An analyst is conducting routine vulnerability assessments on the company infrastructure. When performing these scans, a business-critical server crashes, and the cause is traced back to the vulnerability scanner. Which of the following is the cause of this issue?
Correct Answer: B
The scanner is running in active mode, which is the cause of this issue. Active mode is a type of vulnerability scanning that sends probes or requests to the target systems to test their responses and identify potential vulnerabilities. Active mode can provide more accurate and comprehensive results, but it can also cause more network traffic, performance degradation, or system instability. In some cases, active mode can trigger denial- of-service (DoS) conditions or crash the target systems, especially if they are not configured to handle the scanning requests or if they have underlying vulnerabilities that can be exploited by the scanner12. Therefore, the analyst should use caution when performing active mode scanning, and avoid scanning business-critical or sensitive systems without proper authorization and preparation3. References: Vulnerability Scanning for my Server - Spiceworks Community, Negative Impacts of Automated Vulnerability Scanners and How ... - Acunetix, Vulnerability Scanning Best Practices
CS0-003 Exam Question 202
An analyst is becoming overwhelmed with the number of events that need to be investigated for a timeline. Which of the following should the analyst focus on in order to move the incident forward?
Correct Answer: A
The analyst should focus on the impact of the events in order to move the incident forward. Impact is the measure of the potential or actual damage caused by an incident, such as data loss, financial loss, reputational damage, or regulatory penalties. Impact can help the analyst prioritize the events that need to be investigated based on their severity and urgency, and allocate the appropriate resources and actions to contain and remediate them. Impact can also help the analyst communicate the status and progress of the incident to the stakeholders and customers, and justify the decisions and recommendations made during the incident response12. Vulnerability score, mean time to detect, and isolation are all important metrics or actions for incident response, but they are not the main focus for moving the incident forward. Vulnerability score is the rating of the likelihood and severity of a vulnerability being exploited by a threat actor. Mean time to detect is the average time it takes to discover an incident. Isolation is the process of disconnecting an affected system from the network to prevent further damage or spread of the incident34 . References: Incident Response: Processes, Best Practices & Tools - Atlassian, Incident Response Metrics: What You Should Be Measuring, Vulnerability Scanning Best Practices, How to Track Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) to Cybersecurity Incidents, [Isolation and Quarantine for Incident Response]
CS0-003 Exam Question 203
A vulnerability management team found four major vulnerabilities during an assessment and needs to provide a report for the proper prioritization for further mitigation. Which of the following vulnerabilities should have the highest priority for the mitigation process?
Correct Answer: B
A vulnerability that is related to a specific adversary campaign, with IoCs found in the SIEM, should have the highest priority for the mitigation process. This is because it indicates that the vulnerability is actively being exploited by a known threat actor, and that the organization's security monitoring system has detected signs of compromise. This poses a high risk of data breach, service disruption, or other adverse impacts. References: How to Prioritize Vulnerabilities Effectively: Vulnerability Prioritization Explained, Section: How to prioritize vulnerabilities step by step to avoid drowning in sea of problems; CompTIA CySA+ Study Guide: Exam CS0-003, 3rd Edition, Chapter 4: Security Operations and Monitoring, page 156.
CS0-003 Exam Question 204
Which of the following best explains the importance of playbooks for incident response teams?
Correct Answer: D
Incident response playbooks are preplanned, step-by-step procedures used to respond consistently and effectively to specific incident types. Their importance is that they provide tactical guidance during stressful situations, particularly in the early hours, to ensure a measured, repeatable response that reduces impact and supports recovery. The Sybex CySA+ Study Guide directly defines what playbooks are and why they matter: Exact extract (Sybex Study Guide): "CSIRT teams often develop playbooks that describe the specific procedures that they will follow in the event of a specific type of cybersecurity incident." It also explains the practical purpose: responders can use them as an operational plan, especially early in response: Exact extract (Sybex Study Guide): "The idea behind the playbook is that the team should be able to pick it up and find an operational plan for responding to the security incident that they may follow. Playbooks are especially important in the early hours of incident response..." The Secbay Press CS0-003 guide reinforces that playbooks are step-by-step instructions and that they streamline response and ensure consistency: Exact extract (Secbay Press): "Creation of incident response playbooks detailing step-by-step instructions for responding to common types of security incidents. Playbooks streamline response efforts and ensure consistency across incidents." Therefore, Option D is the best answer because it matches the step-by-step, preplanned nature of playbooks and their goal of minimizing impact and supporting restoration/recovery. Why the other options are not best: * A: Compliance alignment is not the primary function of IR playbooks; playbooks are operational response guides. * B: Preventing incidents is more about security controls/hardening; playbooks are for responding when incidents occur. * C: Metrics/KPIs and lessons learned are part of post-incident improvement, but playbooks aren't primarily "baseline requirements for monitoring." They're response procedures. References (CompTIA CySA+ CS0-003 documents / study guides used): * Mike Chapple & David Seidl, CompTIA CySA+ Study Guide (CS0-003): playbooks describe specific procedures; operational plan; importance early in incident response * Secbay Press, CompTIA CySA+ Exam Prep Guide (CS0-003): playbooks are step-by-step instructions; streamline response; ensure consistency
CS0-003 Exam Question 205
Which of the following is the best metric for an organization to focus on given recent investments in SIEM, SOAR, and a ticketing system?
Correct Answer: A
Mean time to detect (MTTD) is the best metric for an organization to focus on given recent investments in SIEM, SOAR, and a ticketing system. MTTD is a metric that measures how long it takes to detect a security incident or threat from the time it occurs. MTTD can be improved by using tools and processes that can collect, correlate, analyze, and alert on security data from various sources. SIEM, SOAR, and ticketing systems are examples of such tools and processes that can help reduce MTTD and enhance security operations. Official References: https://www.eccouncil.org/cybersecurity-exchange/threat-intelligence/cyber- kill-chain-seven-steps-cyberattack