CS0-003 Sample Questions & Answers
Analyzing malicious activity within system and network architecture carries the most weight, alongside vulnerability scanning and prioritization, attack-methodology frameworks and incident handling, and reporting on vulnerabilities and incidents.
Launch the full CS0-003 simulator →Showing 15 of 30 free samples.
- Question 1Intermediate
A security analyst is tasked with prioritizing vulnerabilities for remediation. The relevant company security policies are shown below:Security Policy 1006: Vulnerability Management1. The Company shall use the CVSSv3.1 Base Score Metrics (Exploitability and Impact) to prioritize the remediation of security vulnerabilities.2. In situations where a choice must be made between confidentiality and availability, the Company shall prioritize confidentiality of data over availability of systems and data.3. The Company shall prioritize patching of publicly available systems and services over patching of internally available system.According to the security policy, which of the following vulnerabilities should be the highest priority to patch?
Show answer & explanation
Correct answer: C
- Question 2Intermediate
Which of the following will most likely ensure that mission-critical services are available in the event of an incident?
Show answer & explanation
Correct answer: B
- Question 3Intermediate
The Chief Information Security Officer wants to eliminate and reduce shadow IT in the enterprise. Several high-risk cloud applications are used that increase the risk to the organization. Which of the following solutions will assist in reducing the risk?
Show answer & explanation
Correct answer: D
- Question 4Intermediate
Security Operations · System and Network Architecture
A security analyst is reviewing a new cloud architecture proposal that utilizes a dedicated secure access layer to connect users to applications. The architecture combines SD-WAN capabilities with comprehensive security functions such as SWG, CASB, FWaaS, and ZTNA, delivered primarily as a service. Which of the following terms BEST describes this architecture?
graph LR User[Remote User] -->|Encrypted Tunnel| Edge[Cloud Edge] Branch[Branch Office] -->|SD-WAN| Edge subgraph SASE_Cloud [Security Cloud] Edge --> FWaaS Edge --> CASB Edge --> DLP Edge --> ZTNA end ZTNA --> SaaS[SaaS Apps] ZTNA --> IaaS[IaaS/PaaS] FWaaS --> InternetShow answer & explanation
Correct answer: A
Secure Access Service Edge (SASE) is a network architecture that combines WAN capabilities (like SD-WAN) with comprehensive cloud-native security functions (SWG, CASB, FWaaS, ZTNA) to support dynamic, secure access needs. The diagram illustrates users connecting to a unified cloud edge that applies security policies before granting access to resources.
- Question 5Intermediate
Vulnerability Management · Analysis of Vulnerability Assessment Output
During a vulnerability scan analysis, an analyst identifies a critical finding on a legacy server. The vulnerability allows remote code execution (RCE) but requires the attacker to have an existing low-privileged user account on the system. The server is located in a segmented VLAN with no direct internet access. When calculating the CVSS v3.1 score to prioritize this vulnerability, which Attack Vector (AV) metric should be selected?
Show answer & explanation
Correct answer: A
The Attack Vector (AV) is 'Network' (N) because the vulnerability is exploitable remotely over the network (the VLAN). Even though the server is internal and requires a user account (which affects Privileges Required, not Attack Vector), the technical means of exploitation is the network stack. 'Local' would imply the attacker needs physical access or a shell.
- Question 6Intermediate
Incident Response Management · Threat Detection and Analysis
A SOC analyst is investigating a suspicious process on a Windows endpoint. The process
svchost.exeis initiating outbound connections to an external IP address on port 4444. The analyst runsGet-Processin PowerShell and notices the process has no parent ID link toservices.exeand is running fromC:\Temp. Which phase of the Cyber Kill Chain is MOST likely being observed?Show answer & explanation
Correct answer: A
The scenario describes an active malware implant (masquerading as svchost.exe) communicating externally on a non-standard port (4444). This outbound communication to receive instructions or exfiltrate data is the definition of the Command and Control (C2) phase. The file location (Temp) and parent process mismatch confirm it is not a legitimate service.
- Question 7Beginner
Reporting and Communication · Metrics and KPIs
An organization is preparing its quarterly executive security report. The CISO requests a metric that best communicates the efficiency of the security team in neutralizing confirmed threats once they are detected. Which of the following KPIs should be highlighted?
Show answer & explanation
Correct answer: B
Mean Time to Respond (MTTR) measures the average time it takes to control, remediate, or eradicate a threat after it has been detected. This is the primary metric for efficiency in neutralizing threats. MTTD focuses on the time before detection.
- Question 8Intermediate
Security Operations · Automation and Scripting
A security analyst is writing a Python script to parse a large volume of JSON logs from a web application firewall. The goal is to identify IP addresses that have triggered more than 100 SQL injection alerts in the last hour. Which of the following logical structures would be MOST appropriate for this task?
Show answer & explanation
Correct answer: B
Using a dictionary (hash map) is the most efficient way to count occurrences of IP addresses. The script would iterate through the logs, incrementing the count for each IP found in an SQLi alert, and then filter for counts > 100. Arrays or lists are less efficient for lookups and counting unique items.
- Question 9Intermediate
Vulnerability Management · Application Security
A company is adopting a DevSecOps model. The security team wants to implement a control that automatically checks for hardcoded credentials in the source code before it can be merged into the main branch. Which type of tool should be integrated into the CI/CD pipeline?
Show answer & explanation
Correct answer: C
SAST analyzes source code at rest (white-box testing) to identify vulnerabilities, including hardcoded secrets, coding errors, and insecure configurations. It is ideal for pre-merge checks in a CI/CD pipeline. DAST requires a running application.
- Question 10Advanced
Security Operations · Malicious Activity Indicators
While analyzing a PCAP file from a suspected data exfiltration incident, an analyst observes the following sequence of packets:
- Client sends SYN to Server Port 443
- Server sends SYN-ACK to Client
- Client sends ACK to Server
- Client sends TLS Client Hello
- Server sends TLS Server Hello
- Client sends 15GB of UDP traffic to Server Port 53
What is the MOST likely technique being used for exfiltration?
Show answer & explanation
Correct answer: D
The initial TCP handshake and TLS setup appear normal, but the sudden shift to massive UDP traffic on Port 53 (DNS) indicates the attacker likely established a secure channel for command and control or checking, but then used DNS tunneling (UDP 53) to move the actual bulk data, likely to bypass firewall rules that inspect HTTPS but allow DNS queries.
- Question 11Beginner
Vulnerability Management · Web Application Vulnerabilities
A security analyst is reviewing the logs of a web application and notices the following URL request:
https://example.com/search?query= alert(document.cookie)
Which vulnerability is the attacker attempting to exploit?Show answer & explanation
Correct answer: B
The payload
alert(document.cookie)is a classic test string for Cross-Site Scripting (XSS). The attacker is trying to inject malicious JavaScript into the application to execute in the victim's browser, potentially stealing session cookies. - Question 12Advanced
Incident Response Management · Containment Strategies
Which of the following containment strategies is MOST appropriate when a critical production database server is confirmed to be infected with ransomware, but the encryption process has not yet completed?
Show answer & explanation
Correct answer: D
Network isolation (segmentation) is the best immediate step. It stops the spread of the ransomware to other hosts and prevents the attacker from controlling the process, while keeping the server running (RAM intact) for forensic analysis. Powering off might trigger anti-forensic mechanisms or lose encryption keys in memory that could help decryption.
- Question 13IntermediateSelect 2
Security Operations · Cloud Security
Case Study: GlobalTech Corp has recently acquired a smaller startup. The startup uses a hybrid cloud environment with AWS and on-premise servers. During the integration, GlobalTech's security team discovers that the startup has no centralized logging and uses shared root accounts for AWS management.
Which of the following immediate actions should the security team prioritize to improve the security posture? (Select TWO)
Show answer & explanation
Correct answers: B, C
Lack of logging is a major visibility gap. Enabling CloudTrail ensures API activity is recorded, and centralizing logs allows for monitoring and incident response.
Securing root accounts is critical. Enabling MFA immediately mitigates the high risk of unauthorized access via shared credentials.
- Question 14Beginner
Security Operations · Zero Trust Architecture
True or False: In a Zero Trust Architecture, a user who has successfully authenticated via MFA to the VPN is automatically trusted to access all internal applications without further verification.
Show answer & explanation
Correct answer: B
False. Zero Trust operates on 'never trust, always verify'. Authentication at the perimeter (VPN) does not grant implicit trust for internal resources. Each access request is verified based on identity, device health, and context.
- Question 15Beginner
Vulnerability Management · Infrastructure Vulnerabilities
A security analyst is reviewing a vulnerability scan report for a fleet of IoT devices. The scan indicates that the devices are using a deprecated version of the SSH protocol (v1). Why is this considered a high-risk vulnerability?
Show answer & explanation
Correct answer: A
SSH v1 has known design flaws, including lack of integrity checks for data streams and support for weak encryption, making it vulnerable to insertion attacks and MitM.
Ready for the real thing?
The full CS0-003 simulator has every exam-style question, timed mode, and instant scoring.