Objective 3.2CS0-003

3.2 Given a scenario, perform incident response activities.

Objective 3.2 sits in Incident Response and Management, which carries 20% of the CySA+ exam. The questions below are original, written from the official objective title above, and each explanation cites the CompTIA page it rests on.

Objective title verbatim from the official objectives. CompTIA exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

3-2Incident Response and ManagementModerate

Your team contains a compromised host by cutting its paths to the rest of the network. Which D3FEND tactic describes this move?

EvictEviction removes the adversary; this step only walls them off.
RestoreRestore returns systems to a better state after the threat is out.
IsolateCorrect · your answerCorrect: barriers that limit further access are the isolate tactic.
ModelModeling is inventory and mapping work done before response.

Correct.

Concept

Containment buys time: barriers placed around compromised assets keep an intruder from converting one foothold into many while investigation proceeds.

Why C

The isolate tactic creates logical or physical barriers in a system which reduces opportunities for adversaries to create further accesses, which is what containment does.

#containment#d3fend#incident-response

Now you: objective 3.2 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

3-2Incident Response and ManagementModerate

During containment, a team wants network-level authorization checks on any user or process connecting over the LAN, WAN, or internet. Which technique is that?

Sample question 2 of 3

3-2Incident Response and ManagementHard

An IR review finds responders' emergency admin access never expires, accumulating rights long after incidents close. Which access-mediation practice fixes that?

Sample question 3 of 3

3-2Incident Response and ManagementModerate

With containment holding, the response team moves to force the adversary out of the network entirely. Which D3FEND tactic covers that phase?

Full CySA+ question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Incident Response and Management