CompTIA CySA+ CS0-003 (V3) Practice Question

A cybersecurity analyst is in the initial reconnaissance phase of a penetration test for a client with a mature security posture, including a well-monitored network with sensitive intrusion detection systems (IDS). The analyst's primary goal is to gather information about the client's internet-facing assets, such as open ports and running services, without triggering any alerts that would reveal the assessment is underway. Which of the following techniques would be the most suitable for this initial, covert information-gathering stage?

  • Using Nmap to perform a service discovery scan

  • Performing ARP cache poisoning to map out the network

  • Sending ICMP echo requests ('ping') to enumerate live hosts

  • Analyzing data from Internet-wide search engines such as Shodan

CompTIA CySA+ CS0-003 (V3)
Vulnerability Management
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

SAVE $51
$425.00 $374.00
SAVE $57
CompTIA Cybersecurity Analyst Voucher with Retake
CySA+ / v3 / CS0-003
Includes Retake
$474.00 $417.00
Bash, the Crucial Exams Chat Bot
AI Bot