, or other sensitive data.<\/span><\/p>\n<h3><b>Question 88<\/b><\/h3>\n<p><b>An analyst receives hundreds of alerts generated by one event. What should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Alert correlation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password reset<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disk replacement<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network shutdown<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Alert correlation can help identify when multiple security alerts are related to the same underlying event. Without correlation, a single attack may generate hundreds of individual alerts, creating alert fatigue and making investigation more difficult. SIEM and security analytics platforms can correlate events using factors such as timestamps, source addresses, usernames, devices, processes, or indicators. Effective correlation allows analysts to focus on the broader incident rather than treating every alert as an independent event. Rules should be carefully tuned to avoid hiding important activity.<\/span><\/p>\n<h3><b>Question 89<\/b><\/h3>\n<p><b>Which attack involves secretly capturing network traffic to obtain sensitive information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet sniffing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password spraying<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privilege escalation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Packet sniffing involves capturing network traffic for analysis or, when performed maliciously, attempting to obtain information transmitted across a network. Unencrypted protocols can expose credentials, session information, or other sensitive data to someone who can observe the traffic. Encryption, secure protocols, network segmentation, and appropriate wireless security can reduce this risk. Analysts can use packet captures during authorized investigations to identify suspicious communications and understand network behavior. The impact of packet sniffing depends heavily on what information is transmitted and whether strong encryption protects it.<\/span><\/p>\n<h3><b>Question 90<\/b><\/h3>\n<p><b>Which process determines whether an alert represents a real security incident?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Alert triage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset disposal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data backup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password hashing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Alert triage is the process of reviewing and evaluating security alerts to determine their significance and whether further investigation is required. Analysts consider the alert source, affected assets, indicators, timestamps, user activity, threat intelligence, and other contextual information. Triage helps distinguish false positives from potentially genuine incidents and allows teams to prioritize their investigative workload. Effective triage procedures should define severity levels, escalation requirements, and evidence to collect. Well-designed triage reduces wasted effort while ensuring important security events receive appropriate attention.<\/span><\/p>\n<h3><b>Question 91<\/b><\/h3>\n<p><b>Which control is designed to identify and block malicious email attachments?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Email security gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An email security gateway can inspect incoming and outgoing email for malicious attachments, suspicious links, spam, phishing indicators, and other threats. Depending on its capabilities, it may use signatures, reputation information, sandboxing, content inspection, or behavioral analysis. Blocking dangerous attachments can prevent malware from reaching users&#8217; inboxes. However, attackers continually modify their techniques, so email security should be combined with endpoint protection, user awareness, multifactor authentication, and monitoring. Analysts should investigate suspicious messages and examine related indicators when malicious email is identified.<\/span><\/p>\n<h3><b>Question 92<\/b><\/h3>\n<p><b>Which type of evidence is most volatile and should generally be collected quickly during an investigation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Archived backups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RAM contents<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Printed reports<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Stored documents<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">RAM contents are considered highly volatile evidence because information stored in memory can disappear when a system is powered off or restarted. Memory may contain running processes, network connections, encryption keys, malicious code, credentials, and other information that may not be available on disk. During appropriate forensic investigations, analysts may capture memory before performing actions that could destroy volatile evidence. Evidence collection should follow established procedures and legal or organizational requirements. Investigators should balance evidence preservation with containment and safety considerations during active incidents.<\/span><\/p>\n<h3><b>Question 93<\/b><\/h3>\n<p><b>Which security process identifies weaknesses by simulating an attack against an organization?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Penetration testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log aggregation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset tagging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Penetration testing simulates authorized attacks against systems, applications, networks, or other defined targets to identify exploitable weaknesses. Testers may attempt techniques similar to those used by real attackers, subject to the agreed scope and rules of engagement. The results can reveal vulnerabilities, ineffective controls, attack paths, and potential business impacts. Penetration testing differs from vulnerability scanning because it generally goes beyond identifying potential weaknesses and attempts controlled exploitation. Testing should always have explicit authorization and clearly defined boundaries to avoid unintended disruption.<\/span><\/p>\n<h3><b>Question 94<\/b><\/h3>\n<p><b>Which security control helps detect unauthorized changes to system configurations?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configuration monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network translation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Configuration monitoring compares current system settings against approved configurations or baselines and can identify unauthorized or unexpected changes. Analysts can monitor settings such as security policies, services, firewall rules, user privileges, and system parameters. Unexpected configuration changes may indicate administrative errors, configuration drift, or malicious activity. Monitoring tools can generate alerts when important settings change. Security teams should establish clear baselines and investigate deviations based on their risk. Regular configuration monitoring complements vulnerability scanning and helps maintain consistent security standards across systems.<\/span><\/p>\n<h3><b>Question 95<\/b><\/h3>\n<p><b>What does a security information and event management system primarily analyze?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security events and logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Employee salaries<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hardware warranties<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Building temperature<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Security Information and Event Management (SIEM) system collects, centralizes, and analyzes security-related events from multiple sources. These may include authentication systems, endpoints, servers, firewalls, applications, cloud services, and network devices. SIEM platforms can correlate events, generate alerts, support investigations, and provide dashboards or reports. Effective SIEM operations depend on collecting relevant logs, maintaining appropriate retention, and tuning detection rules. Analysts should also ensure that important security events are not lost among excessive low-value alerts or poorly configured data sources.<\/span><\/p>\n<h3><b>Question 96<\/b><\/h3>\n<p><b>Which attack uses a compromised legitimate account to access protected resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Account takeover<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DDoS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Buffer overflow<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Account takeover occurs when an attacker gains unauthorized control of a legitimate user account. Attackers may obtain credentials through phishing, credential stuffing, malware, password reuse, or other methods. Once an account is compromised, the attacker may attempt to access sensitive information, move laterally, establish persistence, or perform actions under the legitimate user&#8217;s identity. Analysts should investigate unusual login locations, devices, authentication methods, privilege changes, and unexpected account activity. Multifactor authentication and strong identity monitoring can significantly reduce the risk associated with stolen credentials.<\/span><\/p>\n<h3><b>Question 97<\/b><\/h3>\n<p><b>Which technique can hide malicious communication inside DNS requests?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS tunneling<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password spraying<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shoulder surfing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DNS tunneling uses DNS queries and responses to transmit information or establish communication through DNS infrastructure. Attackers may use this technique for command-and-control communication or data exfiltration because DNS traffic is commonly allowed in network environments. Analysts can investigate unusually long or frequently changing DNS queries, suspicious domains, high volumes of requests, and encoded-looking subdomains. DNS tunneling can be difficult to detect using simple rules, so security teams may combine DNS monitoring with endpoint and network telemetry. Threat intelligence can also help identify suspicious domains.<\/span><\/p>\n<h3><b>Question 98<\/b><\/h3>\n<p><b>Which practice helps ensure incident evidence remains trustworthy?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Maintaining chain of custody<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deleting duplicate logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sharing passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling timestamps<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Chain of custody documents how evidence is collected, handled, transferred, stored, and accessed throughout an investigation. Maintaining this record helps demonstrate that evidence was not improperly altered or mishandled. Investigators should document who collected evidence, when it was collected, where it was stored, and who subsequently accessed it. Appropriate hashing and secure storage can provide additional integrity assurance. Chain-of-custody procedures are particularly important when evidence may be used for legal, regulatory, disciplinary, or formal investigative purposes.<\/span><\/p>\n<h3><b>Question 99<\/b><\/h3>\n<p><b>Which security control can identify unauthorized wireless access points?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Wireless intrusion detection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File integrity monitor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Database scanner<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Wireless intrusion detection systems can monitor wireless environments for unauthorized or suspicious access points, clients, and wireless activity. An unauthorized access point may create a security risk by providing an unmanaged pathway into an organization&#8217;s network. Analysts can investigate the device&#8217;s location, configuration, connected clients, and network behavior. Wireless monitoring can also help identify rogue devices, suspicious wireless attacks, or policy violations. Organizations should maintain an inventory of approved wireless infrastructure so security teams can distinguish legitimate access points from unexpected devices.<\/span><\/p>\n<h3><b>Question 100<\/b><\/h3>\n<p><b>Which incident response document describes actions to take for a specific type of incident?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incident response playbook<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset inventory<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network diagram<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability report<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An incident response playbook provides structured instructions for handling a particular type of security incident. A playbook may define detection criteria, investigation steps, containment actions, communication requirements, evidence collection, escalation procedures, and recovery tasks. Examples include playbooks for phishing, ransomware, compromised accounts, or malware infections. Playbooks help analysts respond consistently and reduce delays during incidents. They should be tested through exercises and updated when technologies, threats, responsibilities, or organizational procedures change. Clear playbooks also help less experienced responders follow established processes during high-pressure situations.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CompTIA CS0-003 Exam Dumps and Practice Test Dumps. &nbsp; Question 81 Which technology can automatically isolate a compromised endpoint from the network? SIEM SOAR EDR DNS Correct Answer: 3 Explanation Endpoint Detection and Response (EDR) solutions provide visibility into endpoint activity and can support response actions such as isolating a compromised device from [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14082"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=14082"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14082\/revisions"}],"predecessor-version":[{"id":14155,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14082\/revisions\/14155"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=14082"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=14082"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=14082"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}