
CompTIACySA+
Domain 3Objective 2
Incident Response Activities CS0-003 Practice Questions (Page 3)
Part of the Incident response management domain, which accounts for 20% of the CS0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~13–22 in this domain), expect 4–7 from this objective — we provide 22 practice questions to prepare you well beyond it. (estimate)
22questions here
5free pages
5concepts
20%of the exam
Questions 11–15
- 11
After a ransomware incident, the incident response team has identified that the attacker used a vulnerability in a web application to gain initial access. The team has removed the ransomware and restored the systems. What is the most important eradication step to prevent a recurrence?
Select an answer first - 12
Which activity is part of incident analysis?
Select an answer first - 13
Which action is part of eradication procedures?
Select an answer first - 14
A company has completed the eradication of a malware infection. The incident response team is now in the recovery phase. Which activity is most important to ensure the systems are safe to return to production?
Select an answer first - 15
A security analyst notices repeated failed login attempts from a single external IP against the company's VPN gateway. The attempts are increasing in frequency and appear to be targeting a specific account. The analyst wants to prevent the attacker from continuing while preserving forensic evidence. Which action should the analyst take first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CS0-003” is a trademark of its owner, used for identification only.