
CompTIACySA+
Domain 3Objective 1
Attack Methodology Frameworks CS0-003 Practice Questions (Page 1)
Part of the Incident response management domain, which accounts for 20% of the CS0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~13–22 in this domain), expect 4–7 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)
21questions here
5free pages
5concepts
20%of the exam
Questions 1–5
- 1
In the Diamond Model of Intrusion Analysis, what does the 'Capability' component represent?
Select an answer first - 2
A threat intelligence analyst is correlating data from two separate incidents. In Incident A, a known APT group used a specific malware variant against a financial institution. In Incident B, a different malware variant was used against a utility company, but the analyst notices the same command-and-control server IP address was used. Using the Diamond Model, which of the following is the most logical hypothesis to form?
Select an answer first - 3
During an incident investigation, an analyst identifies that a specific IP address (10.0.0.50) was used to brute-force a web server. The analyst then finds the same IP address was used to log into a VPN with a stolen account. The analyst creates a graph showing the IP address as a central node connected to both the web server and the VPN. In the Diamond Model, which element is the analyst primarily documenting?
Select an answer first - 4
A penetration tester is assessing a web application. The tester has identified a potential SQL injection vulnerability in the login form. The tester wants to confirm the vulnerability and understand its impact. Which of the following actions, guided by the OWASP Testing Guide, is the most appropriate next step?
Select an answer first - 5
A security analyst is investigating a breach where an attacker exploited a vulnerability in a public-facing web application to gain a foothold. The analyst then observes the attacker using a known hacking tool to escalate privileges on the server. In the Diamond Model, how would the analyst classify the 'known hacking tool'?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CS0-003” is a trademark of its owner, used for identification only.