Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CompTIA logo

CompTIACySA+

Domain 3Objective 1

Attack Methodology Frameworks CS0-003 Practice Questions (Page 3)

Part of the Incident response management domain, which accounts for 20% of the CS0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~13–22 in this domain), expect 4–7 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)

21questions here
5free pages
5concepts
20%of the exam

Questions 11–15

  1. 11application · medium

    A threat hunting team is reviewing a series of alerts. They notice a pattern where an attacker uses a legitimate system tool (PowerShell) to download a script from a remote server and execute it in memory. The team wants to document this behavior in a way that maps to the MITRE ATT&CK framework. Which two tactics should they assign to the actions of 'downloading the script' and 'executing it in memory', respectively?

    Select an answer first
  2. 12expert · hard

    A penetration tester is assessing a web application and has identified a potential cross-site scripting (XSS) vulnerability in a search field. The tester wants to confirm the vulnerability and understand its impact. Which of the following actions, guided by the OWASP Testing Guide, is the most appropriate next step?

    Select an answer first
  3. 13application · medium

    A security operations center (SOC) analyst is documenting a recent incident. The attacker used a spear-phishing email to get an employee to click a link that downloaded a malicious file. The file then created a scheduled task for persistence. In MITRE ATT&CK, which two tactics are being documented by the actions of 'clicking the link' and 'creating a scheduled task'?

    Select an answer first
  4. 14expert · hard

    An incident responder is analyzing a breach. The attacker used a phishing email to deliver a malicious attachment. The attachment was opened, and the malware executed. The malware then beaconed out to a command-and-control server. The responder is trying to map this to the Cyber Kill Chain. Which stage does the 'beaconing out to a command-and-control server' represent?

    Select an answer first
  5. 15expert · hard

    An incident responder is analyzing a breach. The attacker used a zero-day exploit to gain access to a server. After gaining access, the attacker downloaded a tool to the server to maintain persistence. The responder is trying to map this to the Cyber Kill Chain. Which stage does the 'downloading a tool to maintain persistence' represent?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CS0-003” is a trademark of its owner, used for identification only.