CompTIA CySA+ CS0-003 (V3) Practice Question

An analyst is monitoring network traffic and observes a series of suspicious, but not definitively malicious, port scans originating from an internal IP address targeting a critical database server. According to best practices, what is the most appropriate basis for deciding whether to declare this an incident and escalate it?

  • Waiting for the system to generate a critical-level automated alert.

  • Predefined criteria and thresholds documented in the incident response plan.

  • The analyst's personal judgment and experience with similar events.

  • Confirmation from the database administrator that an active compromise has occurred.

CompTIA CySA+ CS0-003 (V3)
Reporting and Communication
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

SAVE $51
$425.00 $374.00
SAVE $57
CompTIA Cybersecurity Analyst Voucher with Retake
CySA+ / v3 / CS0-003
Includes Retake
$474.00 $417.00
Bash, the Crucial Exams Chat Bot
AI Bot