
CompTIACySA+
Domain 2Objective 4
Mitigation Controls CS0-003 Practice Questions (Page 4)
Part of the Vulnerability management domain, which accounts for 30% of the CS0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~20–33 in this domain), expect 4–7 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
7concepts
30%of the exam
Questions 16–20
- 16
A web application accepts a user ID from a query string parameter and uses it to look up records in a database. A security analyst discovers that an attacker can modify the parameter to include SQL commands, causing the database to return unauthorized data. Which control should be implemented to prevent this injection vulnerability?
Select an answer first - 17
A security analyst is reviewing a web application that accepts user input for a search feature. The analyst is concerned about injection attacks that could manipulate the application's behavior. Which control should be implemented to ensure that user input is treated as data, not as executable code?
Select an answer first - 18
Which coding practice is most directly effective at preventing a classic stack-based buffer overflow?
Select an answer first - 19
A security analyst is implementing a Content Security Policy for a web application that uses inline event handlers in some legacy pages. The analyst wants to mitigate XSS but does not want to break the existing functionality. Which CSP directive should be used to allow inline scripts while still restricting external script sources?
Select an answer first - 20
A security analyst is evaluating mitigations for a buffer overflow vulnerability in a Linux application. The analyst notes that the application loads shared libraries at predictable memory addresses, making it easier for an attacker to redirect execution to a useful gadget. Which control should be enabled to make these addresses unpredictable?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CS0-003” is a trademark of its owner, used for identification only.