{"id":14096,"date":"2026-09-16T12:44:09","date_gmt":"2026-09-16T12:44:09","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=14096"},"modified":"2026-09-16T12:44:09","modified_gmt":"2026-09-16T12:44:09","slug":"comptia-cysa-cs0-003-practice-test-questions-and-exam-dumps-part19-q361-380","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-cysa-cs0-003-practice-test-questions-and-exam-dumps-part19-q361-380\/","title":{"rendered":"CompTIA CYSA+ CS0-003 Practice Test Questions and Exam Dumps Part19 Q361-380"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cs0-003-exam-dumps\"><b>CompTIA CS0-003 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 361<\/b><\/h3>\n<p><b>Which technology analyzes endpoint activity to detect and respond to suspicious behavior?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EDR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint Detection and Response (EDR) continuously monitors endpoint activity such as processes, files, network connections, and user actions. It can identify suspicious behavior, generate alerts, collect investigation data, and support response actions such as isolating an affected endpoint. EDR is useful for detecting malware, credential theft, persistence, and other endpoint-based attacks. DHCP assigns network configuration information, NAT translates addresses, and FTP provides file transfer functionality. EDR provides security-focused visibility and response capabilities directly on endpoints, making it valuable for both detection and incident investigation.<\/span><\/p>\n<h3><b>Question 362<\/b><\/h3>\n<p><b>Which log source is most useful for investigating suspicious web requests to an application?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web server logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP logs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Web server logs record requests made to web applications and commonly contain information such as source IP addresses, requested URLs, HTTP methods, status codes, timestamps, and user agents. Analysts can use this information to investigate attacks such as SQL injection, directory traversal, command injection, and unusual authentication activity. DNS logs focus on domain resolution, DHCP logs record address assignments, and NTP logs relate to time synchronization. Web server logs therefore provide detailed visibility into requests reaching web applications and are an important source for application security investigations.<\/span><\/p>\n<h3><b>Question 363<\/b><\/h3>\n<p><b>A security analyst wants to identify systems communicating with a suspicious domain. Which data should be reviewed first?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset inventory<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS query logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File permissions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DNS query logs can show which systems requested resolution for a particular domain. When investigating a suspicious domain, analysts can search DNS records for the domain name and identify source devices, timestamps, query frequency, and potentially related domains. This information can help determine which endpoints may have interacted with malicious infrastructure. Password policies and file permissions provide useful security information but do not directly reveal DNS requests. Asset inventory can identify systems within the environment, but DNS logs provide the actual evidence of domain-resolution activity.<\/span><\/p>\n<h3><b>Question 364<\/b><\/h3>\n<p><b>Which access control model uses attributes such as location, device type, and time of day?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RBAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ABAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MAC<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Attribute-Based Access Control (ABAC) makes authorization decisions using attributes associated with users, resources, actions, and environmental conditions. Examples include a user&#8217;s department, device security status, geographic location, or time of access. ABAC can therefore create detailed policies such as allowing access only from managed devices during approved hours. RBAC primarily uses predefined roles, DAC gives resource owners significant control over permissions, and MAC uses centrally enforced security classifications. ABAC is particularly useful when organizations need flexible access decisions based on multiple contextual conditions.<\/span><\/p>\n<h3><b>Question 365<\/b><\/h3>\n<p><b>Which activity is an example of reconnaissance?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deleting security logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Enumerating publicly available information about a target<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encrypting stolen files<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Installing persistence mechanisms<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Reconnaissance involves gathering information about a target before or during an attack. Attackers may collect publicly available information about domains, employees, technologies, IP addresses, organizational structure, and exposed services. This information can help identify potential attack paths. Deleting security logs is an anti-forensic activity, encrypting stolen files may be associated with ransomware or data theft, and installing persistence is used to maintain access. Security teams can also perform authorized reconnaissance to understand their own attack surface and identify publicly exposed information that could assist attackers.<\/span><\/p>\n<h3><b>Question 366<\/b><\/h3>\n<p><b>Which security control can block known malicious web domains before users connect to them?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File hashing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Memory acquisition<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Patch management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DNS filtering can block or redirect requests for known malicious, phishing, or otherwise prohibited domains. When a user attempts to access a blocked domain, the DNS security service can prevent the domain from resolving to its intended destination or provide a controlled response. This can stop some malicious connections before a user reaches the website. File hashing verifies file integrity, memory acquisition collects volatile forensic evidence, and patch management addresses software vulnerabilities. DNS filtering is therefore a useful preventive control for reducing exposure to known malicious web infrastructure.<\/span><\/p>\n<h3><b>Question 367<\/b><\/h3>\n<p><b>What does CVSS primarily provide?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A vulnerability severity score<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A malware signature<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A network encryption key<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">An incident response procedure<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Common Vulnerability Scoring System (CVSS) provides a standardized method for expressing the severity of vulnerabilities. It considers characteristics such as attack complexity, required privileges, user interaction, scope, and potential impact. Security teams can use CVSS scores as one factor when prioritizing vulnerabilities for remediation. A CVSS score does not itself identify malware, provide encryption keys, or define incident response procedures. Organizations should also consider business context, asset criticality, exploit availability, and exposure because technical severity alone does not determine the complete risk to an organization.<\/span><\/p>\n<h3><b>Question 368<\/b><\/h3>\n<p><b>An analyst notices a user authenticating from two distant locations within a few minutes. What should be investigated?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Impossible travel<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Patch status<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File integrity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Impossible travel is an authentication anomaly in which a user appears to log in from geographically distant locations within a timeframe that would make physical travel between them unrealistic. This can indicate stolen credentials, VPN use, cloud proxy services, or other unusual circumstances. Analysts should investigate the source IP addresses, authentication methods, device information, timestamps, and user activity before determining whether the event is malicious. Data classification, patch status, and file integrity address different security concerns. Impossible-travel detection is particularly useful for identifying potentially compromised accounts.<\/span><\/p>\n<h3><b>Question 369<\/b><\/h3>\n<p><b>Which technique attempts to guess many passwords against one account?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential stuffing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password spraying<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Brute force<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Session hijacking<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A brute-force attack attempts many password combinations against a particular account or authentication service. The attacker may systematically try different characters, words, or combinations until a valid password is discovered. Credential stuffing uses previously compromised credentials, while password spraying typically tests a small number of common passwords against many different accounts to avoid account lockouts. Session hijacking involves taking control of an authenticated session rather than guessing passwords. Account lockout policies, MFA, rate limiting, and monitoring for repeated authentication failures can help reduce brute-force attacks.<\/span><\/p>\n<h3><b>Question 370<\/b><\/h3>\n<p><b>Which activity should occur before an organization deploys a major security control change?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Delete old logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assess potential impact<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove asset inventory<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Before deploying a major security control change, organizations should assess potential impact to understand how the change may affect systems, users, applications, and business operations. Testing in a controlled environment can help identify unexpected consequences before production deployment. This approach reduces the possibility that a security improvement will unintentionally cause outages or disable legitimate functionality. Deleting logs, disabling monitoring, or removing asset inventory would reduce visibility and increase operational risk. Change assessment and controlled testing are important parts of effective security and configuration management.<\/span><\/p>\n<h3><b>Question 371<\/b><\/h3>\n<p><b>Which type of malware encrypts files and demands payment for their recovery?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rootkit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Spyware<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ransomware<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Adware<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Ransomware is malware designed to deny access to systems or data, commonly by encrypting files and demanding payment from victims. Modern ransomware incidents may also involve data theft before encryption, creating additional pressure on victims. Rootkits are designed to maintain stealth or privileged access, spyware collects information, and adware primarily displays unwanted advertising. Security teams can reduce ransomware impact through endpoint protection, network segmentation, least privilege, secure backups, patching, application control, and effective incident response procedures.<\/span><\/p>\n<h3><b>Question 372<\/b><\/h3>\n<p><b>Which backup characteristic is most important for recovering from ransomware?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backups are isolated from normal user access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backups use the same administrator account<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backups are stored only on the infected server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backups are never tested<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Backups should be protected from unauthorized modification or deletion so ransomware cannot easily encrypt or destroy them. Isolated, offline, immutable, or otherwise access-controlled backups can provide stronger protection against ransomware attacks. If backups are accessible using the same compromised administrative credentials, attackers may be able to destroy them as part of the attack. Storing backups only on the infected server also creates a single point of failure. Regular restoration testing is important because an untested backup may not provide reliable recovery when an actual incident occurs.<\/span><\/p>\n<h3><b>Question 373<\/b><\/h3>\n<p><b>Which technology can detect suspicious wireless devices or unauthorized access points?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">WIDS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">WAF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Wireless Intrusion Detection System (WIDS) monitors wireless networks for suspicious activity, unauthorized access points, rogue devices, and potentially malicious wireless behavior. It can help security teams identify devices that should not be operating within the organization&#8217;s wireless environment. DLP focuses on protecting sensitive information, WAF protects web applications, and SIEM aggregates and correlates security events from many sources. WIDS is particularly valuable in environments where unauthorized wireless infrastructure could provide attackers with an alternative path into the organization or expose users to malicious wireless activity.<\/span><\/p>\n<h3><b>Question 374<\/b><\/h3>\n<p><b>What is the purpose of a security playbook?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Store employee passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Define repeatable response actions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace vulnerability scanners<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encrypt all databases<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A security playbook provides documented, repeatable procedures for responding to specific security events. It can define investigation steps, containment actions, communication requirements, escalation paths, evidence collection procedures, and recovery tasks. For example, an organization may maintain separate playbooks for phishing, ransomware, compromised accounts, or malware infections. Playbooks help analysts respond consistently and reduce uncertainty during stressful incidents. They do not replace vulnerability scanners or provide universal encryption. Well-maintained playbooks can also be updated after incidents and exercises to reflect lessons learned and improve response efficiency.<\/span><\/p>\n<h3><b>Question 375<\/b><\/h3>\n<p><b>Which security principle requires users to receive only the permissions necessary for their duties?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separation of duties<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Non-repudiation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least privilege requires users, applications, and systems to receive only the permissions necessary to perform their authorized tasks. Limiting privileges reduces the potential damage caused by compromised accounts, malicious insiders, or software vulnerabilities. For example, a standard employee should not automatically receive administrator privileges if those permissions are unnecessary for their role. Separation of duties divides sensitive responsibilities among multiple individuals, defense in depth uses multiple layers of security controls, and non-repudiation supports accountability. Least privilege is therefore directly focused on minimizing unnecessary access rights.<\/span><\/p>\n<h3><b>Question 376<\/b><\/h3>\n<p><b>A company discovers that an attacker deleted logs after compromising a server. What behavior should analysts investigate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anti-forensic activity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Deleting or modifying security logs after gaining access can be considered anti-forensic behavior because it attempts to remove or obscure evidence of malicious activity. Attackers may clear event logs, modify timestamps, delete files, or otherwise manipulate evidence to make investigation more difficult. Analysts should examine remaining logs from centralized systems, SIEM platforms, network devices, and other sources to reconstruct events. Data classification organizes information, vulnerability scanning identifies weaknesses, and network segmentation separates network zones. Detecting anti-forensic activity can provide an important clue that an attacker attempted to conceal their actions.<\/span><\/p>\n<h3><b>Question 377<\/b><\/h3>\n<p><b>Which analysis method executes suspicious malware in a controlled environment to observe its behavior?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hash analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log normalization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Dynamic malware analysis involves executing suspicious software in a controlled environment, such as a sandbox, and observing its behavior. Analysts can monitor processes, file changes, registry activity, network connections, system calls, and other actions to understand what the malware does. Static analysis examines malware without executing it, often by inspecting strings, metadata, code, or file structure. Hash analysis compares file fingerprints, while log normalization standardizes security events. Dynamic analysis is particularly useful when analysts need behavioral evidence about an unknown or suspicious executable.<\/span><\/p>\n<h3><b>Question 378<\/b><\/h3>\n<p><b>Which cloud access practice best supports least privilege?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Granting every employee administrator access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Using role-based permissions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sharing one administrative account<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling authentication logging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Role-based permissions can support least privilege by assigning users only the access required for their responsibilities. In cloud environments, roles can be designed around specific tasks and services rather than providing broad administrative privileges. Sharing an administrative account reduces accountability and increases the potential impact of credential compromise. Granting everyone administrator access violates least privilege, while disabling authentication logging reduces visibility into account activity. Cloud IAM systems should also use MFA, periodic access reviews, and temporary elevated permissions where appropriate to further reduce unnecessary access.<\/span><\/p>\n<h3><b>Question 379<\/b><\/h3>\n<p><b>Which indicator is most useful for identifying a specific malicious file?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File hash<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Screen resolution<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CPU model<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Keyboard language<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A file hash can serve as an indicator associated with a specific file because the hash is calculated from the file&#8217;s contents. Security teams can compare observed hashes against threat intelligence feeds, malware repositories, or internally identified malicious files. A matching hash can provide strong evidence that the same file has appeared elsewhere, although attackers can modify files to produce different hashes. Hardware characteristics such as CPU model and screen resolution do not uniquely identify malicious files. File hashes are therefore widely used as indicators of compromise during malware investigations.<\/span><\/p>\n<h3><b>Question 380<\/b><\/h3>\n<p><b>Which step should follow successful remediation of a vulnerability?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable all security monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Validate that the vulnerability is resolved<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Delete the remediation records<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove the affected asset from inventory<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">After remediation, security teams should validate that the vulnerability has actually been resolved. Validation may involve rescanning the affected system, reviewing the installed software version, checking configuration settings, or performing another approved verification method. Simply applying a patch or changing a configuration does not guarantee that the underlying issue has been corrected. Disabling monitoring or deleting records would reduce visibility and accountability, while removing an asset from inventory would create inaccurate asset information. Remediation validation provides evidence that the intended security improvement has been successfully implemented.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CompTIA CS0-003 Exam Dumps and Practice Test Dumps. &nbsp; Question 361 Which technology analyzes endpoint activity to detect and respond to suspicious behavior? EDR DHCP NAT FTP Correct Answer: 1 Explanation Endpoint Detection and Response (EDR) continuously monitors endpoint activity such as processes, files, network connections, and user actions. It can identify suspicious [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14096"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=14096"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14096\/revisions"}],"predecessor-version":[{"id":14141,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/14096\/revisions\/14141"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=14096"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=14096"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=14096"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}