
CompTIACySA+
Domain 3Objective 1
Attack Methodology Frameworks CS0-003 Practice Questions (Page 2)
Part of the Incident response management domain, which accounts for 20% of the CS0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~13–22 in this domain), expect 4–7 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)
21questions here
5free pages
5concepts
20%of the exam
Questions 6–10
- 6
A threat hunter is analyzing a series of alerts. They notice that a specific domain name is being used as a command-and-control server. The domain was registered using a fake identity. The threat hunter wants to document this in the Diamond Model. Which two vertices are being documented by the 'domain name' and the 'fake identity'?
Select an answer first - 7
A web developer is tasked with securing a new e-commerce application. They are required to test the application for common vulnerabilities like SQL injection and cross-site scripting (XSS) during the development phase. Which framework provides a structured, comprehensive guide for performing these specific web application security tests?
Select an answer first - 8
In the Cyber Kill Chain, which stage immediately follows the 'delivery' stage?
Select an answer first - 9
A penetration testing firm is hired to assess the security of a client's network. The client specifically asks for a methodology that focuses on operational security metrics, such as how well the network resists a specific attack vector, rather than just a checklist of vulnerabilities. Which methodology should the lead tester recommend to best align with this requirement?
Select an answer first - 10
What is the primary objective of the OWASP Testing Guide?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CS0-003” is a trademark of its owner, used for identification only.