
CompTIACySA+
Domain 2Objective 2
Assessment Tool Output CS0-003 Practice Questions (Page 2)
Part of the Vulnerability management domain, which accounts for 30% of the CS0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~20–33 in this domain), expect 4–7 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
6concepts
30%of the exam
Questions 6–10
- 6
A web application scanner reports a 'Cross-Site Request Forgery (CSRF)' vulnerability in a state-changing form on a banking application. The application uses session cookies that do not have the 'SameSite' attribute set. The analyst needs to recommend a fix. Which of the following is the most effective and comprehensive mitigation?
Select an answer first - 7
An analyst uses 'tcpdump' to capture network traffic and sees a large number of TCP SYN packets being sent to a single host from a single source IP, but no SYN-ACK responses are being returned. What type of activity is the analyst most likely observing?
Select an answer first - 8
A web application scanner flags a 'Reflected XSS' vulnerability in the search functionality of a public website. The analyst verifies the finding by manually submitting a crafted URL and confirms the script executes. What is the most appropriate immediate action?
Select an answer first - 9
An analyst uses a multipurpose tool like 'netcat' to listen on a port and receives a banner that reads 'SSH-2.0-OpenSSH_7.2p2 Ubuntu 4ubuntu2.10'. What can the analyst conclude from this output?
Select an answer first - 10
A network scan output shows `443/tcp open ssl/http`. Which service is most likely running on this port?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CS0-003” is a trademark of its owner, used for identification only.