
CompTIACySA+
Domain 4Objective 2
Incident Response Reporting CS0-003 Practice Questions (Page 4)
Part of the Reporting and communication domain, which accounts for 17% of the CS0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~11–19 in this domain), expect 6–10 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
7concepts
17%of the exam
Questions 16–20
- 16
A security operations center (SOC) analyst discovers a ransomware infection on a single file server that contains sensitive customer data. The analyst has isolated the server, but the malware is actively encrypting files. According to the incident response plan, which action should the analyst take FIRST?
Select an answer first - 17
Which communication channel is most appropriate for real-time coordination among incident response team members during an active incident?
Select an answer first - 18
An incident responder is writing an incident report for a data breach. The report must include the scope of the incident, the root cause, and the actions taken. Which additional component is REQUIRED for a complete incident report?
Select an answer first - 19
What is a key consideration when communicating incident information to external stakeholders, such as customers or the public?
Select an answer first - 20
A web application was compromised due to a SQL injection vulnerability. The investigation shows that the vulnerability was introduced during a recent code update. What is the ROOT CAUSE of the incident?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CS0-003” is a trademark of its owner, used for identification only.