Free CompTIA CS0-003 Exam Braindumps (page: 14)

Which of the following is an important aspect that should be included in the lessons-learned step after an incident?

  1. Identify any improvements or changes in the incident response plan or procedures
  2. Determine if an internal mistake was made and who did it so they do not repeat the error
  3. Present all legal evidence collected and turn it over to iaw enforcement
  4. Discuss the financial impact of the incident to determine if security controls are well spent

Answer(s): A



The security operations team is required to consolidate several threat intelligence feeds due to redundant tools and portals.
Which of the following will best achieve the goal and maximize results?

  1. Single pane of glass
  2. Single sign-on
  3. Data enrichment
  4. Deduplication

Answer(s): A



Which of the following would a security analyst most likely use to compare TTPs between different known adversaries of an organization?

  1. MITRE ATT&CK
  2. Cyber Kill Cham
  3. OWASP
  4. STIX/TAXII

Answer(s): A



An analyst is remediating items associated with a recent incident. The analyst has isolated the vulnerability and is actively removing it from the system.
Which of the following steps of the process does this describe?

  1. Eradication
  2. Recovery
  3. Containment
  4. Preparation

Answer(s): A






Post your Comments and Discuss CompTIA CS0-003 exam prep with other Community members:

CS0-003 Exam Discussions & Posts