{"id":14091,"date":"2026-09-16T12:44:59","date_gmt":"2026-09-16T12:44:59","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=14091"},"modified":"2026-09-16T12:44:59","modified_gmt":"2026-09-16T12:44:59","slug":"comptia-cysa-cs0-003-practice-test-questions-and-exam-dumps-part14-q261-280","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-cysa-cs0-003-practice-test-questions-and-exam-dumps-part14-q261-280\/","title":{"rendered":"CompTIA CYSA+ CS0-003 Practice Test Questions and Exam Dumps Part14 Q261-280"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cs0-003-exam-dumps\"><b>CompTIA CS0-003 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 261<\/b><\/h3>\n<p><b>Which security tool is designed to detect and block malicious network traffic in real time?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Proxy server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IDS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Intrusion Prevention System, or IPS, monitors network traffic and can automatically block or prevent malicious activity based on configured detection rules. Unlike an IDS, which primarily detects and alerts on suspicious traffic, an IPS is positioned to take preventive action. A SIEM collects and correlates security events, while a proxy server intermediates network connections and may enforce access policies. IPS technology can help stop known attack patterns, exploit attempts, and other malicious traffic before it reaches protected systems.<\/span><\/p>\n<h3><b>Question 262<\/b><\/h3>\n<p><b>What is the primary purpose of asset inventory?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identify and track organizational assets<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encrypt sensitive files<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Analyze malware behavior<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Prevent phishing emails<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Asset inventory provides an organization with an accurate record of its hardware, software, cloud resources, applications, and other technology assets. Security teams need this visibility to determine which systems require monitoring, patching, vulnerability assessment, and security controls. Unknown or unmanaged assets can introduce significant risk because they may be exposed without appropriate protection. Asset inventory does not directly encrypt files, analyze malware, or prevent phishing. Maintaining accurate inventory information also helps organizations understand ownership, business purpose, location, and criticality of systems.<\/span><\/p>\n<h3><b>Question 263<\/b><\/h3>\n<p><b>An analyst discovers that an account has suddenly received administrative privileges. What should be investigated first?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network bandwidth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privilege escalation activity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backup compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS caching<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Unexpected administrative privileges can indicate privilege escalation, unauthorized account modification, or misuse of an existing administrative account. The analyst should examine identity and access logs, account changes, authentication activity, administrative actions, and the reason for the privilege assignment. If the change was unauthorized, the account may have been compromised or an attacker may have gained elevated permissions. Network bandwidth and DNS caching are generally unrelated to privilege changes. Prompt investigation is important because elevated privileges can allow attackers to modify systems, access sensitive information, or establish persistence.<\/span><\/p>\n<h3><b>Question 264<\/b><\/h3>\n<p><b>Which protocol is commonly used to securely administer a remote Linux server?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Telnet<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SSH<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HTTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">SSH, or Secure Shell, provides encrypted remote access and administration for systems such as Linux servers. It protects authentication credentials and session data while allowing administrators to execute commands remotely. Telnet also provides remote access but transmits information without strong encryption and is therefore unsuitable for secure administration. FTP is primarily used for file transfers, while HTTP is designed for web communication. Security teams should also monitor SSH activity for unusual login attempts, unfamiliar source addresses, brute-force attacks, and unexpected administrative sessions.<\/span><\/p>\n<h3><b>Question 265<\/b><\/h3>\n<p><b>Which indicator may suggest that a system is communicating with a command-and-control server?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Repeated connections to a suspicious external domain<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A successful local backup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A normal software update<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A routine printer connection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Repeated connections to a suspicious external domain can indicate communication with command-and-control infrastructure. Analysts should examine the destination, connection frequency, DNS activity, network protocol, timing, and associated processes on the endpoint. Command-and-control communication may allow attackers to issue instructions, maintain persistence, or transfer information. A legitimate software update or normal printer connection may also generate network traffic but should be evaluated within its expected context. Correlating network and endpoint telemetry helps determine whether suspicious outbound communication is actually malicious.<\/span><\/p>\n<h3><b>Question 266<\/b><\/h3>\n<p><b>Which technique is commonly used to discover open ports and services on a target system?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File hashing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log normalization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Port scanning is used to identify open ports and potentially determine which network services are accessible on a system. Security professionals may use authorized scanning during vulnerability assessments and penetration tests to identify unnecessary or exposed services. Attackers can also perform port scanning during reconnaissance to identify potential entry points. File hashing verifies data integrity, data classification categorizes information, and log normalization standardizes collected events. Organizations should monitor unauthorized scanning because unexpected reconnaissance activity may indicate preparation for a later attack.<\/span><\/p>\n<h3><b>Question 267<\/b><\/h3>\n<p><b>Which process helps ensure that security controls continue to work as intended?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Control validation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data deletion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password sharing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Control validation involves testing security controls to determine whether they continue to function as expected. Organizations may validate firewall rules, detection mechanisms, access controls, endpoint protections, backups, and other security measures. Validation can identify configuration errors, ineffective rules, expired controls, or gaps caused by environmental changes. Simply deploying a security control does not guarantee that it remains effective over time. Regular testing and validation help security teams confirm that controls provide the expected protection and identify areas requiring adjustment or improvement.<\/span><\/p>\n<h3><b>Question 268<\/b><\/h3>\n<p><b>What is the primary purpose of a proxy server in security monitoring?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Synchronize system clocks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Inspect and control web traffic<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Store password hashes<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace endpoint protection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A proxy server acts as an intermediary between clients and external services and can provide visibility and control over web traffic. Security teams may use proxy logs to investigate requested URLs, source users, destination domains, timestamps, and other information. Proxies can also enforce access policies, filter websites, and help detect suspicious communication. A proxy does not replace endpoint protection or synchronize system clocks. When investigating possible malware or data exfiltration, analysts can correlate proxy activity with DNS, firewall, and endpoint telemetry.<\/span><\/p>\n<h3><b>Question 269<\/b><\/h3>\n<p><b>Which attack attempts to make a database execute unintended SQL commands?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CSRF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">XSS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SSRF<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">SQL injection occurs when an application improperly incorporates untrusted input into database queries, allowing attackers to manipulate the intended SQL commands. Successful exploitation can potentially expose, modify, or delete database information and may sometimes enable further compromise. Secure coding techniques such as parameterized queries and prepared statements help prevent SQL injection. XSS targets browser-side script execution, CSRF abuses a user&#8217;s authenticated session, and SSRF causes a server to make unintended requests. Web application logs and WAF alerts can provide useful evidence when investigating suspected SQL injection attempts.<\/span><\/p>\n<h3><b>Question 270<\/b><\/h3>\n<p><b>Which activity is part of the preparation phase of incident response?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Restoring compromised systems<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Removing malware<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Creating response procedures<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Investigating attacker infrastructure<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The preparation phase occurs before a security incident and focuses on ensuring that an organization is ready to respond effectively. Activities can include creating incident response plans, developing playbooks, assigning responsibilities, training personnel, configuring monitoring tools, and ensuring required forensic and response resources are available. Restoring systems belongs primarily to recovery, while removing malware is associated with eradication. Investigating attacker infrastructure generally occurs during incident analysis. Strong preparation can reduce response delays and help security teams handle incidents consistently.<\/span><\/p>\n<h3><b>Question 271<\/b><\/h3>\n<p><b>Which type of analysis examines a suspicious file by executing it in a controlled environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Source-code review<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hash analysis<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Dynamic analysis involves executing a suspicious file in a controlled environment and observing its behavior. Analysts may monitor processes, file modifications, registry changes, network connections, system calls, and other activities generated during execution. Sandboxes are commonly used to isolate malware while collecting this information. Static analysis examines a file without executing it, while hash analysis primarily provides an identifier for comparison. Dynamic analysis can reveal behaviors that may not be obvious from inspecting a file&#8217;s structure alone, making it useful for malware investigations.<\/span><\/p>\n<h3><b>Question 272<\/b><\/h3>\n<p><b>Which security measure reduces the risk of unauthorized access if a password is stolen?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Multifactor authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log rotation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Multifactor authentication adds another verification requirement beyond a password, reducing the likelihood that stolen credentials alone will provide access. Depending on the implementation, the additional factor may be a hardware security key, authenticator application, biometric factor, or another approved method. MFA is not an absolute guarantee against compromise because attackers may use phishing, session theft, or social engineering to bypass or abuse authentication mechanisms. Nevertheless, properly implemented MFA significantly strengthens account security compared with password-only authentication.<\/span><\/p>\n<h3><b>Question 273<\/b><\/h3>\n<p><b>What does a false negative represent in security detection?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A legitimate event incorrectly marked malicious<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A malicious event incorrectly missed<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A duplicate alert<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A successfully blocked attack<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A false negative occurs when malicious activity is present but a security control fails to detect it. False negatives are particularly concerning because attackers may remain undetected while continuing their activities. A false positive is the opposite situation, where legitimate activity is incorrectly identified as malicious. Security teams can reduce false negatives by improving detection logic, adding telemetry, tuning thresholds, threat hunting, and regularly validating controls. Analysts should balance detection sensitivity with operational requirements because overly aggressive rules can increase false positives and alert fatigue.<\/span><\/p>\n<h3><b>Question 274<\/b><\/h3>\n<p><b>Which control is most useful for identifying unauthorized data transfers through email?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data Loss Prevention can monitor email communications for sensitive information and apply organizational policies to unauthorized transfers. DLP systems may inspect message content, attachments, recipients, classifications, and other attributes to identify potential data leakage. Depending on policy, an organization may block, quarantine, alert on, or log a suspicious message. NTP handles time synchronization, NAC controls network access, and DHCP provides network configuration. Email-focused DLP is particularly useful for reducing accidental or intentional disclosure of confidential information through corporate messaging systems.<\/span><\/p>\n<h3><b>Question 275<\/b><\/h3>\n<p><b>Which threat intelligence activity involves collecting, processing, analyzing, and distributing relevant intelligence?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Intelligence lifecycle<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Patch management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File recovery<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The threat intelligence lifecycle describes the process organizations use to turn collected information into useful intelligence. Common stages include planning or requirements, collection, processing, analysis, dissemination, and feedback. The goal is to provide relevant information that supports security decisions and detection activities. Patch management focuses on updating vulnerable software, network segmentation separates systems, and file recovery restores information after loss. A well-managed intelligence lifecycle helps ensure that intelligence is relevant, timely, actionable, and aligned with the organization&#8217;s security requirements.<\/span><\/p>\n<h3><b>Question 276<\/b><\/h3>\n<p><b>Which vulnerability occurs when an attacker causes a server to make unintended requests to another system?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">XSS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SSRF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CSRF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Server-Side Request Forgery, or SSRF, occurs when an attacker manipulates a vulnerable server into making requests to unintended destinations. Depending on the environment, an attacker may attempt to access internal services, cloud metadata endpoints, or other resources that are not directly accessible from the internet. SSRF defenses can include strict URL validation, allowlists, network restrictions, and limiting the privileges available to application components. XSS targets browser execution, CSRF abuses authenticated user sessions, and SQL injection targets database queries.<\/span><\/p>\n<h3><b>Question 277<\/b><\/h3>\n<p><b>Which log source is most useful for investigating repeated failed login attempts?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authentication logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Printer logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Temperature logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backup logs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Authentication logs record events related to user sign-ins, including successful and failed authentication attempts, usernames, source addresses, timestamps, and authentication methods. Analysts can use these records to identify brute-force attempts, password spraying, unusual login locations, and compromised accounts. Authentication data can also be correlated with endpoint and network information to determine whether suspicious access was successful. Printer, temperature, and backup logs generally do not provide the detailed identity information required to investigate repeated login failures.<\/span><\/p>\n<h3><b>Question 278<\/b><\/h3>\n<p><b>What is the primary purpose of a vulnerability remediation plan?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increase the number of vulnerabilities<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Define how identified weaknesses will be addressed<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable vulnerability scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove asset inventories<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A vulnerability remediation plan defines how identified security weaknesses will be addressed. It may include the responsible team, remediation method, priority, target completion date, affected assets, validation requirements, and escalation procedures. Plans help organizations track vulnerabilities from identification through resolution and verification. Remediation can involve patching software, changing configurations, replacing unsupported systems, implementing compensating controls, or removing unnecessary services. Disabling scanning or removing asset inventories would reduce visibility rather than address the underlying weaknesses.<\/span><\/p>\n<h3><b>Question 279<\/b><\/h3>\n<p><b>Which activity is an example of reconnaissance?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encrypting a backup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Restoring a server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Gathering information about exposed services<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Removing malware<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Reconnaissance involves gathering information about a target before or during an attack. An attacker may identify domains, IP addresses, open ports, exposed services, technologies, employees, or other publicly available information. This information can help determine potential attack paths. Security professionals may also perform authorized reconnaissance during assessments to identify exposures from an attacker&#8217;s perspective. Encrypting backups, restoring systems, and removing malware are defensive or recovery activities rather than reconnaissance. Monitoring unexpected reconnaissance can help organizations identify potential early-stage attack activity.<\/span><\/p>\n<h3><b>Question 280<\/b><\/h3>\n<p><b>Which security control provides a second layer of protection when another control fails?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data normalization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log deletion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential sharing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Defense in depth uses multiple complementary security controls so that the failure or bypass of one control does not automatically result in complete compromise. An organization may combine network segmentation, endpoint protection, identity controls, firewalls, monitoring, encryption, and application security measures. Each layer provides a different opportunity to prevent, detect, or limit an attack. This approach reduces dependence on a single security mechanism. Data normalization improves log consistency, while log deletion and credential sharing weaken security rather than providing additional defensive layers.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CompTIA CS0-003 Exam Dumps and Practice Test Dumps. &nbsp; Question 261 Which security tool is designed to detect and block malicious network traffic in real time? Proxy server IDS IPS SIEM Correct Answer: 4 Explanation An Intrusion Prevention System, or IPS, monitors network traffic and can automatically block or prevent malicious activity based [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14091"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=14091"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14091\/revisions"}],"predecessor-version":[{"id":14146,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14091\/revisions\/14146"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=14091"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=14091"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=14091"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}