easyMultiple Choice
CS0-003 Practice Question: A DAST scan cannot reach authenticated pages of a…
A DAST scan cannot reach authenticated pages of a web application and reports only public content findings. What should be configured? For tool configuration, Which scanner or pipeline change most directly improves result quality?
⚠ Common exam trap
The CS0-004 exam often tests the misconception that disabling authentication or reducing scope is an acceptable workaround, when the correct approach is to configure the scanner to properly handle the existing authentication mechanism.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Authenticated scanning with a test account and session handling
DAST scanners analyze live web applications by sending HTTP requests and inspecting responses. When authentication is required to access protected pages, the scanner must maintain a valid session to reach those endpoints. Configuring authenticated scanning with a test account and proper session handling (e.g., using cookies, tokens, or form-based login) allows the scanner to traverse authenticated pages, ensuring the scan covers the full attack surface and reports findings from restricted areas.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Authenticated scanning with a test account and session handling
Why this is correct
The DAST scanner only crawls unauthenticated content, so it never reaches pages behind login. Configuring authenticated scanning with a test account and session handling lets the scanner maintain a valid session and crawl restricted areas, directly improving coverage and finding quality.
- ✗
Reduce the scan to only the landing page
Why it's wrong here
Restricting the scan to the landing page guarantees the authenticated areas stay unscanned, producing even fewer findings. Landing-page-only scans suit smoke-testing scanner connectivity or pipeline health, not coverage of authenticated functionality, which needs credential or session configuration.
- ✗
Disable all application authentication
Why it's wrong here
Disabling authentication removes the login barrier entirely, so the scanner crawls unauthenticated routes and still misses role-gated content, while exposing the application. It would suit a deliberately public test instance, but authenticated DAST requires session credentials or recorded login macros configured in the scanner.
- ✗
Treat absence of findings as proof of security
Why it's wrong here
Treating no findings as proof of security misreads an unauthenticated scan's blind spots as clean results, hiding real vulnerabilities. Absence of findings legitimately indicates coverage only when the scanner has authenticated and crawled every route; here it reflects unreachable pages, not a secure application.
Go deeper
Related to this question
Learn chapter
Attack Simulation Tools: Atomic Red Team
Key term
DAST
DAST (Dynamic Application Security Testing) is a security testing method that finds vulnerabilities in running web applications by simulating real attacks from the outside.
Key term
Attack surface
The attack surface is the total sum of all points in a system, network, or application where an unauthorized user can try to enter or extract data.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.