CySA+ Domain 3: Incident Response & Management
Domain 3.0: Incident Response and Management · 24% of the exam
What happens when something gets through: all 3 objectives (3.1–3.3), across the Cyber Kill Chain, Diamond Model and MITRE ATT&CK, the seven-phase response process, and every technique from evidence handling to root cause analysis. Follow a live hospital ransomware incident from the 04:12 alert to the regulator submission, with a full reconstructed timeline.
All study guides, current and every new one.
- Interactive online guide
- Downloadable PDF
- Lifetime updates
- 30-day money-back guarantee
Secure checkout via Stripe · no account needed · instant access
24% of your exam score
Domain 3.0 is worth 24% of the CS0-004 exam. Walk in having mastered it, not hoping it doesn't come up.
Every objective, nothing extra
Built line by line from the official CompTIA CySA+ objectives 3.1–3.3: 20 in-depth topics with worked scenarios and exam tips, in a 89-page guide you'll actually finish.
60 exam-style questions
Every question comes with instant feedback and a full explanation, so a wrong answer teaches you as much as a right one.
The analyst's cert, freshly rewritten
CySA+ is the step past Security+ into SOC and vulnerability analyst roles, and CS0-004 is the brand-new V4 blueprint, including the first AI objective CompTIA has put on a CySA+ exam.
Serving, transitioning, or a military spouse?
CySA+ appears in the DoD 8140 qualification matrix. See how it maps to work roles, which credentialing program your branch runs, and what it will and will not pay for. Read the DoD 8140 guide →
Read a real excerpt, free
This is the actual opening of Module 3.1, Attack methodology frameworks, not marketing copy. If you like how it teaches, the rest of the guide reads the same way.
Summarize concepts related to attack methodology frameworks
Three frameworks, three different questions: where in the sequence, how the pieces relate, and what exactly was done.
At 04:12 on a Tuesday, Meridian Health's SOC took the call that changes a shift. Nadia Okonkwo's phone showed the alert Rafael had escalated eleven minutes earlier: mass file modification across a shared drive, shadow copies deleted, and a ransom note in three directories.
Over the next four days the team would need to explain what happened — to each other during the response, to executives on day two, to regulators on day four. Three different audiences, three different questions, and the frameworks in this objective exist because each one answers a different question well.
3.1 is a “summarize” objective with only three named items, which makes it small and highly predictable. Nearly every question resolves to picking the right framework for a stated purpose. Sequence or phases → Cyber Kill Chain. Relationships between actor, tooling, infrastructure and target → Diamond Model. Naming or classifying an observed behaviour → MITRE ATT&CK.
The Cyber Kill Chain
Developed by Lockheed Martin, the Cyber Kill Chain models an intrusion as seven sequential phases. Its central claim is operationally useful: the adversary must complete every phase to succeed, so breaking any single link stops the attack.
| Phase | What the adversary does | Where you break it |
|---|---|---|
| 1. Reconnaissance | Researches the target — staff, technology, exposed services, email addresses. | Reduce public exposure; monitor for typosquat domain registration. |
| 2. Weaponization | Pairs an exploit or payload with a delivery vehicle. Happens entirely on their infrastructure. | You cannot observe or interrupt this phase — a genuine limitation of the model. |
| 3. Delivery | Transmits it — email, compromised site, removable media, third-party access. | Mail filtering, web proxy, awareness training, vendor access control. |
| 4. Exploitation | Triggers the vulnerability to execute code. | Patching (all of Domain 2), hardening, application allow-listing. |
| 5. Installation | Establishes persistence so access survives a reboot. | EDR, monitoring of registry Run keys, scheduled tasks, services. |
| 6. Command and control | Opens a channel back to the operator. | Egress filtering, DNS monitoring, beaconing detection from objective 1.2. |
| 7. Actions on objectives | Does what they came for — exfiltration, encryption, destruction, lateral movement. | DLP, segmentation, least privilege, backup integrity. |
Worth knowing, because CompTIA presents these frameworks as complementary rather than authoritative. The Kill Chain is linear, while real intrusions loop — an adversary re-runs reconnaissance internally, exploits again to move laterally, and installs on each new host. It is also perimeter- and malware-centric, which fits it poorly to insider threats, credential-only attacks that never drop a payload, and cloud control-plane compromise where there is no delivery phase in any recognizable sense.
Not ready to buy? Read it later.
We'll email you a free sample of this guide as a PDF, no purchase needed.
Try 3 sample questions
Pulled straight from the guide's 60-question bank. Tap an answer for instant feedback and the explanation.
From module 3.1 · Attack methodology frameworks
1. An analyst wants to document one intrusion in terms of the relationships between the actor, the tooling used, the servers it was operated from, and the target. Which framework fits?
From module 3.2 · The incident response process
1. Which sequence correctly orders the CS0-004 incident response phases?
From module 3.3 · Incident response techniques
1. A compromised laptop is powered on and connected. Following the order of volatility, what is collected first?
57 more questions like these are waiting inside.
What's inside
- 20 in-depth topics across 3 modules, mapped to objectives 3.1–3.3
- 60 exam-style practice questions with instant feedback
- Full answer key explaining why every distractor is wrong
- A live ransomware incident followed end to end
- Complete CySA+ acronym & key-term reference
- 89-page downloadable PDF for offline study and printing
- Lifetime updates as the exam evolves
The modules, mapped to the objectives
- 3.120 Qs
Attack methodology frameworks
Summarize concepts related to attack methodology frameworks.
Cyber Kill Chain — seven phasesDiamond Model — four verticesMITRE ATT&CK tactics vs. techniquesTechnique IDs and shared vocabularyPivoting across the DiamondBreaking the chain - 3.220 Qs
The incident response process
Summarize the incident response process.
Preparation, detection, analysisContainment before eradicationShort-term vs. long-term containmentEradication and root causeRecovery and validationPost-incident and the feedback loop - 3.320 Qs
Incident response techniques
Given a scenario, implement incident response techniques.
Order of volatilityChain of custody & legal holdTriage, timeline & severityIsolation without tipping offTabletop vs. simulationRoot cause & corrective action

About the author
Chris Rees
Professional information technologist with 25+ years in IT and the author of 51 certification training courses, 50+ live on Pluralsight, rated 4.6/5 across more than 2,000 reviews. This guide is that same exam-focused teaching, in a format you can finish.
More about ChrisSitting the whole exam? Get the Complete CySA+ Collection.
Every domain of the exam, including this guide, for $59, one time.
See everything insideQuestions, answered
Do I need an account to buy?
No. Checkout is a single Stripe form: email and card, about 30 seconds. We create your access from your checkout email automatically and sign you in the moment payment completes.
Is this up to date with the real CS0-004 exam?
Yes. The guide is mapped module-by-module to the official CompTIA CySA+ objectives (3.1–3.3), and lifetime updates are included, so as the exam evolves your guide does too.
What exactly do I get?
Instant access to the interactive online guide with all 60 practice questions, plus a 89-page PDF you can download, print, and keep forever.
Do I need the other domains too?
This guide covers Domain 3.0 (24% of the exam). To prepare for the whole exam, the Complete CySA+ Collection bundles all 4 domains for $59, less than the price of three guides.
What if it isn't for me?
Every purchase comes with a 30-day money-back guarantee. Email us and we'll refund you, no hoops.
Who wrote it?
Chris Rees, a professional information technologist with 25+ years in IT and the author of 51 certification courses published on Pluralsight, rated 4.6/5 across 2,007 ratings.
Be ready for 24% of the exam, for $19.95
Instant access, lifetime updates, and a 30-day money-back guarantee. The only risk is walking into the exam without it.
Get the guide