
CompTIACySA+
Domain 3Objective 3
Incident Management Life Cycle CS0-003 Practice Questions (Page 1)
Part of the Incident response management domain, which accounts for 20% of the CS0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~13–22 in this domain), expect 4–7 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
9concepts
20%of the exam
Questions 1–5
- 1
Which tool is specifically designed to collect and analyze volatile data from a running system during incident response?
Select an answer first - 2
An incident responder is investigating a possible malware infection on a Linux server. The responder suspects that the malware is running as a process and has modified system files. The responder needs to preserve evidence for forensic analysis. Which action should the responder take first?
Select an answer first - 3
A company's disaster recovery plan relies on a single backup vendor. During a recent incident, the backup vendor experienced an outage, and the company could not restore critical systems. Management wants to improve resilience without significantly increasing costs. Which action is most effective?
Select an answer first - 4
Which of the following is a common practice in business continuity planning?
Select an answer first - 5
A security team is creating a playbook for handling phishing emails that contain malicious attachments. The playbook should provide step-by-step instructions for the initial response, including containment and eradication. Which component is essential for the playbook to be effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CS0-003” is a trademark of its owner, used for identification only.