Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CompTIA logo

CompTIACySA+

Domain 4Objective 2

Incident Response Reporting CS0-003 Practice Questions (Page 3)

Part of the Reporting and communication domain, which accounts for 17% of the CS0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~11–19 in this domain), expect 6–10 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)

32questions here
7free pages
7concepts
17%of the exam

Questions 11–15

  1. 11foundation · easy

    What is the primary purpose of tracking incident metrics and KPIs?

    Select an answer first
  2. 12expert · hard

    A security analyst discovers a potential data exfiltration from a finance server. The analyst is not certain if the activity is malicious or a false positive. The organization's incident response plan requires escalation to the incident commander for any potential data exfiltration. What should the analyst do?

    Select an answer first
  3. 13application · medium

    A phishing email bypassed the email filter and led to credential theft. The investigation reveals that the filter was not updated with the latest threat intelligence. What is the ROOT CAUSE of this incident?

    Select an answer first
  4. 14foundation · easy

    What is the primary purpose of an incident report in the context of incident response?

    Select an answer first
  5. 15foundation · easy

    Which of the following is a key component of an effective incident report?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CS0-003” is a trademark of its owner, used for identification only.