
CompTIACySA+
Domain 2Objective 4
Mitigation Controls CS0-003 Practice Questions (Page 1)
Part of the Vulnerability management domain, which accounts for 30% of the CS0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~20–33 in this domain), expect 4–7 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
7concepts
30%of the exam
Questions 1–5
- 1
A security analyst wants to restrict which external domains a web application can load scripts from. Which HTTP security header should be configured?
Select an answer first - 2
Which technique is specifically designed to prevent a browser from interpreting user-supplied data as executable HTML or JavaScript?
Select an answer first - 3
A web application has a search feature that reflects the user's query in the results page without proper encoding. A security analyst discovers that an attacker can craft a URL that executes JavaScript in the victim's browser. The application is built on a framework that provides automatic output encoding, but the developer disabled it for performance reasons. Which control should be recommended?
Select an answer first - 4
A developer is writing a C function that copies user input into a fixed-size buffer. The developer wants to prevent a buffer overflow that could overwrite adjacent memory. Which coding practice should be used?
Select an answer first - 5
Which vulnerability class is most directly mitigated by consistently sanitizing user inputs?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CS0-003” is a trademark of its owner, used for identification only.