
CompTIACySA+
Domain 3Objective 3
Incident Management Life Cycle CS0-003 Practice Questions (Page 2)
Part of the Incident response management domain, which accounts for 20% of the CS0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~13–22 in this domain), expect 4–7 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
9concepts
20%of the exam
Questions 6–10
- 6
What is the primary role of an incident response playbook?
Select an answer first - 7
Which of the following is a key component typically found in an incident response plan?
Select an answer first - 8
A forensic analyst is investigating a suspected insider threat. The analyst has a forensic image of the suspect's workstation and needs to determine if the suspect accessed a specific file on a network share. The analyst has the file's hash. Which approach is most effective?
Select an answer first - 9
A company experienced a data breach that was traced to a misconfigured firewall rule that allowed unauthorized external access to a database. The incident response team has contained the breach and eradicated the threat. What is the next step the team should take to prevent a recurrence?
Select an answer first - 10
A small company is developing its first incident response plan. The plan will be used by a team of three IT staff who have limited security experience. Which approach is most effective for creating a usable plan?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CS0-003” is a trademark of its owner, used for identification only.