Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CompTIA logo

CompTIACySA+

Domain 3Objective 2

Incident Response Activities CS0-003 Practice Questions (Page 5)

Part of the Incident response management domain, which accounts for 20% of the CS0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~13–22 in this domain), expect 4–7 from this objective — we provide 22 practice questions to prepare you well beyond it. (estimate)

22questions here
5free pages
5concepts
20%of the exam

Questions 21–22

  1. 21expert · hard

    After a security incident, the incident response team has identified that the attacker used a phishing email to gain access to a user's credentials. The team has contained the incident and is now in the eradication phase. Which action is most important to prevent the attacker from using the same credentials again?

    Select an answer first
  2. 22foundation · easy

    An analyst wants to detect a known malware strain that leaves a unique string in files it creates. Which detection technique is most appropriate for this task?

    Select an answer first
Finished these 2 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CS0-003

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CS0-003” is a trademark of its owner, used for identification only.