CompTIA CySA+ CS0-003 (V3) Practice Question

A security analyst at a financial institution is reviewing a new bulletin from the national Computer Emergency Response Team (CERT). The bulletin describes a phishing campaign targeting the financial sector and includes specific malware hashes and command-and-control (C2) server IP addresses. What is the most effective immediate action for the analyst to take with this information?

  • Archive the bulletin and its IoCs for inclusion in the next quarterly risk assessment report.

  • Integrate the malware hashes and IP addresses into the SIEM and EDR systems to hunt for existing compromises and create new detection rules.

  • Immediately disconnect the primary internet connection to prevent any potential C2 communication.

  • Forward the bulletin to all employees to warn them about the new phishing campaign.

CompTIA CySA+ CS0-003 (V3)
Security Operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

SAVE $51
$425.00 $374.00
SAVE $57
CompTIA Cybersecurity Analyst Voucher with Retake
CySA+ / v3 / CS0-003
Includes Retake
$474.00 $417.00
Bash, the Crucial Exams Chat Bot
AI Bot