CompTIA CySA+ CS0-003 (V3) Practice Question

During an incident investigation, you discover that attackers compromised a user workstation with a phishing email, then used stolen domain credentials to pivot over SMB into nearby file servers and the ERP database. Endpoint antivirus logs show only generic process-injection alerts, and every asset resides on the same internal subnet. Which recommendation in your incident-response report would most directly reduce the likelihood of similar lateral movement?

  • Implement internal network segmentation using VLANs and firewall rules between user, application, and database tiers.

  • Upgrade the endpoint antivirus engine to the latest version on all workstations.

  • Mandate complex passwords and a 90-day expiration policy for all domain accounts.

  • Deploy a 24×7 managed security service provider (MSSP) to monitor SIEM alerts.

CompTIA CySA+ CS0-003 (V3)
Reporting and Communication
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

SAVE $51
$425.00 $374.00
SAVE $57
CompTIA Cybersecurity Analyst Voucher with Retake
CySA+ / v3 / CS0-003
Includes Retake
$474.00 $417.00
Bash, the Crucial Exams Chat Bot
AI Bot