Objective 3.3CS0-003

3.3 Explain the preparation and post-incident activity phases of the incident management life cycle.

Objective 3.3 sits in Incident Response and Management, which carries 20% of the CySA+ exam. The questions below are original, written from the official objective title above, and each explanation cites the CompTIA page it rests on.

Objective title verbatim from the official objectives. CompTIA exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

3-3Incident Response and ManagementModerate

Before any real incident, a security manager wants the organization to talk through a ransomware scenario and test its readiness. What are CISA's tabletop packages for?

Running live-fire penetration testsLive technical attacks are a different exercise class entirely.
Replacing the incident response planExercises test the plan; they do not stand in for it.
Certifying responders for complianceNo certification attaches to running a tabletop.
Starting discussions on threat readinessCorrect · your answerCorrect: they start structured discussions about readiness for threat scenarios.

Correct.

Concept

Preparation includes rehearsal. A discussion-based exercise walks the team through a scenario on paper, exposing gaps in plans and roles while the stakes are still zero.

Why D

CTEPs assist stakeholders in conducting their own exercises and initiate discussions within their organizations about their ability to address a variety of threat scenarios.

#tabletop#preparation#incident-management

Now you: objective 3.3 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

3-3Incident Response and ManagementModerate

An exercise planner on your team asks what ships inside a CISA tabletop package to build from. What does each package include?

Sample question 2 of 3

3-3Incident Response and ManagementModerate

After a tabletop concludes, the planning team wants participant input captured and findings written up formally. Which CTEP templates support that?

Sample question 3 of 3

3-3Incident Response and ManagementHard

A CISO asks the team for one exercise probing intelligence sharing before an incident, actions during it, and recovery after. Do the CTEP materials support that span?

Full CySA+ question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Incident Response and Management