CS0-003 Sample Questions

CS0-003 Sample Questions & Answers

Analyzing malicious activity within system and network architecture carries the most weight, alongside vulnerability scanning and prioritization, attack-methodology frameworks and incident handling, and reporting on vulnerabilities and incidents.

Launch the full CS0-003 simulator →

Showing 15 of 30 free samples.

  1. Question 1Intermediate

    A security analyst is tasked with prioritizing vulnerabilities for remediation. The relevant company security policies are shown below:Security Policy 1006: Vulnerability Management1. The Company shall use the CVSSv3.1 Base Score Metrics (Exploitability and Impact) to prioritize the remediation of security vulnerabilities.2. In situations where a choice must be made between confidentiality and availability, the Company shall prioritize confidentiality of data over availability of systems and data.3. The Company shall prioritize patching of publicly available systems and services over patching of internally available system.According to the security policy, which of the following vulnerabilities should be the highest priority to patch?

    Show answer & explanation

    Correct answer: C

  2. Question 2Intermediate

    Which of the following will most likely ensure that mission-critical services are available in the event of an incident?

    Show answer & explanation

    Correct answer: B

  3. Question 3Intermediate

    The Chief Information Security Officer wants to eliminate and reduce shadow IT in the enterprise. Several high-risk cloud applications are used that increase the risk to the organization. Which of the following solutions will assist in reducing the risk?

    Show answer & explanation

    Correct answer: D

  4. Question 4Intermediate

    Security Operations · System and Network Architecture

    A security analyst is reviewing a new cloud architecture proposal that utilizes a dedicated secure access layer to connect users to applications. The architecture combines SD-WAN capabilities with comprehensive security functions such as SWG, CASB, FWaaS, and ZTNA, delivered primarily as a service. Which of the following terms BEST describes this architecture?

    graph LR User[Remote User] -->|Encrypted Tunnel| Edge[Cloud Edge] Branch[Branch Office] -->|SD-WAN| Edge subgraph SASE_Cloud [Security Cloud] Edge --> FWaaS Edge --> CASB Edge --> DLP Edge --> ZTNA end ZTNA --> SaaS[SaaS Apps] ZTNA --> IaaS[IaaS/PaaS] FWaaS --> Internet
    Show answer & explanation

    Correct answer: A

    Secure Access Service Edge (SASE) is a network architecture that combines WAN capabilities (like SD-WAN) with comprehensive cloud-native security functions (SWG, CASB, FWaaS, ZTNA) to support dynamic, secure access needs. The diagram illustrates users connecting to a unified cloud edge that applies security policies before granting access to resources.

  5. Question 5Intermediate

    Vulnerability Management · Analysis of Vulnerability Assessment Output

    During a vulnerability scan analysis, an analyst identifies a critical finding on a legacy server. The vulnerability allows remote code execution (RCE) but requires the attacker to have an existing low-privileged user account on the system. The server is located in a segmented VLAN with no direct internet access. When calculating the CVSS v3.1 score to prioritize this vulnerability, which Attack Vector (AV) metric should be selected?

    Show answer & explanation

    Correct answer: A

    The Attack Vector (AV) is 'Network' (N) because the vulnerability is exploitable remotely over the network (the VLAN). Even though the server is internal and requires a user account (which affects Privileges Required, not Attack Vector), the technical means of exploitation is the network stack. 'Local' would imply the attacker needs physical access or a shell.

  6. Question 6Intermediate

    Incident Response Management · Threat Detection and Analysis

    A SOC analyst is investigating a suspicious process on a Windows endpoint. The process svchost.exe is initiating outbound connections to an external IP address on port 4444. The analyst runs Get-Process in PowerShell and notices the process has no parent ID link to services.exe and is running from C:\Temp. Which phase of the Cyber Kill Chain is MOST likely being observed?

    Show answer & explanation

    Correct answer: A

    The scenario describes an active malware implant (masquerading as svchost.exe) communicating externally on a non-standard port (4444). This outbound communication to receive instructions or exfiltrate data is the definition of the Command and Control (C2) phase. The file location (Temp) and parent process mismatch confirm it is not a legitimate service.

  7. Question 7Beginner

    Reporting and Communication · Metrics and KPIs

    An organization is preparing its quarterly executive security report. The CISO requests a metric that best communicates the efficiency of the security team in neutralizing confirmed threats once they are detected. Which of the following KPIs should be highlighted?

    Show answer & explanation

    Correct answer: B

    Mean Time to Respond (MTTR) measures the average time it takes to control, remediate, or eradicate a threat after it has been detected. This is the primary metric for efficiency in neutralizing threats. MTTD focuses on the time before detection.

  8. Question 8Intermediate

    Security Operations · Automation and Scripting

    A security analyst is writing a Python script to parse a large volume of JSON logs from a web application firewall. The goal is to identify IP addresses that have triggered more than 100 SQL injection alerts in the last hour. Which of the following logical structures would be MOST appropriate for this task?

    Show answer & explanation

    Correct answer: B

    Using a dictionary (hash map) is the most efficient way to count occurrences of IP addresses. The script would iterate through the logs, incrementing the count for each IP found in an SQLi alert, and then filter for counts > 100. Arrays or lists are less efficient for lookups and counting unique items.

  9. Question 9Intermediate

    Vulnerability Management · Application Security

    A company is adopting a DevSecOps model. The security team wants to implement a control that automatically checks for hardcoded credentials in the source code before it can be merged into the main branch. Which type of tool should be integrated into the CI/CD pipeline?

    Show answer & explanation

    Correct answer: C

    SAST analyzes source code at rest (white-box testing) to identify vulnerabilities, including hardcoded secrets, coding errors, and insecure configurations. It is ideal for pre-merge checks in a CI/CD pipeline. DAST requires a running application.

  10. Question 10Advanced

    Security Operations · Malicious Activity Indicators

    While analyzing a PCAP file from a suspected data exfiltration incident, an analyst observes the following sequence of packets:

    1. Client sends SYN to Server Port 443
    2. Server sends SYN-ACK to Client
    3. Client sends ACK to Server
    4. Client sends TLS Client Hello
    5. Server sends TLS Server Hello
    6. Client sends 15GB of UDP traffic to Server Port 53

    What is the MOST likely technique being used for exfiltration?

    Show answer & explanation

    Correct answer: D

    The initial TCP handshake and TLS setup appear normal, but the sudden shift to massive UDP traffic on Port 53 (DNS) indicates the attacker likely established a secure channel for command and control or checking, but then used DNS tunneling (UDP 53) to move the actual bulk data, likely to bypass firewall rules that inspect HTTPS but allow DNS queries.

Ready for the real thing?

The full CS0-003 simulator has every exam-style question, timed mode, and instant scoring.