
CompTIACySA+
Domain 2Objective 1
Vulnerability Scanning CS0-003 Practice Questions (Page 6)
Part of the Vulnerability management domain, which accounts for 30% of the CS0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~20–33 in this domain), expect 4–7 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
12concepts
30%of the exam
Questions 26–30
- 26
When is non-credentialed scanning most appropriate?
Select an answer first - 27
What is a primary advantage of credentialed vulnerability scanning?
Select an answer first - 28
A security analyst needs to verify that a newly deployed firewall is not exposing any unnecessary services to the internal network. The analyst wants to actively probe the firewall's internal interface to see which ports are open. Which scanning technique should be used?
Select an answer first - 29
A security analyst is testing a newly developed web application that is running in a staging environment. The analyst wants to identify vulnerabilities that only appear during execution, such as SQL injection and cross-site scripting. Which scanning approach is most appropriate?
Select an answer first - 30
A security team must assess the external attack surface of a company that hosts a web application behind a load balancer. The team wants to identify vulnerabilities in the application and the underlying infrastructure from an external perspective. They have no credentials for the systems. Which approach is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CS0-003
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CS0-003” is a trademark of its owner, used for identification only.