{"id":14083,"date":"2026-09-16T12:46:50","date_gmt":"2026-09-16T12:46:50","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=14083"},"modified":"2026-09-16T12:46:50","modified_gmt":"2026-09-16T12:46:50","slug":"comptia-cysa-cs0-003-practice-test-questions-and-exam-dumps-part6-q101-120","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-cysa-cs0-003-practice-test-questions-and-exam-dumps-part6-q101-120\/","title":{"rendered":"CompTIA CYSA+ CS0-003 Practice Test Questions and Exam Dumps Part6 Q101-120"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cs0-003-exam-dumps\"><b>CompTIA CS0-003 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 101<\/b><\/h3>\n<p><b>Which technology is commonly used to collect and correlate security logs from multiple systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">WAF<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Security Information and Event Management (SIEM) platform collects security events and logs from multiple sources and correlates them to identify suspicious activity. Common sources include firewalls, servers, endpoints, authentication systems, applications, and cloud services. Correlation allows analysts to connect separate events that may represent one attack sequence. SIEM platforms can also support alerting, dashboards, investigations, and reporting. Proper configuration is important because excessive irrelevant logs can create alert fatigue, while missing important sources can leave significant visibility gaps.<\/span><\/p>\n<h3><b>Question 102<\/b><\/h3>\n<p><b>What is the primary purpose of network segmentation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increase bandwidth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Limit unauthorized movement between network areas<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace antivirus software<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Eliminate authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network segmentation divides a network into separate logical or physical areas and controls communication between them. This limits an attacker&#8217;s ability to move laterally after compromising one system. For example, sensitive servers can be separated from user workstations and only required traffic can be permitted between the segments. Segmentation can also reduce the impact of malware outbreaks and improve monitoring. Security teams should regularly review segmentation rules because overly broad access can weaken its effectiveness and unnecessarily expose protected systems to other network zones.<\/span><\/p>\n<h3><b>Question 103<\/b><\/h3>\n<p><b>Which indicator is most useful for identifying a suspicious file across multiple systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MAC address<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hostname<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File hash<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Subnet mask<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A file hash is a fixed-length value generated from the contents of a file using a hashing algorithm. Security analysts can use hashes as indicators of compromise to identify known malicious files across multiple systems. If the same malicious file appears on several endpoints, its hash can help security tools locate it quickly. However, hashes can change when malware is modified, so analysts should combine them with other indicators such as domains, IP addresses, filenames, behavioral indicators, and process activity when investigating suspicious files.<\/span><\/p>\n<h3><b>Question 104<\/b><\/h3>\n<p><b>A user receives an email requesting an urgent password reset through an unfamiliar link. What should the analyst suspect first?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Phishing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DDoS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS poisoning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port scanning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An unexpected email requesting an urgent password reset through an unfamiliar link is a common phishing indicator. Attackers often create a sense of urgency to persuade users to click malicious links or disclose credentials. Analysts should inspect the sender address, email headers, linked domain, message content, and authentication results. The suspicious URL should not be opened directly from the user&#8217;s workstation. If the message is confirmed as malicious, security teams may block related domains, search for other recipients, remove the message, and investigate whether any credentials were submitted.<\/span><\/p>\n<h3><b>Question 105<\/b><\/h3>\n<p><b>Which metric measures the average time required to detect a security incident?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MTTR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MTTC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RPO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MTTD<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Mean Time to Detect (MTTD) measures the average time between the occurrence of a security event and its detection by the security team or monitoring systems. A lower MTTD generally indicates that suspicious activity is being identified more quickly. Analysts can use this metric to evaluate monitoring and detection capabilities over time. MTTD differs from Mean Time to Respond or Mean Time to Recover, which measure later stages of incident handling. Accurate timestamps and consistent measurement methods are necessary for meaningful MTTD calculations.<\/span><\/p>\n<h3><b>Question 106<\/b><\/h3>\n<p><b>Which technique involves testing an application without executing its code?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sandboxing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Behavioral monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Static analysis examines software, source code, binaries, or other artifacts without executing the program. Security professionals can use static analysis to identify suspicious strings, embedded commands, insecure coding patterns, known indicators, and other characteristics. It is commonly used during malware analysis and secure software development. Dynamic analysis differs because it observes software while it is executing in a controlled environment. Static analysis can be performed safely without running potentially malicious code, although sophisticated threats may hide important behavior that becomes visible only during execution.<\/span><\/p>\n<h3><b>Question 107<\/b><\/h3>\n<p><b>Which vulnerability identifier provides a standardized reference for a publicly known software vulnerability?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CVE<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CVSS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CWE<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Common Vulnerabilities and Exposures (CVE) system provides standardized identifiers for publicly known cybersecurity vulnerabilities. A CVE identifier allows security teams, vendors, researchers, and vulnerability-management platforms to refer to the same vulnerability consistently. CVE itself does not determine how severe a vulnerability is. Severity can be assessed using systems such as the Common Vulnerability Scoring System (CVSS). Analysts often use CVE information together with affected software versions, exploit availability, asset importance, and business context when prioritizing remediation.<\/span><\/p>\n<h3><b>Question 108<\/b><\/h3>\n<p><b>Which authentication method requires users to provide two or more different types of evidence?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single sign-on<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Multifactor authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password synchronization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Account federation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Multifactor authentication (MFA) requires users to provide authentication factors from different categories, such as something they know, something they have, or something they are. For example, a password combined with a hardware token or biometric factor provides multiple forms of verification. MFA can significantly reduce the risk of account compromise when passwords are stolen. However, implementation should consider phishing-resistant methods and appropriate recovery procedures. MFA is an authentication control and does not eliminate the need for authorization, monitoring, or least-privilege access.<\/span><\/p>\n<h3><b>Question 109<\/b><\/h3>\n<p><b>What is the primary purpose of a sandbox in malware analysis?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To increase storage capacity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To permanently remove malware<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To safely observe suspicious behavior<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To replace network monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A sandbox provides an isolated environment where suspicious files or programs can be executed and observed without exposing production systems to the same level of risk. Analysts can monitor processes, file changes, registry activity, network connections, and other behaviors. Sandboxing is particularly useful for analyzing malware whose behavior cannot be determined through static inspection alone. The environment should be carefully isolated because sophisticated malware may attempt to detect virtualized or sandboxed conditions. Results can be combined with other indicators to support incident investigation and detection development.<\/span><\/p>\n<h3><b>Question 110<\/b><\/h3>\n<p><b>Which attack attempts to overwhelm a service with excessive traffic or requests?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential stuffing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DDoS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privilege escalation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Distributed Denial-of-Service (DDoS) attack attempts to make a service unavailable by overwhelming it with large amounts of traffic or requests. Distributed attacks commonly use many compromised systems or other sources to generate traffic simultaneously. Security teams can use traffic filtering, rate limiting, content delivery networks, DDoS protection services, and network monitoring to reduce the impact. During an investigation, analysts should examine traffic patterns, source distribution, targeted services, and timing. The objective is generally service disruption rather than directly stealing information.<\/span><\/p>\n<h3><b>Question 111<\/b><\/h3>\n<p><b>Which control is designed to prevent users from executing unauthorized applications?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application allowlisting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network address translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet fragmentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application allowlisting permits only approved applications or software components to execute on a system. This can prevent unauthorized or malicious programs from running even when an attacker attempts to introduce them onto an endpoint. Allowlisting can be especially useful for systems with predictable workloads, such as servers or dedicated business devices. Security teams must maintain accurate application inventories and update policies when legitimate software changes. Poorly maintained allowlists can block necessary applications or create administrative overhead, so regular review is important.<\/span><\/p>\n<h3><b>Question 112<\/b><\/h3>\n<p><b>Which log source is most useful for investigating repeated failed login attempts?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authentication logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Printer logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP lease logs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Authentication logs record events related to user sign-ins, including successful and failed authentication attempts. Analysts can review these logs to identify repeated failures that may indicate brute-force attacks, password spraying, credential misuse, or legitimate user errors. Useful details include usernames, source addresses, timestamps, authentication methods, and targeted systems. Correlating authentication events across multiple systems can reveal broader attack patterns. Analysts should also consider normal user behavior and expected administrative activity before determining whether repeated failures represent malicious activity.<\/span><\/p>\n<h3><b>Question 113<\/b><\/h3>\n<p><b>What is the main purpose of a vulnerability scan?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identify potentially vulnerable systems and software<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Restore deleted files<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encrypt network traffic<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Create user accounts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A vulnerability scan identifies systems, applications, services, and configurations that may contain known security weaknesses. Scanners compare observed software versions and configurations against vulnerability databases and predefined checks. Results can help security teams prioritize systems for further investigation and remediation. Vulnerability scans do not necessarily prove that a vulnerability can be successfully exploited, so important findings may require manual validation or penetration testing. Regular scanning supports vulnerability-management programs by helping organizations discover changes and newly introduced weaknesses across their environments.<\/span><\/p>\n<h3><b>Question 114<\/b><\/h3>\n<p><b>Which security principle gives users only the permissions required for their job?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Fail-open<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The principle of least privilege ensures that users, applications, and services receive only the permissions necessary to perform their authorized tasks. Limiting privileges reduces the potential impact of compromised accounts, malicious insiders, and vulnerable applications. For example, a standard employee should not automatically receive administrative access to servers they do not manage. Security teams should periodically review permissions because responsibilities change and excessive privileges can accumulate over time. Least privilege should be applied across operating systems, applications, cloud environments, databases, and other resources.<\/span><\/p>\n<h3><b>Question 115<\/b><\/h3>\n<p><b>Which technology can inspect and filter HTTP or HTTPS application traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">WAF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPN<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Web Application Firewall (WAF) monitors and filters HTTP or HTTPS traffic directed toward web applications. It can help detect and block attacks such as SQL injection, cross-site scripting, malicious requests, and certain application-layer abuse patterns. WAF rules may be based on request content, headers, URLs, parameters, or known attack patterns. A WAF should complement secure application development rather than replace it. Analysts should monitor WAF alerts and tune rules carefully because overly broad rules can generate false positives and interfere with legitimate application traffic.<\/span><\/p>\n<h3><b>Question 116<\/b><\/h3>\n<p><b>What does a false positive represent in security monitoring?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A real attack that was missed<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A legitimate event incorrectly identified as malicious<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A confirmed security incident<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A successful vulnerability exploit<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A false positive occurs when a security monitoring system identifies legitimate activity as suspicious or malicious. For example, a normal administrative process might trigger an alert because its behavior resembles a known attack pattern. Excessive false positives can cause alert fatigue and reduce analyst efficiency. Security teams can reduce them by tuning detection rules, improving baselines, adding contextual information, and creating appropriate exceptions. However, tuning should be performed carefully because excessively broad exclusions may hide genuine malicious activity and increase the risk of false negatives.<\/span><\/p>\n<h3><b>Question 117<\/b><\/h3>\n<p><b>Which action is part of the containment phase of incident response?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Writing the final report<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Conducting a lessons-learned meeting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Isolating an infected system<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rebuilding all unaffected systems<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Containment focuses on limiting the spread and impact of an active security incident. Isolating an infected endpoint from the network is a common containment action because it can prevent malware from communicating with external systems or spreading to additional internal devices. Other containment measures may include blocking malicious domains, disabling compromised accounts, or restricting affected network segments. Containment should be performed according to the organization&#8217;s incident response procedures and business requirements. Analysts must balance rapid threat reduction with preserving evidence and maintaining essential operations.<\/span><\/p>\n<h3><b>Question 118<\/b><\/h3>\n<p><b>Which protocol securely transfers files over an encrypted SSH connection?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SFTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TFTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Telnet<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secure File Transfer Protocol (SFTP) provides file transfer capabilities over an SSH connection, offering encryption and authentication for the communication session. This helps protect files and credentials from interception while they are transferred across untrusted networks. SFTP should not be confused with FTPS, which uses TLS to secure FTP connections. Security teams should select secure transfer protocols based on organizational requirements and ensure that authentication and access permissions are properly configured. Monitoring file transfers can also help identify unauthorized movement of sensitive information.<\/span><\/p>\n<h3><b>Question 119<\/b><\/h3>\n<p><b>Which threat intelligence type focuses on attacker methods, tactics, and procedures?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Strategic intelligence<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Operational intelligence<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tactical intelligence<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Financial intelligence<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Tactical threat intelligence focuses on the techniques, tactics, and procedures used by threat actors. Security teams can use this information to improve detection rules, threat-hunting hypotheses, defensive controls, and incident investigations. Examples include information about credential attacks, persistence methods, lateral movement, or command-and-control techniques. Strategic intelligence generally addresses broader trends and risks for decision-makers, while operational intelligence focuses on information about specific campaigns or operations. Effective threat intelligence should be relevant to the organization&#8217;s environment and translated into actionable defensive measures.<\/span><\/p>\n<h3><b>Question 120<\/b><\/h3>\n<p><b>Which activity should occur after an incident has been resolved to improve future response?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling all monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Conducting a lessons-learned review<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Removing security controls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deleting incident records<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A lessons-learned review is performed after an incident to identify what worked well, what failed, and what improvements are needed. Security teams may review detection speed, communication, containment actions, evidence handling, technical controls, and response procedures. Findings can lead to updated playbooks, improved monitoring rules, additional training, or changes to security architecture. Incident records should be preserved according to organizational and regulatory requirements. The goal is to use experience from completed incidents to strengthen future prevention, detection, response, and recovery activities.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CompTIA CS0-003 Exam Dumps and Practice Test Dumps. &nbsp; Question 101 Which technology is commonly used to collect and correlate security logs from multiple systems? SIEM VPN NAC WAF Correct Answer: 1 Explanation A Security Information and Event Management (SIEM) platform collects security events and logs from multiple sources and correlates them to [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14083"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=14083"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14083\/revisions"}],"predecessor-version":[{"id":14154,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14083\/revisions\/14154"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=14083"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=14083"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=14083"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}