Cyber Questline

CompTIA CySA+ CS0-003 Study Guide: Incident Response and Management

Coverage: CySA+ domain 3.0 Incident Response and Management Purpose: Original study material built from the supplied CySA+ courseware and exam-objective coverage. This is not copied exam content.

How To Use This Guide

  1. Read the high-yield anchors first.
  2. Study each topic until you can explain the analyst action without looking.
  3. Run a practice test and review every missed item.
  4. Return to the section named in the missed-question remediation.
  5. For lab-style readiness, practice with logs, PCAPs, scanners, command output, and short written findings.

Exam Context

High-Yield Memory Anchors

Domain Map

Visual Model

Incident response lifecycleInspired by NIST incident response guidance: preparation supports the active detect, respond, and recover cycle.
Prepare
Detect
Analyze
Contain
Eradicate
Recover
Lessons learned

Study Notes

Incident response plan

Big Picture

Define roles, escalation paths, communication channels, and response procedures before incidents occur.

Analyst Actions

Evidence To Look For

IR plan, call tree, playbooks, severity matrix, and tabletop records.

Exam Traps

Hands-On Practice

Preparation

Big Picture

Build tools, access, playbooks, logging, contacts, and training before an event.

Analyst Actions

Evidence To Look For

Jump kits, playbooks, access validation, contact lists, and tabletop outcomes.

Exam Traps

Hands-On Practice

Detection and analysis

Big Picture

Validate alerts, identify affected assets, scope activity, and determine likely cause.

Analyst Actions

Evidence To Look For

SIEM events, EDR alerts, firewall logs, DNS logs, and user reports.

Exam Traps

Hands-On Practice

Containment

Big Picture

Limit spread while preserving critical evidence and business function.

Analyst Actions

Evidence To Look For

Network isolation, account disablement, firewall blocks, and containment notes.

Exam Traps

Hands-On Practice

Eradication

Big Picture

Remove attacker access, malware, persistence, and exploited weaknesses.

Analyst Actions

Evidence To Look For

Removed persistence, patched weakness, credential reset, and malware cleanup evidence.

Exam Traps

Hands-On Practice

Recovery

Big Picture

Restore systems safely and monitor for recurrence.

Analyst Actions

Evidence To Look For

Restore records, validation scans, monitoring windows, and owner sign-off.

Exam Traps

Hands-On Practice

Lessons learned

Big Picture

Review what happened and improve controls, playbooks, training, and detections.

Analyst Actions

Evidence To Look For

After-action report, timeline, root cause, and improvement backlog.

Exam Traps

Hands-On Practice

Digital forensics

Big Picture

Collect, preserve, analyze, and report evidence using repeatable methods.

Analyst Actions

Evidence To Look For

Disk images, memory captures, hashes, timestamps, and examiner notes.

Exam Traps

Hands-On Practice

Chain of custody

Big Picture

Document who handled evidence, when, why, and how it was stored.

Analyst Actions

Evidence To Look For

Custody forms, hash values, transfer records, and secure storage logs.

Exam Traps

Hands-On Practice

Big Picture

Understand privacy, notification, law enforcement, retention, and counsel involvement.

Analyst Actions

Evidence To Look For

Legal hold, breach notification timeline, counsel guidance, and retention rules.

Exam Traps

Hands-On Practice

Malware indicators

Big Picture

Identify suspicious files, processes, persistence, registry changes, and network callbacks.

Analyst Actions

Evidence To Look For

Process trees, autoruns, hashes, C2 traffic, and file paths.

Exam Traps

Hands-On Practice

Network attack indicators

Big Picture

Recognize scanning, beaconing, brute force, exfiltration, DNS tunneling, and ARP poisoning clues.

Analyst Actions

Evidence To Look For

Flow logs, packet captures, DNS logs, failed authentication, and unusual volume.

Exam Traps

Hands-On Practice

Host attack indicators

Big Picture

Identify suspicious services, accounts, scheduled tasks, logs, and privilege escalation signs.

Analyst Actions

Evidence To Look For

Event logs, shell history, running services, cron/scheduled tasks, and account changes.

Exam Traps

Hands-On Practice

Deep Review Table

TopicBest EvidenceBest Action
Incident response planIR plan, call tree, playbooks, severity matrix, and tabletop recordsFollow the plan and escalate when severity or scope changes.
PreparationJump kits, playbooks, access validation, contact lists, and tabletop outcomesVerify readiness before the incident starts.
Detection and analysisSIEM events, EDR alerts, firewall logs, DNS logs, and user reportsCorrelate data sources before declaring scope.
ContainmentNetwork isolation, account disablement, firewall blocks, and containment notesChoose short-term and long-term containment based on severity and impact.
EradicationRemoved persistence, patched weakness, credential reset, and malware cleanup evidenceEliminate root cause after containment.
RecoveryRestore records, validation scans, monitoring windows, and owner sign-offValidate clean state before returning assets to production.
Lessons learnedAfter-action report, timeline, root cause, and improvement backlogHold a blameless review and assign corrective actions.
Digital forensicsDisk images, memory captures, hashes, timestamps, and examiner notesPreserve integrity and document actions.
Chain of custodyCustody forms, hash values, transfer records, and secure storage logsMaintain evidence admissibility and integrity.
Legal considerationsLegal hold, breach notification timeline, counsel guidance, and retention rulesEscalate legal-sensitive issues through approved channels.
Malware indicatorsProcess trees, autoruns, hashes, C2 traffic, and file pathsCorrelate host and network evidence.
Network attack indicatorsFlow logs, packet captures, DNS logs, failed authentication, and unusual volumeUse network telemetry to scope malicious behavior.
Host attack indicatorsEvent logs, shell history, running services, cron/scheduled tasks, and account changesCompare host state against baseline.

Scenario Drill

For each scenario below, write the evidence you would collect, the most likely risk, the next action, and the communication target.

  1. A critical internet-facing server has a remotely exploitable vulnerability, but the application owner says the next maintenance window is three weeks away.
  2. A SIEM alert shows a user authenticating from two countries within ten minutes.
  3. DNS logs show repeated long random-looking subdomains from one workstation.
  4. A vulnerability scanner reports a critical finding on an OT device that cannot be rebooted during business hours.
  5. Leadership asks whether a recent incident is contained, but analysis is still underway.

Final Review Checklist