CompTIA CS0-003 Exam Questions
CompTIA CySA+ (CS0-003) (Page 8 )

Updated On: 24-Feb-2026

When starting an investigation, which of the following must be done first?

  1. Notify law enforcement
  2. Secure the scene
  3. Seize all related evidence
  4. Interview the witnesses

Answer(s): B



Which of the following describes how a CSIRT lead determines who should be communicated with and when during a security incident?

  1. The lead should review what is documented in the incident response policy or plan
  2. Management level members of the CSIRT should make that decision
  3. The lead has the authority to decide who to communicate with at any t me
  4. Subject matter experts on the team should communicate with others within the specified area of expertise

Answer(s): A



A new cybersecurity analyst is tasked with creating an executive briefing on possible threats to the organization.
Which of the following will produce the data needed for the briefing?

  1. Firewall logs
  2. Indicators of compromise
  3. Risk assessment
  4. Access control lists

Answer(s): C



An analyst notices there is an internal device sending HTTPS traffic with additional characters in the header to a known-malicious IP in another country.
Which of the following describes what the analyst has noticed?

  1. Beaconing
  2. Cross-site scripting
  3. Buffer overflow
  4. PHP traversal

Answer(s): A



A security analyst is reviewing a packet capture in Wireshark that contains an FTP session from a potentially compromised machine. The analyst sets the following display filter: ftp. The analyst can see there are several RETR requests with 226 Transfer complete responses, but the packet list pane is not showing the packets containing the file transfer itself.
Which of the following can the analyst perform to see the entire contents of the downloaded files?

  1. Change the display filter to ftp.active.port
  2. Change the display filter to tcp.port==20
  3. Change the display filter to ftp-data and follow the TCP streams
  4. Navigate to the File menu and select FTP from the Export objects option

Answer(s): C






Post your Comments and Discuss CompTIA CS0-003 exam dumps with other Community members:

Join the CS0-003 Discussion