{"id":14090,"date":"2026-09-16T12:45:11","date_gmt":"2026-09-16T12:45:11","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=14090"},"modified":"2026-09-16T12:45:11","modified_gmt":"2026-09-16T12:45:11","slug":"comptia-cysa-cs0-003-practice-test-questions-and-exam-dumps-part13-q241-260","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-cysa-cs0-003-practice-test-questions-and-exam-dumps-part13-q241-260\/","title":{"rendered":"CompTIA CYSA+ CS0-003 Practice Test Questions and Exam Dumps Part13 Q241-260"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cs0-003-exam-dumps\"><b>CompTIA CS0-003 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 241<\/b><\/h3>\n<p><b>Which technology can automatically execute predefined actions in response to security alerts?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SOAR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RAID<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security Orchestration, Automation, and Response, or SOAR, can automate predefined actions in response to security alerts and incidents. A SOAR platform can integrate with security tools and execute workflows such as blocking an IP address, disabling an account, collecting additional information, or creating an incident ticket. Automation can reduce repetitive manual work and improve response speed. DHCP assigns network addresses, FTP transfers files, and RAID provides storage redundancy. SOAR is especially useful when organizations need consistent responses to frequent and well-understood security events.<\/span><\/p>\n<h3><b>Question 242<\/b><\/h3>\n<p><b>What is the primary purpose of vulnerability scanning?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Recover deleted files<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identify known security weaknesses<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encrypt network traffic<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Monitor employee attendance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Vulnerability scanning is used to identify known security weaknesses in systems, applications, devices, and network services. Scanners can detect outdated software, missing patches, insecure configurations, exposed services, and vulnerabilities associated with known identifiers. The results help security teams determine which issues require further investigation or remediation. Vulnerability scanning differs from penetration testing because a scanner generally identifies potential weaknesses automatically, while penetration testing involves controlled attempts to exploit weaknesses. Regular scanning helps organizations maintain visibility into their security posture as environments change.<\/span><\/p>\n<h3><b>Question 243<\/b><\/h3>\n<p><b>An analyst observes a process creating a suspicious executable and then launching it from a temporary directory. What should the analyst examine next?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CPU warranty information<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Monitor brightness settings<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Parent-child process relationships<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Printer configuration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Parent-child process relationships can reveal how suspicious processes were created and executed. An analyst should examine which process launched the suspicious executable, the command-line arguments used, the account involved, and the timing of the activity. Unusual relationships, such as an office application spawning a command shell or scripting engine, may indicate malicious execution. Endpoint telemetry can provide this information and help establish an attack chain. Hardware settings and printer configuration generally provide no useful context for determining how a suspicious process was launched.<\/span><\/p>\n<h3><b>Question 244<\/b><\/h3>\n<p><b>Which control helps prevent sensitive information from leaving an organization through unauthorized channels?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data Loss Prevention, or DLP, helps identify and prevent unauthorized transmission, copying, or exposure of sensitive information. DLP controls can monitor email, web uploads, removable media, cloud storage, and other data movement channels. Policies may identify sensitive information using classifications, patterns, keywords, or other detection methods. NTP synchronizes system time, NAT translates network addresses, and DHCP provides IP configuration. DLP is particularly valuable when organizations need to reduce the risk of accidental or intentional disclosure of confidential, financial, personal, or proprietary information.<\/span><\/p>\n<h3><b>Question 245<\/b><\/h3>\n<p><b>Which activity is most likely to reveal an attacker&#8217;s command-and-control infrastructure?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reviewing suspicious outbound connections<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Updating password policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Checking printer toner levels<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reviewing employee vacation records<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Reviewing suspicious outbound connections can help identify command-and-control infrastructure used by attackers to communicate with compromised systems. Analysts may examine destination IP addresses, domains, ports, connection frequency, timing, and traffic patterns. Connections to known malicious infrastructure or unusual external destinations can provide important indicators of compromise. Password policies and unrelated administrative information do not directly reveal command-and-control activity. Network traffic analysis, DNS logs, proxy logs, and endpoint telemetry can be correlated to strengthen the investigation and determine whether a system is communicating with attacker-controlled infrastructure.<\/span><\/p>\n<h3><b>Question 246<\/b><\/h3>\n<p><b>Which vulnerability allows an attacker to inject malicious commands into an operating system through an application?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CSRF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Command injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Clickjacking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Session fixation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Command injection occurs when an application improperly handles user-controlled input and allows an attacker to execute operating system commands. Successful exploitation can enable unauthorized actions using the privileges of the vulnerable application or account. Strong input validation, parameterized interfaces, secure coding practices, and appropriate privilege restrictions can help reduce this risk. CSRF abuses a user&#8217;s authenticated session, clickjacking tricks users into interacting with hidden or misleading interface elements, and session fixation targets session management. Analysts should investigate both the vulnerable application and any commands executed after exploitation.<\/span><\/p>\n<h3><b>Question 247<\/b><\/h3>\n<p><b>Which security assessment actively attempts to exploit vulnerabilities under controlled conditions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Penetration test<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log review<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset inventory<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configuration backup<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A penetration test is a controlled security assessment in which authorized testers attempt to exploit vulnerabilities to determine whether weaknesses can actually be abused. Penetration testing can provide evidence about attack paths, potential impact, and the effectiveness of existing controls. It should be performed under defined rules of engagement to establish scope, permitted techniques, systems, and testing limitations. Log reviews examine recorded events, asset inventories identify systems, and configuration backups preserve settings. Penetration testing complements vulnerability scanning by providing deeper validation of exploitable weaknesses.<\/span><\/p>\n<h3><b>Question 248<\/b><\/h3>\n<p><b>What is the primary purpose of network traffic baselining?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increase network bandwidth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Establish normal traffic patterns<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace endpoint security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove all firewall rules<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network traffic baselining establishes a picture of normal communication patterns within an environment. Analysts can examine factors such as common destinations, protocols, ports, traffic volumes, connection frequencies, and normal communication times. Once a baseline exists, significant deviations can be investigated as potential indicators of compromise, misconfiguration, or unusual activity. Baselining does not automatically prove that an anomaly is malicious because legitimate operational changes can also create deviations. It is therefore most effective when combined with other security telemetry and contextual analysis.<\/span><\/p>\n<h3><b>Question 249<\/b><\/h3>\n<p><b>Which type of malware is designed to conceal its presence by modifying or interfering with operating system functions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Worm<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Trojan<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rootkit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Adware<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A rootkit is malware designed to maintain privileged access while concealing its presence from users and security tools. Rootkits may manipulate operating system components, processes, files, or system information to hide malicious activity. Because they can operate at deep levels of the system, detecting them may require specialized endpoint analysis, integrity checks, memory forensics, or trusted offline tools. Worms primarily self-propagate across systems, Trojans disguise malicious functionality as legitimate software, and adware primarily displays unwanted advertisements. Rootkits are particularly concerning because they can support long-term persistence.<\/span><\/p>\n<h3><b>Question 250<\/b><\/h3>\n<p><b>Which factor should be considered when determining the business impact of a compromised server?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Keyboard layout<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Screen resolution<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset criticality<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mouse sensitivity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Asset criticality is an important factor when determining the business impact of a compromised server. A server supporting essential business operations, financial systems, customer services, or critical infrastructure may require faster response than a system with limited operational importance. Analysts should consider the data stored, services provided, dependencies, number of users affected, and potential consequences of downtime or compromise. Technical vulnerability severity alone may not accurately represent business risk. Combining technical findings with asset criticality allows security teams to prioritize incidents and remediation activities more effectively.<\/span><\/p>\n<h3><b>Question 251<\/b><\/h3>\n<p><b>Which method can help identify whether a suspicious file is associated with a known malware sample?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hash comparison<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Hash comparison can help determine whether a suspicious file matches a previously identified malware sample. Analysts can calculate a cryptographic hash of the file and compare it against trusted malware intelligence or internal records. A matching hash can provide a useful indicator that the file is known, although a different hash does not necessarily mean the file is safe because attackers can modify malware. Hashes are therefore one component of malware analysis. Additional evidence such as behavior, metadata, network activity, and file characteristics may also be required.<\/span><\/p>\n<h3><b>Question 252<\/b><\/h3>\n<p><b>Which cloud security practice helps identify unauthorized activity within cloud resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling audit logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reviewing cloud activity logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Removing access controls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sharing administrative accounts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud activity logs provide visibility into actions performed against cloud resources, such as authentication attempts, administrative changes, resource creation, configuration modifications, and API activity. Reviewing these logs can help identify unauthorized access and suspicious behavior. Security teams should monitor important cloud events and correlate them with identity, endpoint, and network telemetry when possible. Disabling audit logs or sharing administrative accounts reduces accountability and visibility. Cloud monitoring should also include appropriate retention, access protection, alerting, and time synchronization to support effective investigations.<\/span><\/p>\n<h3><b>Question 253<\/b><\/h3>\n<p><b>What is the main security benefit of multifactor authentication?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Eliminates all phishing attacks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Removes the need for passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Adds an additional authentication factor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Prevents every account compromise<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Multifactor authentication, or MFA, improves account security by requiring users to provide multiple authentication factors rather than relying on a single credential. Factors may include something the user knows, something the user has, or something the user is. MFA can reduce the impact of stolen passwords because an attacker may still need another authentication factor. However, MFA does not eliminate every account compromise, particularly when attackers use techniques such as session theft, MFA fatigue, or social engineering. Strong, phishing-resistant MFA provides additional protection against credential-based attacks.<\/span><\/p>\n<h3><b>Question 254<\/b><\/h3>\n<p><b>Which type of threat intelligence is most useful for identifying specific malicious IP addresses and file hashes?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Strategic<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tactical<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Technical<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Operational<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Technical threat intelligence focuses on specific technical indicators associated with malicious activity. Examples include IP addresses, domain names, URLs, file hashes, email addresses, and other indicators of compromise. Security teams can use these indicators in detection systems, SIEM rules, endpoint tools, firewalls, and other controls. Strategic intelligence generally addresses broader business-level trends and risks, while tactical intelligence often focuses on attacker techniques and procedures. Operational intelligence can provide information about active campaigns and adversary activities. Technical intelligence is therefore especially useful for direct detection and blocking.<\/span><\/p>\n<h3><b>Question 255<\/b><\/h3>\n<p><b>Which action is most appropriate when a confirmed compromised endpoint is actively communicating with an attacker?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increase its screen brightness<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Isolate the endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Delete all logs immediately<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable every security control<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Isolating a confirmed compromised endpoint can prevent continued communication with attacker infrastructure and reduce the risk of lateral movement or additional damage. Endpoint isolation should be performed according to the organization&#8217;s incident response procedures and with consideration for business impact. Security teams should preserve relevant evidence before taking actions that could destroy useful forensic information when circumstances permit. Deleting logs would remove valuable evidence, while disabling security controls would increase risk. Containment should limit the incident while allowing investigators to continue analyzing the compromised system appropriately.<\/span><\/p>\n<h3><b>Question 256<\/b><\/h3>\n<p><b>Which attack technique involves moving from one compromised system to another within a network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Lateral movement<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reconnaissance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exfiltration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Initial access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Lateral movement occurs when an attacker moves from one compromised system or account to additional systems within an environment. Attackers may use stolen credentials, remote services, administrative tools, or other techniques to expand their access. Detecting lateral movement often requires correlating authentication events, endpoint activity, network connections, and privilege changes. Reconnaissance generally involves gathering information before or during an attack, while exfiltration concerns unauthorized data transfer. Initial access describes techniques used to gain an initial foothold. Limiting privileges and segmenting networks can reduce lateral movement opportunities.<\/span><\/p>\n<h3><b>Question 257<\/b><\/h3>\n<p><b>Which control can restrict network access based on the security status of a connecting device?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RAID<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SMTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network Access Control, or NAC, can evaluate devices before or during network access and apply policies based on factors such as device identity, authentication status, security posture, or compliance state. An organization may require a device to have approved security software, current updates, or specific configuration settings before granting access. DNS resolves domain names, RAID provides storage redundancy, and SMTP is used for email transmission. NAC can help prevent unmanaged or noncompliant devices from gaining unrestricted access to sensitive network resources.<\/span><\/p>\n<h3><b>Question 258<\/b><\/h3>\n<p><b>What does the principle of separation of duties help prevent?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Excessive log retention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">One person controlling an entire sensitive process<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network congestion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Duplicate backups<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separation of duties divides sensitive responsibilities among multiple individuals so that one person does not have complete control over a critical process. For example, the person who approves a financial transaction may be different from the person who executes it. This reduces the risk of fraud, abuse, and unauthorized changes. Separation of duties differs from least privilege, which limits the permissions granted to an individual or system. Organizations may combine both principles to strengthen access control and reduce the likelihood that a single compromised account can perform an entire sensitive operation.<\/span><\/p>\n<h3><b>Question 259<\/b><\/h3>\n<p><b>Which web attack attempts to execute malicious script code in a victim&#8217;s browser?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SSRF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cross-site scripting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Directory traversal<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cross-site scripting, or XSS, occurs when an attacker causes malicious script content to execute in a victim&#8217;s web browser. Depending on the type and context, XSS may allow attackers to steal session information, manipulate web pages, or perform actions using the victim&#8217;s browser context. Input validation, output encoding, content security policies, and secure application development practices can help reduce XSS risk. SQL injection targets database queries, SSRF abuses server-side requests, and directory traversal attempts to access files outside an intended directory.<\/span><\/p>\n<h3><b>Question 260<\/b><\/h3>\n<p><b>Which recovery objective defines the maximum acceptable amount of data loss measured in time?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RTO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MTTR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MTTD<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RPO<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Recovery Point Objective, or RPO, defines the maximum acceptable amount of data loss measured in time. For example, an organization with an RPO of one hour should have recovery mechanisms capable of restoring data to a point no more than approximately one hour before an incident. RTO, or Recovery Time Objective, instead defines how quickly a service or system should be restored. MTTR measures the time associated with repair or recovery, while MTTD measures the time required to detect an incident. RPO is therefore closely connected to backup and replication strategies.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CompTIA CS0-003 Exam Dumps and Practice Test Dumps. &nbsp; Question 241 Which technology can automatically execute predefined actions in response to security alerts? SOAR DHCP FTP RAID Correct Answer: 4 Explanation Security Orchestration, Automation, and Response, or SOAR, can automate predefined actions in response to security alerts and incidents. A SOAR platform can [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14090"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=14090"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14090\/revisions"}],"predecessor-version":[{"id":14147,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14090\/revisions\/14147"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=14090"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=14090"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=14090"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}