
CompTIACySA+
Domain 4Objective 2
Incident Response Reporting CS0-003 Practice Questions (Page 2)
Part of the Reporting and communication domain, which accounts for 17% of the CS0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~11–19 in this domain), expect 6–10 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
7concepts
17%of the exam
Questions 6–10
- 6
After a major incident, the incident response team is conducting a lessons learned review. Which activity is MOST likely to be part of this review?
Select an answer first - 7
During a major incident, the incident commander needs to communicate with external stakeholders, including customers and regulatory bodies. Which communication strategy is MOST appropriate?
Select an answer first - 8
A security incident occurred because a patch was not applied to a critical server. The investigation reveals that the patch management process failed because the server was not included in the automated patching schedule. What is the ROOT CAUSE of the incident?
Select an answer first - 9
Which technique is commonly used to conduct a root cause analysis by repeatedly asking 'why' to drill down to the underlying cause?
Select an answer first - 10
During an incident, the incident response team needs to share sensitive technical information with a third-party vendor that is assisting with the response. What is the MOST secure method of communication?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CS0-003” is a trademark of its owner, used for identification only.