Incident Response Management CS0-003 Practice Quiz
172 exam-style questions covering 20% of the CS0-003 exam. Instant feedback on every answer, progress tracking, no signup required.
This domain is part of the CompTIA CySA+ practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.
Sample Questions
Which description best matches Cyber kill chain in CySA+ Objective 3.0 Incident Response and Management?
- A. The cyber kill chain is a phased model that describes common stages of an attack from reconnaissance through actions on objectives.
- B. Reconnaissance is the attack phase where an adversary gathers information about targets, technologies, people, and weaknesses before attempting compromise.
- C. Weaponization is the attack phase where an adversary prepares a payload, exploit, or delivery package for use against a target.
- D. Delivery is the attack phase where the adversary transmits the weaponized payload or malicious content to the target.
The cyber kill chain is a phased model that describes common stages of an attack from reconnaissance through actions on objectives. This is the correct answer.
Which option correctly defines Reconnaissance?
- A. The Diamond Model of Intrusion Analysis relates adversary, victim, infrastructure, and capability to analyze and pivot through intrusion activity.
- B. Reconnaissance is the attack phase where an adversary gathers information about targets, technologies, people, and weaknesses before attempting compromise.
- C. In the Diamond Model, the adversary is the attacker or group conducting the intrusion activity.
- D. In the Diamond Model, the victim is the person, organization, system, or resource targeted by adversary activity.
Reconnaissance is the attack phase where an adversary gathers information about targets, technologies, people, and weaknesses before attempting compromise. This is the correct answer.
An analyst is mapping attacker behavior using Cyber kill chain. Which choice best explains the framework concept?
- A. OSSTMM should be selected when the scenario matches this purpose: The Open Source Security Testing Methodology Manual is a methodology for structured security testing and analysis.
- B. Cyber kill chain should be selected when the scenario matches this purpose: The cyber kill chain is a phased model that describes common stages of an attack from reconnaissance through actions on objectives.
- C. OWASP Testing Guide should be selected when the scenario matches this purpose: The OWASP Testing Guide provides guidance for testing web application security weaknesses and controls.
- D. Detection and analysis should be selected when the scenario matches this purpose: Detection and analysis identifies suspicious events, confirms incidents, determines scope, and analyzes evidence and logs.
The cyber kill chain is a phased model that describes common stages of an attack from reconnaissance through actions on objectives. This matches the incident response scenario without shifting to a related but different framework, activity, or phase. This is the correct answer.
An analyst is mapping attacker behavior using Reconnaissance. Which choice best explains the framework concept?
- A. Preservation should be selected when the scenario matches this purpose: Preservation protects evidence and relevant data from alteration, deletion, contamination, or loss.
- B. Legal hold should be selected when the scenario matches this purpose: Legal hold requires relevant data to be preserved because it may be needed for litigation, investigation, or regulatory purposes.
- C. Reconnaissance should be selected when the scenario matches this purpose: Reconnaissance is the attack phase where an adversary gathers information about targets, technologies, people, and weaknesses before attempting compromise.
- D. Data and log analysis should be selected when the scenario matches this purpose: Data and log analysis examines collected events, telemetry, files, and records to reconstruct activity and identify incident facts.
Reconnaissance is the attack phase where an adversary gathers information about targets, technologies, people, and weaknesses before attempting compromise. This matches the incident response scenario without shifting to a related but different framework, activity, or phase. This is the correct answer.
An analyst is mapping attacker behavior using Weaponization. Which choice best explains the framework concept?
- A. Remediation should be selected when the scenario matches this purpose: Remediation fixes the root issue or weakness that allowed or contributed to the incident.
- B. Re-imaging should be selected when the scenario matches this purpose: Re-imaging replaces a compromised or unreliable system image with a clean, trusted image.
- C. Compensating controls should be selected when the scenario matches this purpose: Compensating controls are alternate safeguards used when the preferred control or full fix cannot be implemented immediately.
- D. Weaponization should be selected when the scenario matches this purpose: Weaponization is the attack phase where an adversary prepares a payload, exploit, or delivery package for use against a target.
Weaponization is the attack phase where an adversary prepares a payload, exploit, or delivery package for use against a target. This matches the incident response scenario without shifting to a related but different framework, activity, or phase. This is the correct answer.
An investigation must avoid mixing attack phases and analysis models. Which scenario best matches Cyber kill chain?
- A. A scenario matches Isolation when the responder needs this distinction: Isolation separates affected systems, accounts, or networks to prevent spread or continued attacker access.
- B. A scenario matches Remediation when the responder needs this distinction: Remediation fixes the root issue or weakness that allowed or contributed to the incident.
- C. A scenario matches Cyber kill chain when the responder needs this distinction: The cyber kill chain is a phased model that describes common stages of an attack from reconnaissance through actions on objectives.
- D. A scenario matches Re-imaging when the responder needs this distinction: Re-imaging replaces a compromised or unreliable system image with a clean, trusted image.
The cyber kill chain is a phased model that describes common stages of an attack from reconnaissance through actions on objectives. This distinction matters because choosing a nearby concept would change the evidence handling, response action, framework mapping, or improvement step. This is the correct answer.
An investigation must avoid mixing attack phases and analysis models. Which scenario best matches Reconnaissance?
- A. A scenario matches Playbooks when the responder needs this distinction: Playbooks are predefined step-by-step procedures for responding to common incident types or security events.
- B. A scenario matches Tabletop exercise when the responder needs this distinction: A tabletop exercise is a discussion-based incident response practice session that walks through a scenario without performing live technical actions.
- C. A scenario matches Training when the responder needs this distinction: Training prepares personnel to understand incident response roles, tools, processes, communication, and decision-making.
- D. A scenario matches Reconnaissance when the responder needs this distinction: Reconnaissance is the attack phase where an adversary gathers information about targets, technologies, people, and weaknesses before attempting compromise.
Reconnaissance is the attack phase where an adversary gathers information about targets, technologies, people, and weaknesses before attempting compromise. This distinction matters because choosing a nearby concept would change the evidence handling, response action, framework mapping, or improvement step. This is the correct answer.
A senior analyst must describe attacker behavior precisely for the report and investigation. Which answer applies Cyber kill chain most accurately?
- A. Root cause analysis is the best answer when the incident response decision depends on this exact meaning: Root cause analysis identifies the underlying technical or process cause of an incident so it can be corrected.
- B. Lessons learned is the best answer when the incident response decision depends on this exact meaning: Lessons learned capture what worked, what failed, and what should change after an incident.
- C. Incident evidence handling is the best answer when the incident response decision depends on this exact meaning: Incident evidence handling protects the reliability, integrity, legal usefulness, and investigative value of collected artifacts.
- D. Cyber kill chain is the best answer when the incident response decision depends on this exact meaning: The cyber kill chain is a phased model that describes common stages of an attack from reconnaissance through actions on objectives.
The cyber kill chain is a phased model that describes common stages of an attack from reconnaissance through actions on objectives. This applies the concept at the decision point where the wrong term would lead to an incorrect incident response, reporting, or post-incident action. This is the correct answer.
Link to this quiz
Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:
https://quizbuffet.com/comptia-cysa-plus/incident-response-management/
<a href="https://quizbuffet.com/comptia-cysa-plus/incident-response-management/">CompTIA CySA+ Incident Response Management practice quiz on QuizBuffet</a>
Other CS0-003 Domains
← Back to CS0-003 practice test overview
Questions are written against the published CS0-003 objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.