CySA+

COMPTIA_CS0_003
IntermediateVersion CS0-003Official exam guide โ†—

Ready to test yourself?

A timed, blueprint-proportional exam drawn fresh from this bank โ€” with a per-domain score report.

๐Ÿ”’ Unlock the simulation โ†’

๐Ÿ”“ Free preview: showing 10 of 90 questions. Unlock the full bank โ€” every question, explanation, and reference.

Unlock all 90 questions โ†’

10 questions across 5 topics. Choose an answer for each question, then check it to see the correct answer and explanation.

Filter by topic

All 10 questions

SECOPS_ARCH

Security Operations: Architecture, Identity & Logs

10 questions in topic

Security architecture, identity and access, SIEM/log analysis, and analyst tooling.

1
Single choice~60s

An analyst must correlate authentication failures across many servers to detect a distributed brute-force attempt. Which platform is designed for this?

2
Single choice~80s

Which Windows Security event IDs record successful and failed logons, useful for detecting password-guessing?

3
Single choice~80s

Before correlating logs from multiple systems during an investigation, why is time synchronization (NTP) essential?

4
Single choice~80s

Which model requires that every access request be authenticated and authorized continuously, regardless of network location?

5
Single choice~85s

A company wants to limit lateral movement so a breach in one zone cannot reach critical servers. Which control best achieves this?

6
Single choice~80s

Which control most effectively prevents account takeover even when a user's password has been phished?

7
Single choice~85s

Which capability vaults administrator credentials and grants time-limited, just-in-time elevation with session recording?

8
Single choice~100s

Which combination of email-authentication technologies lets a receiver detect and reject spoofed messages and get failure reports?

9
Single choice~85s

An analyst must safely determine what a suspicious executable does without risking production. Which technique is appropriate?

10
Single choice~80s

Which endpoint technology continuously records process, file, and network activity and enables behavioral detection and response?