
CompTIACySA+
Domain 2Objective 2
Assessment Tool Output CS0-003 Practice Questions (Page 4)
Part of the Vulnerability management domain, which accounts for 30% of the CS0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~20–33 in this domain), expect 4–7 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
6concepts
30%of the exam
Questions 16–20
- 16
A web application scanner reports a finding with the description: 'The application reflects user-supplied input in the HTTP response without proper sanitization.' Which vulnerability is this most likely describing?
Select an answer first - 17
A developer uses a debugger to analyze a crash in a C++ application. The debugger shows a 'segmentation fault' occurring when the program tries to access memory at address 0x00000000. What is the most likely cause of this crash?
Select an answer first - 18
While analyzing a debugger output, an analyst sees a stack trace that includes a function call to `strcpy`. What vulnerability is this most likely related to?
Select an answer first - 19
An analyst is reviewing a network scan and sees that a host has port 3389/tcp open. The host is a Windows Server 2019 machine that is not part of a domain. The analyst also notices that the 'Network Level Authentication (NLA)' is disabled on the host. What is the most significant risk?
Select an answer first - 20
A web application scanner reports a 'SQL Injection' vulnerability in the login form of a customer portal. The report also shows a 'Low' severity 'Information Disclosure' finding for a verbose error message on a different page. The development team has limited resources. What should the analyst recommend as the next step?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CS0-003” is a trademark of its owner, used for identification only.