← Back

19 Incident Reporting & Metrics Practice Questions & Answers

Every Incident Reporting & Metrics practice question from the CompTIA CySA+ Practice Test, with the correct answer and a short explanation.

Start practice test →
  1. 1. An analyst is writing the incident record. The evidence is a proxy log entry showing 1.8 GB sent from a workstation to an unfamiliar external host over TLS, and an endpoint log showing an archive utility ran on that workstation minutes earlier. No inventory of the archive's contents exists. How should the record state this?

    • A.Record the proxy transfer and the archive process as observed evidence, and record probable exfiltration of file-share data as an assessment with its confidence and the evidence still missing.✓ Answer
    • B.Record the transfer as confirmed exfiltration of file-share data, since 1.8 GB of TLS traffic to an unknown host right after an archive utility ran admits no other realistic reading.
    • C.Record only the two log entries and keep every interpretation out of the written case file, because analytic wording could later be challenged by opposing counsel in litigation.
    • D.Record the event as a probable false positive until the archive contents are recovered, and omit the transfer detail so that leadership is not alarmed by an unproven claim.

    An incident record is only defensible later if a reader can tell what was measured from what was concluded. The proxy byte count and the archive process are observations; 'data was exfiltrated' is an inference, so it belongs in the record as a judgement with a confidence level and a statement of what would confirm or overturn it. Deleting the hypothesis leaves responders no direction, and stating it as fact is what collapses under scrutiny.

    Source: CompTIA CySA+ CS0-004 Exam Objectives, Objective 4.2 — post-incident reporting (after action report): separating observed fact from analytic judgementReport a problem with this question

  2. 2. During containment three responders acted: one blocked an external address at the perimeter, one disabled a user account, and one removed a laptop from the network. The ticket says only 'host contained, account handled, traffic blocked.' What is the MOST important correction to the record?

    • A.Write each action as its own entry, naming the person who performed it, the exact time it took effect, and the system it was applied on.✓ Answer
    • B.Add the tool category and the rule syntax used for the perimeter block, so another analyst can reproduce that same filter later on.
    • C.Attach the severity rating and the business impact estimate, so that the entry matches what the executive summary is going to say.
    • D.Replace the wording with the playbook step numbers that were executed, since the playbook already defines who owns each of those steps.

    A response record has to answer 'who did what to which system, and when' because containment actions themselves change the evidence and the environment. Without an actor and a timestamp per action, nobody can rebuild the timeline, prove that a change was authorized, or tell an attacker's activity apart from a responder's. Tool syntax, severity and playbook numbers are useful context but none of them establishes accountability or sequence.

    Source: CompTIA CySA+ CS0-004 Exam Objectives, Objective 4.2 — post-incident reporting (after action report): documented actions taken, with time and actorReport a problem with this question

  3. 3. The team reports that the intrusion was limited to two servers and that there is no evidence of lateral movement. Authentication logging is centralized for the server estate, but roughly a third of workstations forward no endpoint telemetry. How should the scope section be written?

    • A.State the confirmed scope as final, because an exhaustive search of every centralized log returned no indication of activity beyond the two affected servers at all.
    • B.State that scope cannot be established in any form while a telemetry gap exists, and leave the section open until the missing workstation coverage has been deployed.
    • C.State the confirmed scope, then state that the absence of lateral movement is asserted only for the estate that forwards telemetry, and name the unmonitored segment.✓ Answer
    • D.State the confirmed scope and add that the unmonitored workstations are presumed clean, since no user on that segment reported unusual behaviour during the period.

    'No evidence of X' is only as strong as the visibility behind it, so a scope statement must carry the boundary of what could be searched. Naming the unmonitored third converts an overclaim into a bounded finding and simultaneously documents a real gap that the review can act on. Presuming unmonitored hosts clean on the strength of no user complaints is an assumption dressed as a conclusion, and refusing to state any scope withholds the information stakeholders need.

    Source: CompTIA CySA+ CS0-004 Exam Objectives, Objective 4.2 — post-incident reporting: documented scope and residual uncertaintyReport a problem with this question

  4. 4. Six hours into a live intrusion, the response lead is answering individual questions from managers, legal and two executives as they arrive, and each answer differs slightly as new findings land. What change should be made to the communication?

    • A.Route all questions to the legal team for an authorized answer, so that a single reviewer controls every statement about the incident before anyone hears it.
    • B.Answer every requester the moment any new finding lands, so that no stakeholder is ever holding information that is even a few minutes out of date.
    • C.Move to a scheduled update at a fixed interval, issued by one named coordinator, that separates confirmed findings from current working hypotheses.✓ Answer
    • D.Suspend stakeholder updates until containment is verified and then issue one complete account, so that nothing provisional is ever put before management.

    A stream of raw findings is worse than a slower cadence because early readings change, and stakeholders who each hold a different version start making decisions on contradictory facts. A fixed-interval situation report from one coordinator gives everyone the same picture at the same time and forces the writer to label what is confirmed versus assumed. Silence until closure denies management the information it needs to make business decisions during the incident.

    Source: CompTIA CySA+ CS0-004 Exam Objectives, Objective 4.2 — communication plan (stakeholder identification; communication channels)Report a problem with this question

  5. 5. An executive summary is being written for a board that will read nothing else about the incident. The investigation continues and the root cause is not yet confirmed. Which content is MOST appropriate?

    • A.A plain account of what happened, the business impact known so far, current status, the decision requested, and which conclusions remain provisional.✓ Answer
    • B.A timeline of every analyst action taken so far with the indicators recovered from each host, so the board can see the depth of the work performed.
    • C.A statement of the confirmed root cause and the remediation plan, written without qualifiers, because a briefing to a board must not read as indecisive.
    • D.A mapping of the attacker's observed techniques to a public framework, together with the detection logic written to catch a repeat of the activity.

    An executive summary exists to let someone who reads only that page decide something, so it is organized around impact, status, the ask and the confidence attached to each claim. Presenting an unconfirmed cause as settled fact is the failure that destroys credibility when the finding changes, and indicator lists, per-host timelines and framework mappings are the technical annexes this audience will not use. Saying plainly which parts are provisional is what makes the rest trustworthy.

    Source: CompTIA CySA+ CS0-004 Exam Objectives, Objective 4.2 — executive summaryReport a problem with this question

  6. 6. An intrusion is in progress and the adversary is known to hold valid credentials for the corporate identity provider, which also fronts corporate mail and the chat platform. The response team must coordinate for several more hours. What should they do?

    • A.Coordinate on a pre-arranged channel outside the affected identity and mail systems, and record in the case why that channel was chosen.✓ Answer
    • B.Continue on corporate chat but open a private channel restricted to responders, so that the discussion is not visible to any other staff.
    • C.Continue on corporate mail with the incident thread encrypted, so that the content stays unreadable even if the mailbox itself is accessed.
    • D.Move coordination onto personal mobile messaging accounts chosen by each responder, so that no company-managed service carries any of it.

    While an intruder holds identity to the platforms the team would talk on, those platforms are part of the compromised estate: the adversary can read the plan, see when containment is scheduled and adapt. An out-of-band channel agreed before the incident preserves confidentiality and is documented as a deliberate decision, whereas ad-hoc personal accounts leave the coordination unrecorded and outside any retention or legal hold. Encrypting a thread in a mailbox the attacker can open does not help.

    Source: CompTIA CySA+ CS0-004 Exam Objectives, Objective 4.2 — operational security awareness (communication channels)Report a problem with this question

  7. 7. An analyst confirms that a finance server has an interactive session from an address outside the company and an unknown service installed. The organization's plan lists this as meeting its incident criteria. What should the analyst do FIRST?

    • A.Notify the legal team and the regulatory liaison directly, because an intrusion involving a finance system creates an obligation to report externally.
    • B.Begin containment by pulling the server's network cable, because every further minute of attacker access widens the damage that has to be repaired.
    • C.Declare the incident under the plan's criteria and notify the incident lead, which starts the documented response and authorizes the actions that follow.✓ Answer
    • D.Collect a memory image and the running process list, because the volatile evidence of that session disappears the moment anything on the host changes.

    Detecting an event and declaring an incident are different acts: declaration is the documented decision that the criteria in the plan are met, and it is what starts the clock, activates the response team and the communication plan, and gives an analyst authority to take disruptive action. Evidence acquisition and containment are correct steps, but taken before declaration they are unauthorized changes to a system that is now evidence, and external notification is a decision for management and legal, not the first act of the analyst.

    Source: CompTIA CySA+ CS0-004 Exam Objectives, Objective 4.2 — incident declaration and escalationReport a problem with this question

  8. 8. A security operations manager reports the share of alerts closed by automated workflows with no analyst involvement. What does this measure legitimately tell the reader, and how can it mislead?

    • A.It shows how quickly the operation responds to intrusions, and it rises misleadingly when analysts begin spending longer on each investigation.
    • B.It shows how much routine work automation absorbs, and it rises misleadingly when workflows auto-close alert classes whose logic was never validated.✓ Answer
    • C.It shows the accuracy of the detection rules in use, and it falls misleadingly whenever the team writes new rules that generate additional alerts.
    • D.It shows the proportion of true positives in the queue, and it falls misleadingly when a noisy log source is withdrawn from collection entirely.

    This is a workload measure: it says what fraction of the queue never needed a human, which is what justifies the automation and frees analyst time for investigation. It says nothing about whether those closures were right, so it climbs exactly as fast when a workflow is silently disposing of real detections as when it is clearing genuine noise, which is why it has to be read next to the true-positive rate and a sample review of automated closures.

    Source: CompTIA CySA+ CS0-004 Exam Objectives, Objective 4.2 — metrics and KPIs (alert volume, true-positive rate) read together rather than aloneReport a problem with this question

  9. 9. A night-shift analyst must hand an open intrusion to the day shift. Which handover practice is BEST?

    • A.A summary emailed to the manager who will brief the incoming shift, keeping the case record free of interim notes that may later prove wrong.
    • B.A verbal walkthrough at the desk covering what happened overnight, so that the incoming analyst can ask questions and pick the work up immediately.
    • C.A message to the incoming analyst listing the alert identifiers involved, leaving the reconstruction of events to a fresh reading of the console.
    • D.A written handover in the case record: current severity, actions taken with their results, open items with owners, next steps, and approvals pending.✓ Answer

    A handover exists so that a 24x7 operation loses no context at the shift boundary: the incoming analyst must know the status, what was already tried and what it produced, what is still open and who owns it, and what approvals are in flight, or work is duplicated and a containment step is dropped. Written into the case record it is auditable and survives the person, which verbal-only or identifier-only handoffs do not, and interim notes are part of the timeline rather than something to hide.

    Source: CompTIA CySA+ CS0-004 Exam Objectives, Objective 4.2 — shift/incident handoverReport a problem with this question

  10. 10. A post-incident review is being scheduled. The last one produced a document nobody acted on, and staff withheld candour because an analyst was reprimanded afterwards. Which approach is MOST likely to produce change?

    • A.Restrict attendance to senior responders and the manager, so the discussion is candid and the findings are not distorted by junior speculation.
    • B.Have every participant document in writing the errors they personally made, so accountability is explicit and nobody repeats the same mistake.
    • C.Examine the response process rather than individual performance, and leave with prioritized actions that each carry an owner and a due date.✓ Answer
    • D.Keep the session to a factual reconstruction of the timeline only, and send the conclusions to management to decide what ought to change.

    A lessons-learned review only changes anything if people say what actually went wrong and the output is work someone is obliged to do. Focusing on the process keeps candour intact, because responders who expect blame describe events selectively; attaching an owner and a date converts an observation into something that can be tracked to completion. Excluding junior responders removes the people who saw the alert first, and handing an undirected timeline to management is how the last document died.

    Source: CompTIA CySA+ CS0-004 Exam Objectives, Objective 4.2 — post-incident reporting (lessons learned)Report a problem with this question

  11. 11. The review establishes three things: no application allowlisting existed on the affected servers; the mail gateway scanned the attachment and passed it; and the endpoint agent raised a correct alert that sat untriaged in a saturated queue for most of a day. How should these be classified, in order?

    • A.A missing control, a control that was misconfigured by the administrator, and a control that failed because the agent raised no alert.
    • B.A control gap accepted by the business, a control that worked exactly as designed, and a control disabled by the attacker during the intrusion.
    • C.A missing control, a control that operated and failed to catch it, and a control that worked but whose output was never acted on.✓ Answer
    • D.Three symptoms of one root cause, all of them resolved by replacing the endpoint agent with a product that blocks automatically on detection.

    These three failures need different corrective actions, which is why the classification matters: a control that was never deployed calls for implementation, a control that ran and missed calls for tuning or a different detection method, and a control that produced a correct alert nobody read calls for fixing triage capacity and alert quality. Buying another product changes nothing about the queue that swallowed the alert, and the agent did generate an alert, so calling it a detection failure misdirects the remediation.

    Source: CompTIA CySA+ CS0-004 Exam Objectives, Objective 4.2 — post-incident reporting (root cause analysis, lessons learned)Report a problem with this question

  12. 12. The review notes read 'communication was poor' and 'we should improve monitoring.' A manager asks that each lesson be turned into something trackable. Which item is properly formed?

    • A.The security operations centre will increase monitoring of the affected server segment as soon as budget for the additional collection is approved.
    • B.The detection engineer will add and test a rule for the technique used, with a named reviewer and a completion date in the coming sprint.✓ Answer
    • C.The team will improve coordination during incidents by holding more frequent syncs and by sharing information earlier across every group involved.
    • D.All analysts will read the after-action report and confirm to the manager that they understand what went wrong during the response effort.

    A lesson becomes an improvement only when it names a single owner, a specific deliverable, a verification step and a date, so that someone can later be shown to have done it or not. 'Improve coordination' and 'increase monitoring' state an intention with no owner, no test and no deadline, and the second is additionally parked behind an approval that may never come; an attestation that people read the report changes no control at all.

    Source: CompTIA CySA+ CS0-004 Exam Objectives, Objective 4.2 — post-incident reporting (lessons learned; recommendations with owners)Report a problem with this question

  13. 13. After a phishing-led intrusion the after-action report is signed off. Which output of the review most directly reduces the chance that the same activity succeeds again undetected?

    • A.A tested detection rule for the observed technique, plus the playbook and runbook updates that tell the next analyst how to handle it.✓ Answer
    • B.An entry for the incident in the risk register with a residual risk rating, to be reviewed at the next quarterly governance committee meeting.
    • C.A company-wide message describing the phishing mail and reminding staff to report suspicious messages through the reporting button.
    • D.A purchase of an additional mail filtering layer, so that the class of attachment which arrived in this incident is blocked before delivery.

    The question asks specifically about recurrence going undetected, and the only output that closes a detection gap is engineering and testing a rule for the behaviour that was observed, then writing down how the next analyst should respond to it. Risk-register entries record the exposure without changing any detection, awareness messaging reduces the chance of a click but not the chance of missing the activity, and a new filter addresses delivery of one attachment class while leaving the same technique unmonitored.

    Source: CompTIA CySA+ CS0-004 Exam Objectives, Objective 4.2 — post-incident reporting outputs feeding detection and documentation updatesReport a problem with this question

  14. 14. After an incident the team produces: (1) a finding that an unpatched internet-facing service allowed initial access; (2) a decision to change the escalation threshold because the on-call path failed; (3) a document recording the timeline, scope, actions taken and recommendations. Which mapping is correct?

    • A.1 is remediation, 2 is the after-action report, and 3 is root cause analysis.
    • B.1 is root cause analysis, 2 is a lesson learned, and 3 is the after-action report.✓ Answer
    • C.1 is a lesson learned, 2 is root cause analysis, and 3 is the after-action report.
    • D.1 is the after-action report, 2 is remediation, and 3 is a lesson learned.

    Root cause analysis answers why the incident was possible at all, and a missing patch on an exposed service is exactly that underlying failure. A lesson learned is a change to how the team responds, so altering the escalation threshold after the on-call path failed belongs there. The after-action report is the formal written record that carries both, together with the timeline, scope and actions; reimaging or patching the host is remediation and not a report at all.

    Source: CompTIA CySA+ CS0-004 Exam Objectives, Objective 4.2 — post-incident reporting (after action report, lessons learned, root cause analysis)Report a problem with this question

  15. 15. A manager wants one measure that answers 'how long did the intruder operate before we knew?' and another that answers 'once we knew, how long until we acted to stop it?' Which pair, in that order?

    • A.Mean time to remediate, and then mean time to respond.
    • B.Mean time to detect, and then mean time to respond.✓ Answer
    • C.Mean time to detect, and then mean time to close.
    • D.Mean time to respond, and then mean time to detect.

    Mean time to detect measures the latency from the event occurring to the operation knowing about it, which is the figure that bounds how long an adversary worked unobserved. Mean time to respond measures from that point to effective action against the threat. Mean time to close covers the whole case lifecycle through documentation and formal closure, so it is the wrong instrument for either question.

    Source: CompTIA CySA+ CS0-004 Exam Objectives, Objective 4.2 — metrics and KPIs (mean time to detect, mean time to respond)Report a problem with this question

  16. 16. A host was reimaged and returned to service the same day, the vulnerable service was patched across the estate later that week, and the case was formally closed with its documentation the following week. Which metric does each of those last two milestones feed, in order?

    • A.Mean time to close, and then mean time to remediate.
    • B.Mean time to remediate, and then mean time to respond.
    • C.Mean time to respond, and then mean time to remediate.
    • D.Mean time to remediate, and then mean time to close.✓ Answer

    Remediation is the point at which the underlying cause is eliminated, so patching the vulnerable service everywhere is what stops the clock on mean time to remediate; reimaging one host restored service but left the cause in place. Formal closure with documentation completed is the end of the case lifecycle and feeds mean time to close, which is normally the longest of the four intervals because it includes the reporting work after the technical fix.

    Source: CompTIA CySA+ CS0-004 Exam Objectives, Objective 4.2 — metrics and KPIs (mean time to remediate, mean time to close)Report a problem with this question

  17. 17. A CISO must ask the board to fund telemetry on segments the operation currently cannot see. Which presentation is MOST likely to support that decision?

    • A.The total number of alerts handled last quarter, the year-over-year growth in queue volume, and the headcount needed to keep pace with it.
    • B.The share of critical assets whose logs reach the platform, the detection-time trend, and what the unmonitored segments would have shown.✓ Answer
    • C.The list of techniques the operation can detect today, mapped to a public adversary framework, with the coverage gap marked for each tactic.
    • D.The count of incidents declared last year with their severity ratings, alongside the number of vulnerabilities remediated in the same period.

    A funding decision turns on what the gap costs, so the case has to connect the proportion of critical assets actually monitored to the consequence of the blind spot and to the trend the investment is meant to move. A technique-coverage map is the right internal engineering artifact but asks the board to judge tactics it cannot assess, while alert totals, headcount arithmetic and counts of declared incidents describe activity without showing what remains invisible.

    Source: CompTIA CySA+ CS0-004 Exam Objectives, Objective 4.2 — metrics and KPIs reported to stakeholders; executive summary framing for decision-makersReport a problem with this question

  18. 18. Mean time to respond has improved in each of the last three reporting periods, but two intrusions were later found to have been closed early as false positives. What is the MOST likely explanation, and what would reveal it?

    • A.Automation now contains threats faster than analysts did, which shortens the clock; reading it beside mean time to close confirms the workflows are effective.
    • B.Analyst headcount has grown faster than alert volume, which shortens the clock; reading it beside alerts handled per analyst confirms the gain is real.
    • C.Detection rules have become more precise, which shortens the clock; reading it beside the false-positive rate confirms that tuning work is responsible.
    • D.Ambiguous alerts are being closed unvalidated, which shortens the clock; reading it beside the true-positive rate and a quality review of closures exposes that.✓ Answer

    Any time-based metric can be improved by lowering the standard for calling a case finished, so an operation that disposes of hard alerts as false positives will report faster response while actually missing intrusions. That is why a timing metric is never reported alone: pairing it with detection fidelity and a sample review of how closed alerts were decided is what distinguishes genuine speed from a quality collapse. The other readings are plausible causes of real improvement but none of them explains intrusions closed as false positives.

    Source: CompTIA CySA+ CS0-004 Exam Objectives, Objective 4.2 — metrics and KPIs (mean time to respond, true-positive rate) interpreted togetherReport a problem with this question

  19. 19. Counsel advises that this incident will trigger an obligation to notify outside the company. Nothing about the technical response changes. What does this change about the team's documentation?

    • A.Interim working notes should be deleted from the case once superseded, so that the final record holds no statement that later turned out to be wrong.
    • B.Analysts should draft the notification text themselves while the details are fresh, and send it once the technical containment work has been verified.
    • C.The case record should be restricted to the incident lead, with other responders keeping their observations in personal notes until the matter closes.
    • D.Facts, times, actors and decisions must be captured as they happen and preserved under legal review, so that the notification rests on the record.✓ Answer

    When an external notification duty applies, the case record stops being an internal work product and becomes the evidentiary basis for statements the organization will have to stand behind, so contemporaneous capture of facts, timestamps, actors and decisions plus preservation under legal review is what makes the notification defensible. Deleting superseded notes destroys the audit trail the record is for, analysts do not author or release external notifications, and scattering observations into personal notes puts them outside preservation entirely.

    Source: CompTIA CySA+ CS0-004 Exam Objectives, Objective 4.2 — communication plan (legal team, regulatory reporting agencies) and incident documentationReport a problem with this question

Practice questions based on the CompTIA CySA+ exam objectives. This site is not affiliated with or endorsed by CompTIA, and these are not real exam questions. CompTIA refreshes this exam periodically, runs two versions side by side during a transition, and sets the exam length, passing standard and eligibility terms — confirm the current objectives and the live exam code with CompTIA before you register. The real exam also includes performance-based items that a multiple-choice bank cannot reproduce, so pair this with hands-on practice. Official CySA+ exam objectives →