
CompTIACySA+
Domain 2Objective 2
Assessment Tool Output CS0-003 Practice Questions (Page 1)
Part of the Vulnerability management domain, which accounts for 30% of the CS0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~20–33 in this domain), expect 4–7 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
6concepts
30%of the exam
Questions 1–5
- 1
A cloud security tool reports that an Azure VM has 'Just-in-Time (JIT) access' disabled for RDP. The VM is a domain controller that is only accessed by a few administrators. What is the primary security benefit of enabling JIT access?
Select an answer first - 2
An analyst is reviewing the results of an internal network scan. The scan shows that a database server has port 1433/tcp open, which is used by Microsoft SQL Server. The server is also running a web application that is accessible on port 443. The analyst discovers that the SQL Server service is using a 'sa' account with a weak password. What is the most significant risk?
Select an answer first - 3
A developer is analyzing a crash dump from a production application. The debugger shows a buffer overflow in a function that processes network packets. The overflow overwrites a return address on the stack. What is the most likely security impact if this vulnerability is exploited?
Select an answer first - 4
A vulnerability scanner output lists a finding with a CVSS v3.1 base score of 9.8. How should an analyst prioritize this finding?
Select an answer first - 5
A cloud security assessment tool reports that an AWS IAM role has a policy that grants 's3:PutObject' permission to all S3 buckets in the account. The role is used by an EC2 instance that runs a web application. What is the most significant risk associated with this configuration?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CS0-003” is a trademark of its owner, used for identification only.