COMPTIA CYSA+ (CS0-003) EXAM 2026–2027 | LATEST
PRACTICE QUESTIONS WITH CORRECT DETAILED
ANSWERS, PBQS & COMPREHENSIVE RATIONALES
1. An incident response team is actively handling a security incident. Following the principles of
the NIST SP 800-61, which of the following activities is MOST likely to be performed during the
"Containment, Eradication, and Recovery" phase?
a. Implementing a firewall rule to block traffic from known malicious IP addresses.
b. Interviewing the system administrator to understand the normal behavior of the network.
c. Documenting the timeline of events and actions taken during the incident.
d. Conducting a post-incident review meeting to identify lessons learned.
Correct Answer: a. Implementing a firewall rule to block traffic from known malicious IP
addresses.
Rationale: Blocking traffic from known malicious IP addresses is a classic containment strategy.
The containment phase focuses on isolating the incident to prevent it from spreading or causing
further damage. This is a critical and immediate action in incident response.
2. A cybersecurity analyst is looking to improve the security of a Linux web server. Which of the
following actions BEST aligns with the principle of least privilege?
a. Allowing all users to execute the sudo command to run any application.
b. Installing a comprehensive antivirus suite on the server.
c. Removing the sudo privilege from a group of users who do not require administrative rights.
d. Creating a single account for all developers to share when accessing the server.
Correct Answer: c. Removing the sudo privilege from a group of users who do not require
administrative rights.
Rationale: The principle of least privilege dictates that users, applications, and systems should
be granted only the permissions essential to perform their designated functions.
Removing sudo from non-admin users directly applies this principle, minimizing the attack
surface.
3. During a vulnerability assessment, a scanner identifies multiple systems running a legacy
version of the Apache web server, which is known to be vulnerable to a specific remote code
execution exploit. The risk is high, but the patch cannot be applied immediately due to
compatibility concerns with a critical business application. What is the MOST appropriate
compensating control in this scenario?
,a. Immediately shut down the web servers to prevent exploitation.
b. Implement a web application firewall (WAF) rule to block exploit attempts against the known
vulnerability.
c. Accept the risk and document the decision, as the business impact is minimal.
d. Upgrade all systems to the latest version of the web server, overriding compatibility concerns.
Correct Answer: b. Implement a web application firewall (WAF) rule to block exploit attempts
against the known vulnerability.
Rationale: When a vulnerability cannot be immediately patched, a compensating control is
necessary. A WAF can provide virtual patching by detecting and blocking attempts to exploit the
known vulnerability, reducing the risk until the patch can be applied.
4. Which of the following is an example of a "known plaintext" cryptographic attack?
a. The attacker intercepts encrypted passwords and uses them to authenticate to other systems.
b. The attacker has obtained several samples of encrypted data and the corresponding original
unencrypted data.
c. The attacker observes the power consumption of a CPU during encryption operations.
d. The attacker uses a precomputed table of hash values to reverse-engineer a password.
Correct Answer: b. The attacker has obtained several samples of encrypted data and the
corresponding original unencrypted data.
Rationale: In a known plaintext attack, the adversary possesses pairs of plaintext (unencrypted)
data and its corresponding ciphertext (encrypted) data. The goal is to use these pairs to deduce
the encryption key.
5. An organization has a Service Level Agreement (SLA) with a cloud provider that guarantees
99.99% uptime for a critical web application. This uptime guarantee is MOST accurately
described as a:
a. Service Level Objective (SLO)
b. Key Performance Indicator (KPI)
c. Business Impact Analysis (BIA)
d. Recovery Point Objective (RPO)
Correct Answer: a. Service Level Objective (SLO)
Rationale: A Service Level Objective (SLO) is a specific, measurable metric defined within an SLA,
such as the target uptime percentage. It represents the level of performance the provider is
expected to deliver.
6. After a security incident, the incident response team identifies that a web application is
vulnerable to a specific attack. To correct this vulnerability, they recommend a code change to
sanitize user inputs. This activity falls under which phase of the incident response lifecycle?
a. Detection and Analysis
,b. Containment, Eradication, and Recovery
c. Post-Incident Activity
d. Preparation
Correct Answer: b. Containment, Eradication, and Recovery
Rationale: Eradication is the phase where the cause of the incident is removed. By
recommending a code change to fix the vulnerability, the team is actively eradicating the root
cause of the incident.
7. A company is evaluating the risk of a potential vulnerability in its system. They determine that
the cost of implementing the safeguard is greater than the potential financial loss from a
successful attack. Based on this analysis, the company decides to take no action. This is an
example of which risk management principle?
a. Risk Mitigation
b. Risk Transference
c. Risk Avoidance
d. Risk Acceptance
Correct Answer: d. Risk Acceptance
Rationale: Risk acceptance involves acknowledging the risk and choosing not to implement a
control, typically because the cost of the control outweighs the potential impact of the risk. This
is a valid response when the risk is within the organization's risk appetite.
8. A security analyst is investigating a server and notices an entry in a user's bash history file
that shows the command unset HISTFILE. What is the MOST likely reason for this command
being run?
a. To set a new environment variable for a script.
b. To permanently delete all command history from the system.
c. To prevent the current terminal session's commands from being written to the history file.
d. To disable the command-line interface for the user.
Correct Answer: c. To prevent the current terminal session's commands from being written to
the history file.
Rationale: The unset HISTFILE command is a common technique used by attackers to cover their
tracks by preventing the current session's command history from being saved to the bash
history file.
9. An organization wants to implement a control to prevent a common attack against its
cryptographic systems. They decide to add a random value to each password before it is hashed.
This technique is known as:
a. Encryption
b. Salting
, c. Non-repudiation
d. Tokenization
Correct Answer: b. Salting
Rationale: Salting involves adding a random, unique value to a password before it is hashed.
This is a defense against rainbow table attacks, as it ensures that two identical passwords will
have different hashes.
10. A cybersecurity analyst is preparing a report for the executive team on a recent vulnerability.
The report should explain the potential business impact in terms of financial loss, reputational
damage, and regulatory fines, rather than just technical details. This type of reporting is MOST
associated with which domain?
a. Security Operations
b. Vulnerability Management
c. Incident Response
d. Reporting and Communication
Correct Answer: d. Reporting and Communication
Rationale: The Reporting and Communication domain, covering approximately 17% of the CS0-
003 exam, emphasizes the importance of communicating vulnerability and incident
management findings effectively to both technical and non-technical stakeholders, highlighting
business impact.
11. A security analyst is reviewing logs after a suspected security incident. The analyst is tasked
with determining the root cause and identifying lessons learned. This activity is part of the:
a. Incident Response lifecycle, specifically the "Containment, Eradication, and Recovery" phase.
b. Post-Incident Activity phase, which includes lessons learned meetings.
c. Vulnerability Management process, focusing on reporting.
d. Preparation phase, which involves planning for future incidents.
Correct Answer: b. Post-Incident Activity phase, which includes lessons learned meetings.
Rationale: The post-incident activity phase is crucial for improvement. Conducting a lessons-
learned meeting and analyzing the root cause to prevent future incidents is a key part of this
phase.
12. Which of the following is a key characteristic of the "Stuxnet" attack, which targeted
Supervisory Control and Data Acquisition (SCADA) systems?
a. It was a ransomware attack that encrypted data and demanded payment.
b. It was a physical attack that destroyed centrifuges by modifying PLCs.
c. It was a distributed denial-of-service (DDoS) attack on public web servers.
d. It was a phishing campaign aimed at stealing financial credentials.
Correct Answer: b. It was a physical attack that destroyed centrifuges by modifying PLCs.
PRACTICE QUESTIONS WITH CORRECT DETAILED
ANSWERS, PBQS & COMPREHENSIVE RATIONALES
1. An incident response team is actively handling a security incident. Following the principles of
the NIST SP 800-61, which of the following activities is MOST likely to be performed during the
"Containment, Eradication, and Recovery" phase?
a. Implementing a firewall rule to block traffic from known malicious IP addresses.
b. Interviewing the system administrator to understand the normal behavior of the network.
c. Documenting the timeline of events and actions taken during the incident.
d. Conducting a post-incident review meeting to identify lessons learned.
Correct Answer: a. Implementing a firewall rule to block traffic from known malicious IP
addresses.
Rationale: Blocking traffic from known malicious IP addresses is a classic containment strategy.
The containment phase focuses on isolating the incident to prevent it from spreading or causing
further damage. This is a critical and immediate action in incident response.
2. A cybersecurity analyst is looking to improve the security of a Linux web server. Which of the
following actions BEST aligns with the principle of least privilege?
a. Allowing all users to execute the sudo command to run any application.
b. Installing a comprehensive antivirus suite on the server.
c. Removing the sudo privilege from a group of users who do not require administrative rights.
d. Creating a single account for all developers to share when accessing the server.
Correct Answer: c. Removing the sudo privilege from a group of users who do not require
administrative rights.
Rationale: The principle of least privilege dictates that users, applications, and systems should
be granted only the permissions essential to perform their designated functions.
Removing sudo from non-admin users directly applies this principle, minimizing the attack
surface.
3. During a vulnerability assessment, a scanner identifies multiple systems running a legacy
version of the Apache web server, which is known to be vulnerable to a specific remote code
execution exploit. The risk is high, but the patch cannot be applied immediately due to
compatibility concerns with a critical business application. What is the MOST appropriate
compensating control in this scenario?
,a. Immediately shut down the web servers to prevent exploitation.
b. Implement a web application firewall (WAF) rule to block exploit attempts against the known
vulnerability.
c. Accept the risk and document the decision, as the business impact is minimal.
d. Upgrade all systems to the latest version of the web server, overriding compatibility concerns.
Correct Answer: b. Implement a web application firewall (WAF) rule to block exploit attempts
against the known vulnerability.
Rationale: When a vulnerability cannot be immediately patched, a compensating control is
necessary. A WAF can provide virtual patching by detecting and blocking attempts to exploit the
known vulnerability, reducing the risk until the patch can be applied.
4. Which of the following is an example of a "known plaintext" cryptographic attack?
a. The attacker intercepts encrypted passwords and uses them to authenticate to other systems.
b. The attacker has obtained several samples of encrypted data and the corresponding original
unencrypted data.
c. The attacker observes the power consumption of a CPU during encryption operations.
d. The attacker uses a precomputed table of hash values to reverse-engineer a password.
Correct Answer: b. The attacker has obtained several samples of encrypted data and the
corresponding original unencrypted data.
Rationale: In a known plaintext attack, the adversary possesses pairs of plaintext (unencrypted)
data and its corresponding ciphertext (encrypted) data. The goal is to use these pairs to deduce
the encryption key.
5. An organization has a Service Level Agreement (SLA) with a cloud provider that guarantees
99.99% uptime for a critical web application. This uptime guarantee is MOST accurately
described as a:
a. Service Level Objective (SLO)
b. Key Performance Indicator (KPI)
c. Business Impact Analysis (BIA)
d. Recovery Point Objective (RPO)
Correct Answer: a. Service Level Objective (SLO)
Rationale: A Service Level Objective (SLO) is a specific, measurable metric defined within an SLA,
such as the target uptime percentage. It represents the level of performance the provider is
expected to deliver.
6. After a security incident, the incident response team identifies that a web application is
vulnerable to a specific attack. To correct this vulnerability, they recommend a code change to
sanitize user inputs. This activity falls under which phase of the incident response lifecycle?
a. Detection and Analysis
,b. Containment, Eradication, and Recovery
c. Post-Incident Activity
d. Preparation
Correct Answer: b. Containment, Eradication, and Recovery
Rationale: Eradication is the phase where the cause of the incident is removed. By
recommending a code change to fix the vulnerability, the team is actively eradicating the root
cause of the incident.
7. A company is evaluating the risk of a potential vulnerability in its system. They determine that
the cost of implementing the safeguard is greater than the potential financial loss from a
successful attack. Based on this analysis, the company decides to take no action. This is an
example of which risk management principle?
a. Risk Mitigation
b. Risk Transference
c. Risk Avoidance
d. Risk Acceptance
Correct Answer: d. Risk Acceptance
Rationale: Risk acceptance involves acknowledging the risk and choosing not to implement a
control, typically because the cost of the control outweighs the potential impact of the risk. This
is a valid response when the risk is within the organization's risk appetite.
8. A security analyst is investigating a server and notices an entry in a user's bash history file
that shows the command unset HISTFILE. What is the MOST likely reason for this command
being run?
a. To set a new environment variable for a script.
b. To permanently delete all command history from the system.
c. To prevent the current terminal session's commands from being written to the history file.
d. To disable the command-line interface for the user.
Correct Answer: c. To prevent the current terminal session's commands from being written to
the history file.
Rationale: The unset HISTFILE command is a common technique used by attackers to cover their
tracks by preventing the current session's command history from being saved to the bash
history file.
9. An organization wants to implement a control to prevent a common attack against its
cryptographic systems. They decide to add a random value to each password before it is hashed.
This technique is known as:
a. Encryption
b. Salting
, c. Non-repudiation
d. Tokenization
Correct Answer: b. Salting
Rationale: Salting involves adding a random, unique value to a password before it is hashed.
This is a defense against rainbow table attacks, as it ensures that two identical passwords will
have different hashes.
10. A cybersecurity analyst is preparing a report for the executive team on a recent vulnerability.
The report should explain the potential business impact in terms of financial loss, reputational
damage, and regulatory fines, rather than just technical details. This type of reporting is MOST
associated with which domain?
a. Security Operations
b. Vulnerability Management
c. Incident Response
d. Reporting and Communication
Correct Answer: d. Reporting and Communication
Rationale: The Reporting and Communication domain, covering approximately 17% of the CS0-
003 exam, emphasizes the importance of communicating vulnerability and incident
management findings effectively to both technical and non-technical stakeholders, highlighting
business impact.
11. A security analyst is reviewing logs after a suspected security incident. The analyst is tasked
with determining the root cause and identifying lessons learned. This activity is part of the:
a. Incident Response lifecycle, specifically the "Containment, Eradication, and Recovery" phase.
b. Post-Incident Activity phase, which includes lessons learned meetings.
c. Vulnerability Management process, focusing on reporting.
d. Preparation phase, which involves planning for future incidents.
Correct Answer: b. Post-Incident Activity phase, which includes lessons learned meetings.
Rationale: The post-incident activity phase is crucial for improvement. Conducting a lessons-
learned meeting and analyzing the root cause to prevent future incidents is a key part of this
phase.
12. Which of the following is a key characteristic of the "Stuxnet" attack, which targeted
Supervisory Control and Data Acquisition (SCADA) systems?
a. It was a ransomware attack that encrypted data and demanded payment.
b. It was a physical attack that destroyed centrifuges by modifying PLCs.
c. It was a distributed denial-of-service (DDoS) attack on public web servers.
d. It was a phishing campaign aimed at stealing financial credentials.
Correct Answer: b. It was a physical attack that destroyed centrifuges by modifying PLCs.