CompTIA CySA+ (CS0-003) — Questions and Answers
Question 1: A company's IR plan calls for activating a 'war room' during a major incident. What is the PRIMARY benefit of this approach?
- It centralizes decision-making and communication among key stakeholders (Correct answer)
- It satisfies regulatory notification requirements
- It physically isolates affected systems
- It ensures evidence is stored securely
Correct answer: It centralizes decision-making and communication among key stakeholders
A war room centralizes key personnel and communications, enabling faster coordinated decision-making during high-pressure incidents.
Question 2: OAuth 2.0 is primarily used to provide which of the following capabilities?
- Certificate-based identity verification
- Password-based authentication for web applications
- Delegated authorization allowing third-party apps to access resources on behalf of a user (Correct answer)
- Mutual TLS authentication between servers
Correct answer: Delegated authorization allowing third-party apps to access resources on behalf of a user
OAuth 2.0 is an authorization framework that enables third-party applications to obtain limited access to a user's resources without exposing their credentials.
Question 3: What does a 'false negative' mean in the context of vulnerability scanning?
- The scanner reports a vulnerability with the wrong CVSS score
- The scanner fails to detect a vulnerability that is actually present (Correct answer)
- The scanner crashes during the scan
- The scanner reports a vulnerability that does not actually exist
Correct answer: The scanner fails to detect a vulnerability that is actually present
A false negative is a missed detection — the real vulnerability exists on the target but the scanner does not flag it, often due to scan limitations or evasion.
Question 4: During a vulnerability assessment, the analyst finds an open service on port 8080 returning a banner that identifies an outdated web server version. What is the analyst's next BEST action?
- Rescan the port to confirm the banner is accurate
- Immediately shut down the service
- Report it as critical without further investigation
- Correlate the version with known CVEs and assess exploitability in context (Correct answer)
Correct answer: Correlate the version with known CVEs and assess exploitability in context
Banner information identifies software version; the analyst should look up CVEs for that version and evaluate whether the vulnerability is exploitable given the environment.
Question 5: What is encryption?
- Deleting data
- Converting data into coded format to prevent unauthorized access (Correct answer)
- Compressing files
- Backing up data
Correct answer: Converting data into coded format to prevent unauthorized access
Encryption transforms readable data into unreadable ciphertext using algorithms and keys, ensuring only authorized parties can access the information.
Question 6: A SOC analyst identifies a process injecting code into a legitimate Windows process (e.g., svchost.exe). Which MITRE ATT&CK technique does this represent?
- Credential dumping
- Process injection (Correct answer)
- DLL side-loading
- Scheduled task abuse
Correct answer: Process injection
Process injection is a MITRE ATT&CK technique where adversaries inject malicious code into legitimate running processes to evade detection.
Question 7: Which threat intelligence source provides near-real-time, community-contributed indicators of compromise (IOCs) and vulnerability information shared between organizations?
- Internal SIEM logs
- Information Sharing and Analysis Centers (ISACs) (Correct answer)
- CVE/NVD database
- Vendor security advisories
Correct answer: Information Sharing and Analysis Centers (ISACs)
ISACs facilitate trusted, industry-specific sharing of threat intelligence including active IOCs and exploitation activity among member organizations.
Question 8: An analyst examines a suspect workstation and finds an unusual scheduled task that runs a PowerShell command encoded with -EncodedCommand. Which Windows artifact would BEST corroborate this finding?
- Application event log errors
- Windows Defender exclusion list
- Windows Firewall logs
- Task Scheduler operational event logs (Event ID 4698, 4702) (Correct answer)
Correct answer: Task Scheduler operational event logs (Event ID 4698, 4702)
Windows Task Scheduler logs Event ID 4698 (task created) and 4702 (task updated) in the Security log, providing corroborating evidence of scheduled task manipulation.
Question 9: An analyst notices that the vulnerability scanner is flagging a particular finding on a host every week despite a patch being applied a month ago. What should the analyst suspect?
- The scanner is configured to report informational items
- The CVE score has been revised upward
- The patch was not successfully applied or was rolled back (Correct answer)
- The scanner's plugin is outdated
Correct answer: The patch was not successfully applied or was rolled back
Persistent findings after patching most commonly indicate the patch did not apply correctly, was reverted, or the scan is targeting a different instance of the software.
Question 10: During an IR engagement, an analyst needs to determine the last time a specific user account logged into a Windows domain workstation. Which is the MOST reliable source?
- Active Directory's lastLogon attribute on the domain controller
- The workstation's local Security event log (Event ID 4624)
- Active Directory's lastLogonTimestamp attribute replicated across all DCs (Correct answer)
- The workstation's System event log
Correct answer: Active Directory's lastLogonTimestamp attribute replicated across all DCs
lastLogonTimestamp is replicated across all domain controllers and provides a consistent view, while lastLogon is only updated on the authenticating DC and not replicated.
Question 11: What is the purpose of a vulnerability disclosure policy (VDP)?
- To establish a formal, safe channel for external researchers to report security vulnerabilities to an organization (Correct answer)
- To restrict which vendors can submit CVEs to the NVD
- To define how often vulnerability scans must be run
- To determine remediation SLA timelines for internal teams
Correct answer: To establish a formal, safe channel for external researchers to report security vulnerabilities to an organization
A VDP provides a legal and procedural safe harbor for security researchers to responsibly report vulnerabilities they discover in an organization's systems.
Question 12: Which technique helps analysts determine the true difficulty of the CySA+ exam before sitting for it?
- Completing official CompTIA practice exams and hands-on lab simulations (Correct answer)
- Estimating difficulty from the exam fee
- Reading third-party brain dump sites
- Reviewing only the glossary section of study guides
Correct answer: Completing official CompTIA practice exams and hands-on lab simulations
Official practice exams and hands-on labs accurately simulate the performance-based question style and cognitive demand of the actual CySA+ exam.
Question 13: Which document formally records that an organization has acknowledged a vulnerability and chosen not to remediate it based on business justification?
- Scan configuration baseline
- Remediation ticket
- Risk register entry with accepted risk notation (Correct answer)
- Vulnerability exception request
Correct answer: Risk register entry with accepted risk notation
Accepted risks are documented in the risk register with the business owner's sign-off, providing an audit trail for why known vulnerabilities were not remediated.
Question 14: During vulnerability triage, an analyst identifies a vulnerability marked as 'informational' by the scanner. How should this be handled?
- Informational findings should be patched immediately as they indicate critical flaws
- Informational findings are always false positives
- Informational findings reveal configuration or enumeration data that may aid attackers and should be reviewed for risk in context (Correct answer)
- Informational findings can always be closed without review
Correct answer: Informational findings reveal configuration or enumeration data that may aid attackers and should be reviewed for risk in context
Informational findings do not indicate a directly exploitable flaw but can expose system details useful for reconnaissance; analysts should assess whether they increase overall risk.
Question 15: A CySA+ analyst is tasked with reducing the attack surface of cloud-hosted workloads. Which domain does this align with?
- Compliance and Assessment
- Security Operations and Monitoring
- Software and Systems Security (Correct answer)
- Threat Intelligence
Correct answer: Software and Systems Security
Hardening cloud workloads and reducing attack surface are Software and Systems Security responsibilities in CySA+.
Question 16: What does a pie chart represent?
- Changes over time
- Scatter patterns
- Parts of a whole as percentages (Correct answer)
- Comparisons between groups
Correct answer: Parts of a whole as percentages
Pie charts display data as proportional slices of a circle, showing how individual parts contribute to the total.
Question 17: A security team sets a target that 100% of high-severity alerts must be triaged within 15 minutes. This target is best described as a:
- Risk appetite statement
- Vulnerability score threshold
- Threat hunting hypothesis
- Service Level Agreement (SLA) (Correct answer)
Correct answer: Service Level Agreement (SLA)
An SLA defines a committed performance standard, here specifying the maximum acceptable triage time for high-severity alerts.
Question 18: What does the term 'threat actor TTP' stand for, and why is it more durable than IOCs for detection?
- Tactics, Techniques, and Procedures; TTPs change slowly compared to infrastructure IOCs (Correct answer)
- Tactics, Tools, and Policies; they are enforced by security controls
- Triggers, Thresholds, and Protocols; they define network behavior baselines
- Targets, Tools, and Payloads; they are embedded in malware signatures
Correct answer: Tactics, Techniques, and Procedures; TTPs change slowly compared to infrastructure IOCs
TTPs (Tactics, Techniques, and Procedures) describe how adversaries operate and are far more stable than IOCs like IPs or domains, which adversaries rotate frequently.
Question 19: Which scanning technique sends specially crafted packets to elicit responses that reveal OS and service version information without authentication?
- Credentialed host scan
- Passive network monitoring
- Fuzzing
- Active fingerprinting (Correct answer)
Correct answer: Active fingerprinting
Active fingerprinting (e.g., Nmap OS detection) probes target systems with specific packets and analyzes responses to identify OS, services, and versions.
Question 20: A forensic analyst is reviewing Windows Security event logs and sees Event ID 4624 with Logon Type 3 from an external IP. What does this indicate?
- A service account logon
- A remote desktop (RDP) session
- A network logon, such as accessing a shared folder (Correct answer)
- A local interactive logon at the console
Correct answer: A network logon, such as accessing a shared folder
Logon Type 3 in Windows Security Event 4624 indicates a network logon, typically used for accessing shared resources over SMB.
Question 21: A security analyst identifies that an attacker achieved persistence through a scheduled task running a malicious executable. Which remediation step is MOST critical?
- Reset all user passwords on the domain
- Delete the scheduled task AND the malicious executable, then verify no other persistence exists (Correct answer)
- Disable the Task Scheduler service permanently
- Change the system's IP address
Correct answer: Delete the scheduled task AND the malicious executable, then verify no other persistence exists
Full remediation requires removing both the scheduled task trigger and the malicious payload, then hunting for additional persistence mechanisms the attacker may have established.
Question 22: Which vulnerability remediation strategy involves deploying a temporary measure to reduce risk while a permanent patch is being developed or tested?
- Vulnerability suppression
- Compensating control (Correct answer)
- Risk acceptance
- Patch management
Correct answer: Compensating control
A compensating control (e.g., WAF rule, network ACL) reduces exploitability temporarily until a proper fix is available.
Question 23: An analyst identifies malware that changes its code on each infection cycle to evade signature detection. Which technique is this?
- Rootkit behavior
- Beaconing
- Polymorphism (Correct answer)
- Process hollowing
Correct answer: Polymorphism
Polymorphic malware mutates its code or signature with each replication while maintaining its original functionality.
Question 24: During the containment phase of incident response, a security analyst isolates an infected workstation from the network. Which action should be taken NEXT?
- Preserve forensic evidence before any remediation (Correct answer)
- Notify all users about the breach
- Wipe and reimage the system immediately
- Restore from the most recent backup
Correct answer: Preserve forensic evidence before any remediation
Preserving forensic evidence before remediation ensures that volatile data and artifacts needed for investigation are not lost.
Question 25: Which vulnerability management lifecycle phase involves verifying that applied patches or configuration changes successfully closed the identified vulnerability?
- Discovery
- Prioritization
- Remediation
- Validation (Correct answer)
Correct answer: Validation
Validation (verification) involves rescanning or retesting after remediation to confirm the vulnerability is no longer present.
Question 26: An analyst discovers that the organization's cloud provider holds a shared responsibility for compliance. Under PCI DSS, who is ultimately accountable for cardholder data protection?
- The cloud provider, as the infrastructure owner
- The merchant (covered entity) (Correct answer)
- Both the merchant and cloud provider equally
- The card brands (Visa, Mastercard)
Correct answer: The merchant (covered entity)
Under PCI DSS, the merchant (covered entity) retains ultimate accountability for cardholder data protection regardless of what a cloud provider manages.
Question 27: Which directory protocol is most commonly used by enterprises to centrally store and manage user identities, credentials, and group memberships?
- LDAP (Correct answer)
- TACACS+
- RADIUS
- Kerberos
Correct answer: LDAP
LDAP (Lightweight Directory Access Protocol) is the standard protocol for querying and modifying directory services such as Microsoft Active Directory where user identities and attributes are stored.
Question 28: Which of the following BEST describes the purpose of a cyber threat intelligence (CTI) feed in incident response?
- Ensuring regulatory compliance requirements are met
- Replacing the need for a SIEM platform
- Providing context about attacker TTPs to improve detection and response (Correct answer)
- Automatically blocking all detected threats
Correct answer: Providing context about attacker TTPs to improve detection and response
CTI feeds provide context about adversary tactics, techniques, and procedures (TTPs) that help analysts detect, investigate, and respond to threats more effectively.
Question 29: Which element of a Business Impact Analysis (BIA) identifies the maximum time a business process can be unavailable before causing unacceptable harm?
- Maximum Tolerable Downtime (MTD) (Correct answer)
- Mean Time to Repair (MTTR)
- Recovery Point Objective (RPO)
- Recovery Time Objective (RTO)
Correct answer: Maximum Tolerable Downtime (MTD)
Maximum Tolerable Downtime (MTD) defines the absolute longest period a business function can be offline before causing unacceptable consequences to the organization.
Question 30: A vulnerability management program reports that mean time to remediate (MTTR) critical vulnerabilities has increased from 7 days to 21 days over the past quarter. What is the MOST likely root cause to investigate first?
- The patch deployment process or change management workflow has a bottleneck (Correct answer)
- The organization's risk appetite has changed
- Critical vulnerabilities are being discovered less frequently
- The vulnerability scanner is generating more false positives
Correct answer: The patch deployment process or change management workflow has a bottleneck
An increasing MTTR typically signals a bottleneck in the patching or change management process — approvals, testing cycles, or resource constraints are slowing remediation.
Question 31: A CySA+ analyst needs to prioritize hundreds of vulnerabilities. Which combination of factors BEST represents an effective risk-based prioritization model?
- CVSS base score, asset criticality, and exploitability in the wild (Correct answer)
- Patch availability and OS platform type
- CVE publication date and vendor severity rating
- Number of affected hosts and time since last scan
Correct answer: CVSS base score, asset criticality, and exploitability in the wild
Effective prioritization combines the technical severity (CVSS), business value of the asset, and whether active exploitation is occurring to focus remediation effort on the highest real-world risk.
Question 32: Which type of threat intelligence focuses on the day-to-day activities of security operations and includes IOCs, malware hashes, and IP blocklists?
- Tactical intelligence
- Technical intelligence (Correct answer)
- Strategic intelligence
- Operational intelligence
Correct answer: Technical intelligence
Technical intelligence provides specific IOCs such as hashes, IPs, and domains used directly in detection tools and blocklists.
Question 33: A company wants to ensure its web application controls align with OWASP Top 10. Which CySA+ domain is most relevant?
- Threat Intelligence
- Software and Systems Security (Correct answer)
- Security Operations and Monitoring
- Compliance and Assessment
Correct answer: Software and Systems Security
Evaluating and securing applications against OWASP Top 10 falls under the Software and Systems Security domain.
Question 34: A test center administrator informs a candidate that their exam will be proctored remotely. Which of the following is a requirement for online proctored CySA+ exams?
- A separate keyboard and mouse are prohibited
- A webcam and microphone must be functional (Correct answer)
- The room must be completely dark
- A VPN connection must be active throughout the exam
Correct answer: A webcam and microphone must be functional
Online-proctored exams require a working webcam and microphone so the remote proctor can monitor the candidate.
Question 35: Intermediate: A security analyst detects unusual outbound traffic from a workstation. Which of the following should be the first step in addressing this potential incident?
- Notify the user and ask them to stop using the workstation
- Perform a vulnerability scan on the workstation
- Isolate the workstation from the network (Correct answer)
- Re-image the workstation immediately
Correct answer: Isolate the workstation from the network
When unusual outbound traffic is detected, the immediate priority is to contain the potential threat and prevent further compromise or data exfiltration. Isolating the workstation from the network severs its connection to other systems and the internet, stopping the malicious activity from spreading or continuing. This containment step is critical in incident response before further investigation and remediation can occur.
Question 36: Which risk assessment methodology uses likelihood and impact ratings to produce a risk score matrix?
- OCTAVE
- Qualitative risk assessment (Correct answer)
- FAIR
- Monte Carlo simulation
Correct answer: Qualitative risk assessment
Qualitative risk assessment assigns descriptive ratings (e.g., High/Medium/Low) for likelihood and impact, plotted on a risk matrix.
Question 37: Which metric within the CVSS v3 Temporal Score group reflects whether a working exploit code is publicly available?
- Exploit Code Maturity (Correct answer)
- Report Confidence
- Remediation Level
- Attack Vector
Correct answer: Exploit Code Maturity
Exploit Code Maturity (E) in the Temporal group indicates the current state of available exploit techniques, ranging from unproven to functional to weaponized.
Question 38: An analyst is reviewing Windows Prefetch files and notices that an executable was run once but the Prefetch file shows references to files in a temp directory that no longer exist. This MOST likely indicates:
- Normal Prefetch optimization behavior
- A self-deleting malware dropper that cleaned up after execution (Correct answer)
- Filesystem corruption affecting Prefetch data
- The program was run in Safe Mode
Correct answer: A self-deleting malware dropper that cleaned up after execution
Self-deleting malware often drops a payload, executes it, then removes the temporary files, but Prefetch retains references to all files accessed during execution.
Question 39: Which HIPAA rule establishes national standards for the protection of electronically protected health information (ePHI)?
- HIPAA Security Rule (Correct answer)
- HIPAA Breach Notification Rule
- HIPAA Privacy Rule
- HIPAA Enforcement Rule
Correct answer: HIPAA Security Rule
The HIPAA Security Rule specifically addresses the protection of ePHI through administrative, physical, and technical safeguards.
Question 40: A CySA+ analyst is reviewing an IAM report and finds several accounts that have not been used in 90 days. What should be the FIRST action taken?
- Disable the accounts pending review and notify account owners (Correct answer)
- Reset the passwords on all inactive accounts
- Immediately delete all inactive accounts
- Add the accounts to a high-privilege monitoring group
Correct answer: Disable the accounts pending review and notify account owners
Disabling (rather than immediately deleting) inactive accounts pending review follows proper IAM hygiene — it prevents unauthorized use while allowing time to verify the accounts are truly abandoned before permanent removal.
Question 41: Which CySA+ knowledge area includes reviewing software development pipelines for security misconfigurations?
- Compliance and Assessment
- Software and Systems Security (Correct answer)
- Security Operations
- Threat Intelligence
Correct answer: Software and Systems Security
Securing CI/CD pipelines and development environments falls within the Software and Systems Security domain.
Question 42: A vulnerability scanner returns a finding with a CVSS base score of 9.8. Before prioritizing remediation, which contextual factor should a security analyst evaluate FIRST?
- Whether the vendor has released a patch
- Whether the CVE was published in the last 30 days
- Whether the affected asset is internet-facing and stores sensitive data (Correct answer)
- Whether the finding has a public proof-of-concept exploit
Correct answer: Whether the affected asset is internet-facing and stores sensitive data
Asset criticality and exposure context determine true business risk; a high CVSS score on an isolated, non-critical system may rank lower than a moderate score on an internet-facing critical asset.
Question 43: What is a firewall?
- An antivirus program
- A security device that monitors and controls network traffic based on rules (Correct answer)
- A fire-resistant building component
- A password manager
Correct answer: A security device that monitors and controls network traffic based on rules
Firewalls filter incoming and outgoing network traffic based on security rules, creating a barrier between trusted and untrusted networks.
Question 44: What is the CIA triad in information security?
- Certified Information Auditor
- Confidentiality, Integrity, Availability (Correct answer)
- Cybersecurity Infrastructure Act
- Central Intelligence Agency
Correct answer: Confidentiality, Integrity, Availability
The CIA triad represents three core security principles: Confidentiality (keeping data private), Integrity (data accuracy), Availability (systems accessible when needed).
Question 45: Which forensic artifact on macOS is equivalent to Windows Prefetch and can help an analyst determine what applications were recently executed?
- Spotlight index (.Spotlight-V100)
- macOS Unified Logs (log show command) (Correct answer)
- .plist files in /private/var/folders (FolderActions) and Spotlight metadata
- Recently Used application plist files and macOS .DS_Store files
Correct answer: macOS Unified Logs (log show command)
macOS Unified Logs (accessed via the `log show` command) record detailed process execution events and are the primary source for application execution history on macOS.
Question 46: A security analyst notices that a terminated employee's account is still active in Active Directory two weeks after their departure. Which IAM process failed?
- Role-based access review
- De-provisioning (off-boarding) (Correct answer)
- Provisioning
- Authentication
Correct answer: De-provisioning (off-boarding)
De-provisioning is the process of removing access rights when an employee leaves; failure to perform this step leaves orphaned accounts that can be exploited.
Question 47: What is multi-factor authentication (MFA)?
- Using multiple passwords
- Requiring two or more verification methods to confirm identity (Correct answer)
- Having multiple accounts
- Logging in from multiple devices
Correct answer: Requiring two or more verification methods to confirm identity
MFA combines two or more authentication factors (something you know, have, or are) for stronger identity verification.
Question 48: A candidate with network security experience but limited scripting exposure should focus exam preparation on which CySA+ skill area?
- Creating SIEM dashboards from scratch
- Designing firewall rule sets
- Advanced Python development for exploit writing
- Reading and interpreting scripts/code for malicious activity indicators (Correct answer)
Correct answer: Reading and interpreting scripts/code for malicious activity indicators
CySA+ tests the ability to read and interpret code/scripts for indicators of malicious behavior, not to write production code.
Question 49: What is the key difference between a threat feed and threat intelligence?
- Threat feeds provide raw data; threat intelligence adds analysis and context (Correct answer)
- Threat feeds are structured in STIX; intelligence uses plain text
- Threat feeds are always paid; threat intelligence is free
- Threat intelligence only covers nation-state actors
Correct answer: Threat feeds provide raw data; threat intelligence adds analysis and context
Threat feeds deliver raw IOC data, while threat intelligence involves processing, analyzing, and contextualizing that data to support decision-making.
Question 50: A purple team exercise concludes. Which output is most useful for improving detection KPIs?
- A log of all successful defenses by the blue team
- A list of attack techniques that were executed but NOT detected by existing controls (Correct answer)
- An invoice for the exercise cost
- A summary of red team tools and their versions
Correct answer: A list of attack techniques that were executed but NOT detected by existing controls
Undetected techniques reveal gaps in detection coverage, directly informing rule improvements and KPI targets for future detection effectiveness.
Question 51: An analyst notices outbound traffic to a domain registered 24 hours ago with a high entropy subdomain. Which threat technique does this MOST suggest?
- ARP Spoofing
- SQL Injection
- Domain Generation Algorithm (DGA) (Correct answer)
- Pass-the-Hash
Correct answer: Domain Generation Algorithm (DGA)
Newly registered domains with high-entropy subdomains are a hallmark of Domain Generation Algorithms used by malware to locate C2 infrastructure.
Question 52: What is encryption?
- Backing up data
- Converting data into coded format to prevent unauthorized access (Correct answer)
- Compressing files
- Deleting data
Correct answer: Converting data into coded format to prevent unauthorized access
Encryption transforms readable data into unreadable ciphertext using algorithms and keys, ensuring only authorized parties can access the information.
Question 53: What is a firewall?
- An antivirus program
- A security device that monitors and controls network traffic based on rules (Correct answer)
- A password manager
- A fire-resistant building component
Correct answer: A security device that monitors and controls network traffic based on rules
Firewalls filter incoming and outgoing network traffic based on security rules, creating a barrier between trusted and untrusted networks.
Question 54: Which metric in CVSSv3 indicates that an attacker must be on the same logical or physical network as the vulnerable system to exploit it?
- Attack Vector: Physical
- Attack Vector: Network
- Attack Vector: Adjacent (Correct answer)
- Attack Vector: Local
Correct answer: Attack Vector: Adjacent
The Adjacent (A) attack vector requires the attacker to be on the same network segment or broadcast domain as the target.
Question 55: During threat modeling, which technique involves working backward from a defined adverse outcome to identify contributing causes?
- STRIDE modeling
- Fault tree analysis (Correct answer)
- PASTA methodology
- Attack tree analysis
Correct answer: Fault tree analysis
Fault tree analysis starts with an undesired top-level event and traces backward through logical branches to identify root causes and contributing failures.
Question 56: When analyzing network packet captures during an incident, an analyst notices large DNS TXT record responses to an unusual external domain at regular intervals. This MOST likely indicates:
- Normal CDN health-check traffic
- DNS tunneling used for data exfiltration or C2 (Correct answer)
- A misconfigured internal DNS resolver
- DNS cache poisoning in progress
Correct answer: DNS tunneling used for data exfiltration or C2
DNS tunneling encodes data in DNS TXT queries/responses to bypass firewalls, and regular large TXT responses to unusual domains are a strong indicator.
Question 57: Which chain-of-custody practice is MOST important when collecting digital evidence from a live system?
- Collect evidence directly to a network share for safekeeping
- Power off the system before collecting evidence
- Document every action taken and hash all collected artifacts (Correct answer)
- Use the system's built-in backup tools
Correct answer: Document every action taken and hash all collected artifacts
Documenting all actions and hashing artifacts ensures evidence integrity and maintains a defensible chain of custody for legal proceedings.
Question 58: An analyst discovers that an attacker used valid administrative credentials to access systems without triggering any alerts. What security control gap does this reveal?
- Absence of user and entity behavior analytics (UEBA) to detect anomalous use of legitimate credentials (Correct answer)
- Lack of endpoint antivirus
- Insufficient firewall rules
- Failure to implement multi-factor authentication
Correct answer: Absence of user and entity behavior analytics (UEBA) to detect anomalous use of legitimate credentials
UEBA establishes behavioral baselines for accounts and detects anomalies in how legitimate credentials are used, catching attackers who evade signature-based detection.
Question 59: An analyst examines a malware sample and finds it queries the registry key HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid at startup. What is the MOST likely purpose of this behavior?
- To establish persistence via a registry run key
- To fingerprint the specific machine and avoid executing in sandbox or VM environments (Correct answer)
- To escalate privileges using a known registry exploit
- To disable Windows Defender by modifying security settings
Correct answer: To fingerprint the specific machine and avoid executing in sandbox or VM environments
MachineGuid is a unique identifier; malware reads it to fingerprint the host, detect sandboxes (where the GUID may be generic), and avoid analysis environments.
Question 60: What is a firewall?
- A fire-resistant building component
- An antivirus program
- A security device that monitors and controls network traffic based on rules (Correct answer)
- A password manager
Correct answer: A security device that monitors and controls network traffic based on rules
Firewalls filter incoming and outgoing network traffic based on security rules, creating a barrier between trusted and untrusted networks.
Question 61: Which of the following MOST accurately describes what the CySA+ exam does NOT test?
- Interpreting vulnerability scan reports
- Using SIEM queries to correlate events
- Analyzing network packet captures
- Exploiting vulnerabilities with offensive tools for penetration testing (Correct answer)
Correct answer: Exploiting vulnerabilities with offensive tools for penetration testing
CySA+ is a defensive/analyst certification; active exploitation and offensive penetration testing are covered by PenTest+, not CySA+.
Question 62: Which of the following BEST describes the relationship between vulnerability, threat, and risk?
- Risk arises when a threat exploits a vulnerability to impact an asset (Correct answer)
- Threat and vulnerability are interchangeable terms in risk assessment
- Risk = Threat × Vulnerability, independent of asset value
- A vulnerability without a threat still constitutes an active risk requiring immediate action
Correct answer: Risk arises when a threat exploits a vulnerability to impact an asset
Risk exists at the intersection of a threat (capable actor or event), a vulnerability (exploitable weakness), and an asset with value — all three components must be present.
Question 63: Which security design principle recommends using multiple overlapping security controls so that the failure of one does not compromise the entire system?
- Least privilege
- Defense in depth (Correct answer)
- Separation of duties
- Fail open
Correct answer: Defense in depth
Defense in depth layers multiple security controls so that if one layer fails, additional layers continue to protect assets.
Question 64: During network monitoring, an analyst identifies TCP sessions with the SYN flag set but no corresponding SYN-ACK responses from the destination. What does this pattern MOST likely indicate?
- ARP spoofing in progress
- TCP session hijacking
- SYN scan (half-open scan) reconnaissance (Correct answer)
- Established encrypted tunnels
Correct answer: SYN scan (half-open scan) reconnaissance
A SYN scan sends SYN packets but never completes the handshake; unanswered SYNs are characteristic of port scanning with half-open connections.
Question 65: Which framework uses a maturity model with five levels (Initial, Managed, Defined, Quantitatively Managed, Optimizing) to assess cybersecurity processes?
- NIST CSF
- ISO 27001
- COBIT 5
- CMMI (Correct answer)
Correct answer: CMMI
CMMI (Capability Maturity Model Integration) defines five maturity levels used to benchmark and improve organizational processes including security.
Question 66: A CySA+ analyst discovers that an attacker used a privileged service account to move laterally across systems. Which control would BEST have mitigated this risk?
- Encrypting all network traffic
- MFA on all user accounts
- Privileged Access Management (PAM) (Correct answer)
- Deploying a SIEM
Correct answer: Privileged Access Management (PAM)
PAM controls, monitors, and limits the use of privileged accounts, reducing the risk of their abuse for lateral movement.
Question 67: What is the primary purpose of credentialed scanning versus unauthenticated scanning?
- Credentialed scans can enumerate installed software, patch levels, and local configuration without relying on exposed network services (Correct answer)
- Credentialed scans run faster and produce fewer false positives
- Credentialed scans only work on Windows systems
- Unauthenticated scans require more network bandwidth
Correct answer: Credentialed scans can enumerate installed software, patch levels, and local configuration without relying on exposed network services
Providing scanner credentials allows it to log into hosts and inspect installed packages, registry settings, and configuration files, producing far more comprehensive and accurate results.
Question 68: During a PCI DSS assessment, the QSA finds that the organization uses multi-factor authentication only for remote access. According to PCI DSS v4.0, where else is MFA now required?
- Only for service accounts accessing cardholder databases
- Only for privileged accounts accessing the CDE remotely
- Solely for external-facing web applications
- For all non-console administrative access into the CDE (Correct answer)
Correct answer: For all non-console administrative access into the CDE
PCI DSS v4.0 Requirement 8.4.2 requires MFA for all non-console administrative access into the CDE, expanding beyond just remote access.
Question 69: Which tool is BEST suited for capturing and analyzing volatile memory from a compromised Windows system?
- Nmap
- Autopsy
- Volatility (Correct answer)
- Wireshark
Correct answer: Volatility
Volatility is a memory forensics framework specifically designed to analyze RAM dumps from Windows (and other) systems for malicious artifacts.
Question 70: Which IAM solution is specifically designed to manage, monitor, and control access to privileged accounts such as domain administrators and service accounts?
- Directory Services (LDAP)
- Privileged Access Management (PAM) (Correct answer)
- Identity Governance and Administration (IGA)
- Identity Federation Service
Correct answer: Privileged Access Management (PAM)
PAM solutions provide vaulting, session recording, just-in-time access, and fine-grained controls over privileged accounts, which are the highest-value targets for attackers.
Question 71: What is multi-factor authentication (MFA)?
- Having multiple accounts
- Logging in from multiple devices
- Requiring two or more verification methods to confirm identity (Correct answer)
- Using multiple passwords
Correct answer: Requiring two or more verification methods to confirm identity
MFA combines two or more authentication factors (something you know, have, or are) for stronger identity verification.
Question 72: Which SOAR capability directly reduces analyst workload by automatically executing predefined response actions when specific alert conditions are met?
- Playbook automation (Correct answer)
- Threat intelligence aggregation
- Vulnerability scanning
- Log normalization
Correct answer: Playbook automation
SOAR playbook automation triggers predefined response workflows automatically when alert criteria match, executing containment and enrichment without manual intervention.
Question 73: An organization scans its environment weekly but new vulnerabilities are continuously introduced through software deployments. Which process BEST addresses this gap?
- Requiring manual code reviews for all deployments
- Integrating vulnerability scanning into the CI/CD pipeline (Correct answer)
- Disabling automatic deployments until weekly scans complete
- Increasing scan frequency to daily
Correct answer: Integrating vulnerability scanning into the CI/CD pipeline
Embedding scanning into CI/CD pipelines ensures every build is tested before it reaches production, addressing the gap that periodic scans miss newly deployed code.
Question 74: An organization subject to SOX must ensure that controls over financial reporting are audited annually. Which section of SOX specifically addresses internal control requirements?
- Section 906
- Section 302
- Section 802
- Section 404 (Correct answer)
Correct answer: Section 404
SOX Section 404 requires management and external auditors to report annually on the adequacy of the internal control structure over financial reporting.
Question 75: Which CVSS v3 metric describes the conditions beyond the attacker's control that must exist for a vulnerability to be exploited, such as a race condition or a specific system state?
- Privileges Required
- User Interaction
- Attack Complexity (Correct answer)
- Scope
Correct answer: Attack Complexity
Attack Complexity (AC) captures prerequisite conditions outside attacker control — High AC means the attacker must meet additional circumstances like timing or configuration.
Question 76: What is phishing?
- A social engineering attack using fraudulent communications to steal sensitive data (Correct answer)
- A type of firewall
- A backup system
- A network scanning tool
Correct answer: A social engineering attack using fraudulent communications to steal sensitive data
Phishing uses deceptive emails, websites, or messages that appear legitimate to trick victims into revealing passwords, credit cards, or personal information.
Question 77: Which indicator type is considered MOST actionable for immediate blocking because it has the shortest useful lifespan in threat intelligence?
- Tactics, Techniques, and Procedures (TTPs)
- IP addresses (Correct answer)
- Adversary motivations
- Malware behavior patterns
Correct answer: IP addresses
IP addresses are immediately blockable but change frequently as attackers rotate infrastructure, making them short-lived but operationally useful.
Question 78: An analyst receives an alert that a vulnerable version of Apache Struts is running on a production server. The CVE has a known weaponized exploit. What is the MOST urgent first step?
- File a remediation ticket for the next patch cycle
- Increase logging verbosity on the server
- Notify users of potential downtime
- Immediately isolate the server and apply emergency patch procedures while monitoring for exploitation (Correct answer)
Correct answer: Immediately isolate the server and apply emergency patch procedures while monitoring for exploitation
A known weaponized exploit on a production system with network exposure demands immediate containment and emergency patching to prevent active exploitation.
Question 79: An attacker captures the NTLM hash of an administrator account from memory and uses it to authenticate to network services without cracking the password. What technique is being used?
- Pass-the-Hash (Correct answer)
- Kerberoasting
- Token impersonation
- Credential stuffing
Correct answer: Pass-the-Hash
Pass-the-Hash exploits NTLM authentication by using the stolen password hash directly for authentication without needing the plaintext password.
Question 80: An analyst discovers that a critical vulnerability on a legacy PLC cannot be patched due to vendor support constraints. What is the MOST appropriate response?
- Accept the risk and document it with no further action
- Run daily vulnerability scans against the device
- Implement network segmentation and enhanced monitoring as compensating controls (Correct answer)
- Decommission the system immediately
Correct answer: Implement network segmentation and enhanced monitoring as compensating controls
When patching is not feasible, isolating the system via network segmentation and increasing monitoring reduces the attack surface and detection time.
Question 81: When assessing vulnerabilities in a cloud IaaS environment, which responsibility typically remains with the customer rather than the cloud provider?
- Guest OS and application-level vulnerabilities (Correct answer)
- Physical host hardware patching
- Network backbone maintenance
- Hypervisor security
Correct answer: Guest OS and application-level vulnerabilities
Under the shared responsibility model in IaaS, the customer owns the guest OS, middleware, and applications — including patching them for vulnerabilities.
Question 82: An organization wants to allow employees to log in to multiple internal applications using a single set of credentials. Which technology best supports this requirement?
- Single Sign-On (SSO) (Correct answer)
- Multi-Factor Authentication (MFA)
- Public Key Infrastructure (PKI)
- Privileged Access Management (PAM)
Correct answer: Single Sign-On (SSO)
SSO allows users to authenticate once and gain access to multiple applications without re-entering credentials, improving usability while centralizing authentication control.
Question 83: An analyst needs to determine if malware communicated with a command-and-control server. Which artifact provides the MOST direct evidence?
- Registry run keys
- Firewall outbound connection logs (Correct answer)
- User account creation logs
- Windows prefetch files
Correct answer: Firewall outbound connection logs
Firewall outbound connection logs directly show network communication attempts, including connections to C2 servers.
Question 84: When performing dead-box forensics on a suspect drive, which action should be taken FIRST before connecting the drive to the forensic workstation?
- Create a logical copy of the drive
- Document the drive's serial number and model
- Run antivirus software on the workstation
- Attach a hardware write blocker to the suspect drive (Correct answer)
Correct answer: Attach a hardware write blocker to the suspect drive
A hardware write blocker must be attached first to prevent any writes to the suspect drive, preserving forensic integrity before any other action.
Question 85: A CISO requests a briefing on how a recent APT campaign may affect the organization's industry vertical. Which intelligence product best fulfills this request?
- A STIX bundle of campaign IOCs
- A blocklist of malicious IPs
- A strategic threat intelligence report (Correct answer)
- A YARA rule set for detection
Correct answer: A strategic threat intelligence report
A strategic threat intelligence report contextualizes adversary campaigns within industry trends and provides actionable insights for executive decision-making.
CompTIA CySA+ (CS0-003)
The CompTIA Cybersecurity Analyst+ (CySA+) certification validates skills in applying behavioral analytics to networks and devices to prevent, detect, and combat cybersecurity threats through continuous security monitoring. It covers security operations, vulnerability management, incident response, and compliance reporting.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds