CompTIA CySA+ CS0-003 (V3) Practice Question

A cybersecurity analyst is responding to a security breach where attackers compromised a public-facing web application. Following a standard incident response process, which of the following is the most critical initial step to take during the detection and analysis phase to gather evidence of the attacker's activity?

  • Immediately reviewing all account integrity for signs of compromise

  • Performing an exhaustive code review on the current web applications

  • Examining user behavior patterns for anomalies in application usage

  • Securing and analyzing the web server logs

CompTIA CySA+ CS0-003 (V3)
Incident Response and Management
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

SAVE $51
$425.00 $374.00
SAVE $57
CompTIA Cybersecurity Analyst Voucher with Retake
CySA+ / v3 / CS0-003
Includes Retake
$474.00 $417.00
Bash, the Crucial Exams Chat Bot
AI Bot