Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CompTIA logo

CompTIACySA+

Domain 2Objective 4

Mitigation Controls CS0-003 Practice Questions (Page 6)

Part of the Vulnerability management domain, which accounts for 30% of the CS0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~20–33 in this domain), expect 4–7 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)

31questions here
7free pages
7concepts
30%of the exam

Questions 26–30

  1. 26foundation · easy

    Which function is considered a safer alternative to strcpy() when copying strings in C?

    Select an answer first
  2. 27application · medium

    A web application allows users to post comments that are displayed to other users. A security analyst discovers that an attacker can inject a script tag into a comment, and when another user views the comment, the script executes in their browser. The application currently uses no output encoding and has no security headers. Which combination of controls should the analyst recommend to mitigate this vulnerability?

    Select an answer first
  3. 28application · medium

    A security analyst is reviewing the security posture of a Linux server that runs a custom application. The analyst wants to make it more difficult for an attacker to exploit a buffer overflow by predicting the memory addresses of system libraries. Which control should be enabled?

    Select an answer first
  4. 29foundation · easy

    A machine learning model is being trained on data collected from a public web form. What is the most effective way to prevent an attacker from poisoning the training dataset?

    Select an answer first
  5. 30application · medium

    A security analyst is responsible for a machine learning model that predicts customer churn. The model is trained on data collected from a public API. The analyst is concerned that an attacker could submit fake data to the API to influence the model's predictions. Which control should be implemented to reduce the risk of data poisoning?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CS0-003” is a trademark of its owner, used for identification only.