{"id":14086,"date":"2026-09-16T12:46:10","date_gmt":"2026-09-16T12:46:10","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=14086"},"modified":"2026-09-16T12:46:10","modified_gmt":"2026-09-16T12:46:10","slug":"comptia-cysa-cs0-003-practice-test-questions-and-exam-dumps-part9-q161-180","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-cysa-cs0-003-practice-test-questions-and-exam-dumps-part9-q161-180\/","title":{"rendered":"CompTIA CYSA+ CS0-003 Practice Test Questions and Exam Dumps Part9 Q161-180"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cs0-003-exam-dumps\"><b>CompTIA CS0-003 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 161<\/b><\/h3>\n<p><b>Which security control can detect and block malicious network traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IDS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Intrusion Prevention System (IPS) monitors network traffic and can take automated action against traffic identified as malicious. Depending on its configuration, an IPS may block connections, drop packets, or otherwise prevent detected attacks. This differs from an Intrusion Detection System (IDS), which primarily detects and alerts on suspicious activity without automatically blocking it. IPS solutions can help defend against known exploits, malicious traffic patterns, and certain network attacks. Security teams should tune detection rules carefully to reduce false positives and avoid blocking legitimate business traffic.<\/span><\/p>\n<h3><b>Question 162<\/b><\/h3>\n<p><b>What is the main purpose of security log retention?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Preserve information for future investigation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increase processor speed<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Prevent phishing emails<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace endpoint protection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security log retention ensures that important event records remain available for a defined period so analysts can investigate incidents, identify historical activity, and satisfy organizational or regulatory requirements. Retained logs can help reconstruct attack timelines and determine whether suspicious activity occurred before an incident was detected. Organizations should establish retention periods based on business needs, legal requirements, storage capacity, and security objectives. Logs should also be protected against unauthorized modification or deletion because compromised or incomplete records can significantly reduce their usefulness during investigations.<\/span><\/p>\n<h3><b>Question 163<\/b><\/h3>\n<p><b>Which type of malware encrypts files and demands payment for recovery?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Spyware<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rootkit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ransomware<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Adware<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Ransomware is malware that commonly encrypts files or systems and demands payment in exchange for restoring access. Modern ransomware attacks may also involve data theft and threats to publish stolen information. Security teams can reduce ransomware risk through secure backups, endpoint protection, network segmentation, least privilege, patch management, and user awareness. During an incident, analysts should isolate affected systems quickly while following evidence-preservation procedures. Organizations should maintain tested backups because relying on attackers to restore access does not provide a dependable recovery strategy.<\/span><\/p>\n<h3><b>Question 164<\/b><\/h3>\n<p><b>Which access control model assigns permissions based on a user&#8217;s job function?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ABAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RBAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MAC<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Role-Based Access Control (RBAC) assigns permissions according to predefined roles associated with job responsibilities. For example, a database administrator may receive permissions needed to manage databases, while a standard employee receives only the access required for normal work. RBAC simplifies access management by allowing administrators to manage permissions through roles rather than individually configuring every user. Organizations should regularly review role assignments because outdated roles can result in excessive privileges. RBAC also supports least privilege when roles are designed carefully and permissions are appropriately limited.<\/span><\/p>\n<h3><b>Question 165<\/b><\/h3>\n<p><b>Which security activity identifies attack paths against an application before exploitation occurs?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data backup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Threat modeling<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log rotation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Account provisioning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Threat modeling identifies potential threats, attack paths, trust boundaries, and weaknesses during the design or development of a system. Security teams can analyze how an attacker might interact with an application, access sensitive information, bypass controls, or abuse legitimate functionality. Finding these risks early allows developers to implement safeguards before deployment. Threat modeling can support decisions involving authentication, authorization, encryption, input validation, and network architecture. It should be revisited when significant application functionality, architecture, or data flows change.<\/span><\/p>\n<h3><b>Question 166<\/b><\/h3>\n<p><b>Which log would be most useful when investigating suspicious outbound web requests from an employee workstation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Proxy log<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP log<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Printer log<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP log<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Proxy logs can provide valuable information about web requests made by systems and users. They may record destination domains, URLs, timestamps, source addresses, usernames, response codes, and transferred data volumes, depending on the organization&#8217;s configuration. Analysts can use this information to investigate connections to suspicious domains, malware command-and-control infrastructure, phishing sites, or unusual data transfers. Proxy logs become more useful when correlated with endpoint, DNS, authentication, and firewall data. Proper retention and accurate timestamps are important for reconstructing web-based activity during investigations.<\/span><\/p>\n<h3><b>Question 167<\/b><\/h3>\n<p><b>Which technique involves searching for attacker behavior that may not trigger existing alerts?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Threat hunting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Patch management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset disposal<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Threat hunting is a proactive process in which analysts search for suspicious or malicious activity that automated security controls may not have detected. Hunters may begin with a hypothesis based on threat intelligence, known attacker techniques, unusual behaviors, or previous incidents. They can examine endpoint telemetry, authentication events, DNS activity, network traffic, and other data sources. Successful hunting can reveal hidden threats and improve detection capabilities. Findings may lead to new alerts, updated monitoring rules, additional indicators, or changes to defensive controls.<\/span><\/p>\n<h3><b>Question 168<\/b><\/h3>\n<p><b>What is the primary purpose of network traffic baselining?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identify normal behavior for comparison<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable unused accounts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encrypt database files<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove vulnerabilities automatically<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network traffic baselining establishes a picture of normal network behavior so analysts can recognize significant deviations. A baseline may include typical traffic volumes, communication patterns, protocols, destinations, and usage times. Once normal behavior is understood, unusual activity such as unexpected outbound connections, large data transfers, or abnormal protocols can receive additional investigation. Baselines should account for legitimate changes such as business hours, seasonal activity, software updates, and new services. Poorly defined baselines can generate excessive alerts or fail to identify meaningful anomalies.<\/span><\/p>\n<h3><b>Question 169<\/b><\/h3>\n<p><b>Which attack technique attempts to obtain higher permissions than originally granted?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Persistence<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privilege escalation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reconnaissance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exfiltration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Privilege escalation occurs when an attacker gains permissions beyond those originally assigned to an account or process. It can be vertical, such as a standard user obtaining administrator privileges, or involve unauthorized access to another user&#8217;s resources. Attackers may exploit software vulnerabilities, misconfigurations, weak permissions, or stolen privileged credentials. Security teams can reduce this risk through least privilege, patching, application control, strong authentication, and endpoint monitoring. Analysts should investigate unexpected privilege changes, suspicious administrative activity, and processes running with higher privileges than expected.<\/span><\/p>\n<h3><b>Question 170<\/b><\/h3>\n<p><b>Which technology can identify suspicious behavior across multiple security data sources using user activity patterns?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">UEBA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RAID<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">User and Entity Behavior Analytics (UEBA) analyzes behavior associated with users and entities such as devices, applications, or service accounts. It can identify unusual activity by comparing current behavior with established patterns or baselines. Examples include unexpected login locations, unusual data access, abnormal administrative actions, or atypical resource usage. UEBA can help detect compromised accounts and insider-related risks that may not match simple signature-based rules. Analysts should investigate anomalies with additional context because unusual behavior is not automatically evidence of malicious activity.<\/span><\/p>\n<h3><b>Question 171<\/b><\/h3>\n<p><b>Which vulnerability occurs when an application trusts user input without proper validation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Input validation vulnerability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hardware failure<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Power interruption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backup failure<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Input validation vulnerabilities occur when applications accept untrusted user input without properly checking whether it is safe and appropriate. Attackers may exploit weak validation to manipulate application behavior or inject malicious content. Depending on the application, insufficient validation can contribute to SQL injection, command injection, cross-site scripting, or other attacks. Developers should validate input according to expected data types, formats, lengths, and allowed values. Security testing can help identify weak validation before deployment, while application monitoring can help detect suspicious requests after deployment.<\/span><\/p>\n<h3><b>Question 172<\/b><\/h3>\n<p><b>Which process prioritizes vulnerabilities based on risk and business impact?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password synchronization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Vulnerability management includes identifying, assessing, prioritizing, remediating, and validating security weaknesses. Prioritization should consider factors such as vulnerability severity, exploit availability, system exposure, asset importance, existing controls, and potential business impact. Treating every vulnerability identically can waste resources because some weaknesses present significantly greater risk than others. Security teams should establish clear remediation priorities and deadlines. After remediation, affected systems should be rescanned or otherwise validated to confirm that vulnerabilities have been addressed successfully.<\/span><\/p>\n<h3><b>Question 173<\/b><\/h3>\n<p><b>Which security mechanism verifies that a file has not changed unexpectedly?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hash comparison<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS forwarding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Hash comparison can help determine whether a file&#8217;s contents have changed. A cryptographic hash is calculated from the file, and the resulting value can be compared with a previously trusted hash. If the values differ, the file contents have changed. This technique is commonly used in file integrity monitoring, malware investigations, and forensic analysis. Hashes do not explain why a file changed or who changed it, so analysts need additional information such as timestamps, process activity, user accounts, and system logs to understand the event.<\/span><\/p>\n<h3><b>Question 174<\/b><\/h3>\n<p><b>Which control helps protect sensitive information from being sent through unauthorized channels?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data Loss Prevention (DLP) controls help identify and prevent unauthorized transmission of sensitive information. DLP policies can inspect data moving through email, web applications, endpoints, cloud services, or removable media, depending on the organization&#8217;s implementation. Policies may use data classifications, keywords, patterns, labels, or other identifiers to recognize protected information. Security teams can configure actions such as blocking, alerting, encrypting, or requiring approval. DLP should be carefully tuned because overly broad policies can interrupt legitimate business activities and create excessive alerts.<\/span><\/p>\n<h3><b>Question 175<\/b><\/h3>\n<p><b>Which attack attempts to trick a victim into revealing confidential information through deception?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Social engineering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet fragmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Social engineering manipulates people into performing actions or revealing information that benefits an attacker. Common examples include phishing, pretexting, impersonation, baiting, and fraudulent support requests. Attackers often use urgency, authority, fear, or familiarity to influence victims. Security awareness training can help users recognize suspicious requests, but technical controls such as MFA, email filtering, identity verification, and least privilege are also important. Analysts investigating social-engineering incidents should examine communication records, affected accounts, authentication events, and any sensitive information that may have been disclosed.<\/span><\/p>\n<h3><b>Question 176<\/b><\/h3>\n<p><b>Which security concept assumes that no user or device should automatically be trusted?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Zero Trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat networking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Implicit trust<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Zero Trust is a security approach based on continuously verifying users, devices, applications, and access requests rather than automatically trusting entities because they are inside a network. Access decisions can consider identity, device posture, location, resource sensitivity, and other contextual factors. Least privilege and segmentation are commonly used alongside Zero Trust principles. The goal is to limit unnecessary access and reduce the potential impact of compromised accounts or devices. Implementing Zero Trust generally involves multiple technologies and processes rather than a single security product.<\/span><\/p>\n<h3><b>Question 177<\/b><\/h3>\n<p><b>Which type of malware is designed to hide its presence by modifying or interacting with low-level system components?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rootkit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Adware<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Worm<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Spyware<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A rootkit is malware designed to conceal its presence and potentially maintain privileged access to a system. Rootkits may manipulate operating-system components, processes, files, or other low-level mechanisms to evade detection. Because they can operate deeply within a system, detecting them may require specialized tools and forensic techniques. Security teams can reduce rootkit risk through secure configurations, patching, endpoint protection, integrity monitoring, and restricted administrative access. If a rootkit is strongly suspected, organizations may need to consider rebuilding affected systems from trusted sources.<\/span><\/p>\n<h3><b>Question 178<\/b><\/h3>\n<p><b>Which metric measures how quickly a security team responds after detecting an incident?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MTTD<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MTTR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MTTA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RPO<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Mean Time to Acknowledge (MTTA) measures the average time between the generation or detection of an alert and the point when the security team acknowledges it and begins handling the event. A lower MTTA can indicate that alerts are being reviewed promptly. Organizations can improve MTTA through effective alert routing, staffing, prioritization, automation, and well-defined escalation procedures. MTTA differs from MTTD, which measures how long it takes to detect an event, and MTTR, which generally measures the time required to resolve or recover from an incident.<\/span><\/p>\n<h3><b>Question 179<\/b><\/h3>\n<p><b>Which protocol is commonly used to securely administer a remote Linux server?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Telnet<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SSH<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HTTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secure Shell (SSH) provides encrypted remote administration and command-line access to systems. It protects authentication credentials and session data from being transmitted in plaintext across the network. SSH can use passwords, public-key authentication, or other authentication mechanisms depending on configuration. Security teams should restrict SSH access to authorized users, disable unnecessary authentication methods, use strong keys or credentials, and monitor login activity. Limiting exposure through firewalls or network segmentation can further reduce the attack surface of remote administration services.<\/span><\/p>\n<h3><b>Question 180<\/b><\/h3>\n<p><b>Which phase of incident response focuses on restoring systems to normal operation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Recovery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Preparation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Containment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The recovery phase focuses on restoring affected systems and services to normal operation after the threat has been contained and removed. Activities may include rebuilding systems, restoring clean backups, validating security controls, monitoring restored assets, and gradually returning services to production. Recovery should be performed carefully to ensure that attackers no longer have access and that vulnerabilities exploited during the incident have been addressed. Teams should document recovery actions and monitor systems afterward because reinfection or recurring unauthorized activity may indicate incomplete eradication.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CompTIA CS0-003 Exam Dumps and Practice Test Dumps. &nbsp; Question 161 Which security control can detect and block malicious network traffic? DHCP NTP IDS IPS Correct Answer: 4 Explanation An Intrusion Prevention System (IPS) monitors network traffic and can take automated action against traffic identified as malicious. Depending on its configuration, an IPS [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14086"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=14086"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14086\/revisions"}],"predecessor-version":[{"id":14151,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14086\/revisions\/14151"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=14086"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=14086"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=14086"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}