
CompTIAServer+
Domain 3Objective 4
Mitigation Strategies SK0-005 Practice Questions (Page 1)
Part of the Security and disaster recovery domain, which accounts for 24% of the SK0-005 exam. CompTIA does not publish an official question count, but from its 90-minute exam (~35–60 total, ~8–14 in this domain), expect 1–2 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
7concepts
24%of the exam
Questions 1–5
- 1
A SIEM administrator is configuring the system to detect unauthorized changes to critical files on a web server. Which SIEM feature is most appropriate for this task?
Select an answer first - 2
A security operations center (SOC) is overwhelmed by a high volume of SIEM alerts, many of which are false positives. Analysts are missing critical alerts. The SOC manager wants to improve the signal-to-noise ratio without losing important detections. Which approach is most effective?
Select an answer first - 3
A user reports that all their personal files have been renamed with a .encrypted extension and a message demands payment in cryptocurrency to restore access. Which type of malware is most likely responsible?
Select an answer first - 4
Which tool is commonly used to implement DLP by inspecting data as it is copied to a USB drive?
Select an answer first - 5
A server administrator notices that a server is sending large amounts of data to an external IP address. The administrator suspects a Trojan horse. Which action should the administrator take first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “SK0-005” is a trademark of its owner, used for identification only.