Courseiva
hardMultiple Choice

CS0-003 Practice Question: A security analyst is tasked with performing a…

A security analyst is tasked with performing a risk assessment for a new web application. The application will handle sensitive customer data. Which of the following should the analyst do FIRST to identify vulnerabilities specific to the application?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conduct a threat model of the application.

Conducting a threat model helps identify potential vulnerabilities early in the development lifecycle, especially for a new application handling sensitive data. Option A is wrong because a network vulnerability scan is too broad and does not focus on application-specific vulnerabilities. Option B is wrong because penetration testing is typically performed later after the application is deployed. Option C is wrong because source code review is important but threat modeling should be performed first to identify risks at a higher level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run a network vulnerability scan against the application server.

    Why it's wrong here

    A network vulnerability scan probes hosts, ports and services, so it cannot inspect application-layer logic such as input handling, authentication flows or session management. It is tempting because it is a fast, low-effort first sweep, and it would be the correct starting point when the target is infrastructure rather than the application's own code and business logic.

  • ✗

    Perform a penetration test on the application.

    Why it's wrong here

    Penetration testing exploits discovered weaknesses and validates impact, so it presupposes an existing vulnerability inventory rather than producing the initial application-specific one. It is tempting because it delivers the most realistic assurance, and it would be correct once a baseline of findings exists and the goal is to confirm exploitability under controlled conditions.

  • ✗

    Perform a source code review.

    Why it's wrong here

    Source code review examines implementation flaws in code the analyst may not possess or have rights to inspect, and it misses runtime and configuration vulnerabilities. It would be correct for a white-box assessment of an application whose codebase is available and in scope.

  • ✓

    Conduct a threat model of the application.

    Why this is correct

    Threat modelling systematically enumerates threats against the application's architecture, data flows and trust boundaries before any testing begins, satisfying the stem's requirement to identify vulnerabilities specific to this application. Unlike vulnerability scanning, which only detects known signatures, it exposes design-level weaknesses such as insecure data handling of sensitive customer information.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.