CompTIA CySA+ CS0-003 Practice Question

During the monitoring phase, an anomaly is detected in the network traffic pattern indicating potential exfiltration of sensitive data. The security analyst observes a consistent high volume of outbound traffic heading to an unusual external IP address. What should the analyst do FIRST in accordance with incident declaration and escalation practices?

  • You selected this option

    Immediately disconnect the network to prevent further potential data loss without validating the incident.

  • You selected this option

    Follow the organizational incident response plan to determine if the observed activity meets the criteria for incident declaration and escalate as required.

  • You selected this option

    Draft an executive summary of the event to be distributed to all employees to ensure company-wide awareness.

  • You selected this option

    Contact law enforcement for immediate investigation before taking any internal response measures.

CompTIA CySA+ CS0-003
Reporting and Communication
Your Score:
Settings & Objectives
N/A
N/A
N/A
N/A
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot