CompTIA CySA+ exam (CS0-003) - CompTIA Actual Exam Questions
Last updated on April 15, 2026
Which of the following is an important aspect that should be included in the lessons-learned step after an incident?
Identify any improvements or changes in the incident response plan or procedures
Determine if an internal mistake was made and who did it so they do not repeat the error
Present all legal evidence collected and turn it over to iaw enforcement
Discuss the financial impact of the incident to determine if security controls are well spent
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
A security administrator needs to import Pll data records from the production environment to the test environment for testing purposes. Which of the following would best protect data confidentiality?
Data masking
Hashing
Watermarking
Encoding
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
A cybersecurity analyst notices unusual network scanning activity coming from a country that the company does not do business with. Which of the following is the best mitigation technique?
Geoblock the offending source country
Block the IP range of the scans at the network firewall.
Perform a historical trend analysis and look for similar scanning activity.
Block the specific IP address of the scans at the network firewall
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
After identifying a threat, a company has decided to implement a patch management program to remediate vulnerabilities. Which of the following risk management principles is the company exercising?
Transfer
Accept
Mitigate
Avoid
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
A security analyst needs to secure digital evidence related to an incident. The security analyst must ensure that the accuracy of the data cannot be repudiated. Which of the following should be implemented?
Offline storage
Evidence collection
Integrity validation
Legal hold
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
Finish Practice?
Are you sure you want to finish? This will end your practice session.