Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CompTIA logo

CompTIACySA+

Domain 1Objective 2

Malicious Activity Indicators CS0-003 Practice Questions (Page 3)

Part of the Security operations domain, which accounts for 33% of the CS0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~21–36 in this domain), expect 4–7 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)

20questions here
4free pages
4concepts
33%of the exam

Questions 11–15

  1. 11application · easy

    An employee receives an email that appears to be from the company's IT department, stating that their password has expired and they must click a link to renew it immediately. The link points to a URL that closely resembles the company's official domain but is slightly misspelled. Which of the following is the BEST immediate action for the employee to take?

    Select an answer first
  2. 12application · medium

    A security analyst is reviewing network traffic logs and notices a series of DNS queries for a domain that is known to be malicious. The queries are coming from a single internal IP address. Which of the following is the MOST likely explanation for this activity?

    Select an answer first
  3. 13expert · hard

    A security analyst is reviewing a report of a successful phishing attack. The attacker sent an email to a group of employees, and one employee clicked the link and entered their credentials. The analyst needs to determine the scope of the attack. Which of the following is the MOST important information to gather first?

    Select an answer first
  4. 14application · medium

    A security analyst is investigating a potential data exfiltration incident. The analyst notices that a large amount of data has been transferred from a database server to an external IP address via the File Transfer Protocol (FTP). The database server is not supposed to have any FTP client software installed. Which of the following is the BEST evidence that this activity is malicious?

    Select an answer first
  5. 15expert · hard

    A security analyst is investigating a host that is suspected of being compromised. The analyst finds a new service running on the host that is not part of any approved software. The service is configured to start automatically. The analyst also notices that the host is communicating with an external IP address on a non-standard port. Which of the following is the BEST course of action to confirm the host is compromised?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CS0-003” is a trademark of its owner, used for identification only.