Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CompTIA logo

CompTIACySA+

Domain 2Objective 4

Mitigation Controls CS0-003 Practice Questions (Page 2)

Part of the Vulnerability management domain, which accounts for 30% of the CS0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~20–33 in this domain), expect 4–7 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)

31questions here
7free pages
7concepts
30%of the exam

Questions 6–10

  1. 6expert · hard

    A security analyst is hardening a web application that allows users to upload profile pictures. The application already uses output encoding for user-generated content, but the analyst wants to add a Content Security Policy to further reduce the risk of XSS. The application also loads images from a third-party CDN. Which CSP directive should be configured to allow images from the CDN while still preventing script injection?

    Select an answer first
  2. 7expert · hard

    A security analyst is responsible for a machine learning system that classifies emails as spam or not spam. An attacker has been submitting carefully crafted emails that are misclassified, causing the model to learn incorrect patterns. The analyst needs to implement a control that will prevent the attacker from influencing the model's training data. Which approach is most effective?

    Select an answer first
  3. 8expert · hard

    A security analyst is reviewing a web application that allows users to submit HTML content that is later displayed to other users. The application currently uses a rich text editor that allows some HTML tags. The analyst is concerned about stored XSS attacks. Which combination of controls should be implemented to provide the most robust protection while still allowing the rich text functionality?

    Select an answer first
  4. 9application · medium

    A company's web application has been the target of multiple reflected XSS attacks. The development team has already implemented output encoding, but the security team wants an additional control that will stop the browser from executing any script that is not explicitly allowed by the application. Which control should be implemented?

    Select an answer first
  5. 10foundation · easy

    Which practice is most directly aimed at preventing data poisoning in a data collection pipeline?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CS0-003” is a trademark of its owner, used for identification only.