CompTIA CySA+ (CS0-003) — Questions and Answers
Question 1: Which metric in CVSSv3 indicates that an attacker must be on the same logical or physical network as the vulnerable system to exploit it?
- Attack Vector: Network
- Attack Vector: Adjacent (Correct answer)
- Attack Vector: Physical
- Attack Vector: Local
Correct answer: Attack Vector: Adjacent
The Adjacent (A) attack vector requires the attacker to be on the same network segment or broadcast domain as the target.
Question 2: A CySA+ analyst is using the FAIR (Factor Analysis of Information Risk) model. What does FAIR primarily focus on?
- Categorizing assets by sensitivity level
- Defining qualitative risk tiers for compliance
- Quantifying risk in financial terms using probability and magnitude (Correct answer)
- Creating a heat map of threat actors
Correct answer: Quantifying risk in financial terms using probability and magnitude
FAIR is a quantitative framework that models risk as a function of probable frequency and probable magnitude of loss events.
Question 3: What is encryption?
- Compressing files
- Deleting data
- Backing up data
- Converting data into coded format to prevent unauthorized access (Correct answer)
Correct answer: Converting data into coded format to prevent unauthorized access
Encryption transforms readable data into unreadable ciphertext using algorithms and keys, ensuring only authorized parties can access the information.
Question 4: Which term describes a security weakness introduced by a developer leaving debugging code, hardcoded credentials, or undocumented functions in production software?
- Race condition
- Zero-day vulnerability
- Logic error
- Backdoor / developer backdoor (Correct answer)
Correct answer: Backdoor / developer backdoor
Backdoors or developer backdoors are unintended or intentional access mechanisms left in production code that bypass normal authentication or authorization controls.
Question 5: An analyst needs to determine if malware communicated with a command-and-control server. Which artifact provides the MOST direct evidence?
- Firewall outbound connection logs (Correct answer)
- User account creation logs
- Windows prefetch files
- Registry run keys
Correct answer: Firewall outbound connection logs
Firewall outbound connection logs directly show network communication attempts, including connections to C2 servers.
Question 6: A threat actor compromises a domain controller and forges a Kerberos ticket-granting ticket (TGT) with a custom lifetime of 10 years using the KRBTGT hash. What type of attack is this?
- Golden Ticket attack (Correct answer)
- Kerberoasting
- Silver Ticket attack
- Pass-the-Hash attack
Correct answer: Golden Ticket attack
A Golden Ticket attack uses the compromised KRBTGT account hash to forge valid Kerberos TGTs, granting the attacker persistent, domain-wide access that persists even after password resets.
Question 7: Which Volatility framework plugin would BEST help an analyst identify injected code in a running Windows process during memory forensics?
- malfind (Correct answer)
- netscan
- dlllist
- pslist
Correct answer: malfind
The `malfind` plugin scans process memory for regions with suspicious characteristics such as executable permissions and MZ headers not associated with mapped DLLs.
Question 8: Which of the following is an example of a lagging indicator in a security program?
- Current CVSS score distribution across the environment
- Percentage of systems missing endpoint agents today
- Number of security incidents confirmed last quarter (Correct answer)
- Number of unpatched critical vulnerabilities currently open
Correct answer: Number of security incidents confirmed last quarter
Incidents confirmed last quarter are a lagging indicator because they reflect past performance rather than current or predictive security posture.
Question 9: An analyst discovers that a critical vulnerability on a legacy PLC cannot be patched due to vendor support constraints. What is the MOST appropriate response?
- Implement network segmentation and enhanced monitoring as compensating controls (Correct answer)
- Decommission the system immediately
- Accept the risk and document it with no further action
- Run daily vulnerability scans against the device
Correct answer: Implement network segmentation and enhanced monitoring as compensating controls
When patching is not feasible, isolating the system via network segmentation and increasing monitoring reduces the attack surface and detection time.
Question 10: An organization wants to enforce that its vendors can only access specific systems during business hours from approved IP addresses. Which access control model is MOST suited to enforce this policy?
- Role-Based Access Control (RBAC)
- Attribute-Based Access Control (ABAC) (Correct answer)
- Discretionary Access Control (DAC)
- Mandatory Access Control (MAC)
Correct answer: Attribute-Based Access Control (ABAC)
ABAC makes access decisions based on multiple attributes — such as user identity, time of day, IP address, and resource type — making it the most flexible model for complex, context-aware policies.
Question 11: Which metric within the CVSS v3 Temporal Score group reflects whether a working exploit code is publicly available?
- Exploit Code Maturity (Correct answer)
- Report Confidence
- Attack Vector
- Remediation Level
Correct answer: Exploit Code Maturity
Exploit Code Maturity (E) in the Temporal group indicates the current state of available exploit techniques, ranging from unproven to functional to weaponized.
Question 12: Which NIST SP 800-61 phase occurs immediately after detecting and analyzing a potential incident?
- Post-Incident Activity
- Containment, Eradication, and Recovery (Correct answer)
- Communication and Escalation
- Preparation
Correct answer: Containment, Eradication, and Recovery
NIST SP 800-61 defines four phases; Containment, Eradication, and Recovery follow the Detection and Analysis phase.
Question 13: Which metric BEST measures the efficiency of a SOC's incident detection capability?
- Mean Time to Detect (MTTD) (Correct answer)
- Mean Time to Respond (MTTR)
- Number of alerts closed per day
- False positive rate
Correct answer: Mean Time to Detect (MTTD)
MTTD measures how quickly the SOC identifies a threat after it occurs, directly reflecting detection capability effectiveness.
Question 14: What is encryption?
- Backing up data
- Converting data into coded format to prevent unauthorized access (Correct answer)
- Compressing files
- Deleting data
Correct answer: Converting data into coded format to prevent unauthorized access
Encryption transforms readable data into unreadable ciphertext using algorithms and keys, ensuring only authorized parties can access the information.
Question 15: An analyst is performing triage on 50 simultaneous alerts. Which approach BEST prioritizes response efforts?
- Focus only on alerts with the highest CVSS scores
- Prioritize by asset criticality and potential business impact (Correct answer)
- Address alerts in the order they were received
- Escalate all alerts to senior analysts
Correct answer: Prioritize by asset criticality and potential business impact
Triaging by asset criticality and business impact ensures the most damaging potential incidents receive immediate attention.
Question 16: A CySA+ analyst needs to capture all network traffic on a segment for analysis. Which device should be used to provide a copy of traffic to the monitoring tool without interrupting the data flow?
- Load balancer
- Network tap (Correct answer)
- Router
- Hub
Correct answer: Network tap
A network tap passively copies traffic from a link and sends it to a monitoring or analysis tool without affecting the production data flow.
Question 17: A candidate finishes the CySA+ exam with 15 minutes remaining. They want to revisit flagged questions. Which of the following is TRUE about review capability?
- The exam auto-submits when the last question is answered
- Candidates can return to any flagged question before final submission (Correct answer)
- Only PBQs can be revisited
- Flagged items cannot be reviewed after initial submission
Correct answer: Candidates can return to any flagged question before final submission
CompTIA allows candidates to flag and return to questions within the same section before final submission.
Question 18: A company's IR plan calls for activating a 'war room' during a major incident. What is the PRIMARY benefit of this approach?
- It ensures evidence is stored securely
- It satisfies regulatory notification requirements
- It physically isolates affected systems
- It centralizes decision-making and communication among key stakeholders (Correct answer)
Correct answer: It centralizes decision-making and communication among key stakeholders
A war room centralizes key personnel and communications, enabling faster coordinated decision-making during high-pressure incidents.
Question 19: What does the term 'threat actor TTP' stand for, and why is it more durable than IOCs for detection?
- Triggers, Thresholds, and Protocols; they define network behavior baselines
- Targets, Tools, and Payloads; they are embedded in malware signatures
- Tactics, Tools, and Policies; they are enforced by security controls
- Tactics, Techniques, and Procedures; TTPs change slowly compared to infrastructure IOCs (Correct answer)
Correct answer: Tactics, Techniques, and Procedures; TTPs change slowly compared to infrastructure IOCs
TTPs (Tactics, Techniques, and Procedures) describe how adversaries operate and are far more stable than IOCs like IPs or domains, which adversaries rotate frequently.
Question 20: What does a 'false negative' mean in the context of vulnerability scanning?
- The scanner reports a vulnerability with the wrong CVSS score
- The scanner fails to detect a vulnerability that is actually present (Correct answer)
- The scanner crashes during the scan
- The scanner reports a vulnerability that does not actually exist
Correct answer: The scanner fails to detect a vulnerability that is actually present
A false negative is a missed detection — the real vulnerability exists on the target but the scanner does not flag it, often due to scan limitations or evasion.
Question 21: During a Linux forensic investigation, which file would an analyst examine to find a history of commands executed as root using sudo, even if the user's bash history was cleared?
- /etc/sudoers
- /root/.bash_history
- /var/log/auth.log or /var/log/secure (Correct answer)
- /var/log/syslog
Correct answer: /var/log/auth.log or /var/log/secure
The auth.log (Debian/Ubuntu) or secure (RHEL/CentOS) log records all sudo command executions with timestamps and the originating user.
Question 22: A vulnerability management program reports that mean time to remediate (MTTR) critical vulnerabilities has increased from 7 days to 21 days over the past quarter. What is the MOST likely root cause to investigate first?
- The patch deployment process or change management workflow has a bottleneck (Correct answer)
- Critical vulnerabilities are being discovered less frequently
- The vulnerability scanner is generating more false positives
- The organization's risk appetite has changed
Correct answer: The patch deployment process or change management workflow has a bottleneck
An increasing MTTR typically signals a bottleneck in the patching or change management process — approvals, testing cycles, or resource constraints are slowing remediation.
Question 23: A forensic analyst is examining an email header and finds the 'Received-SPF' field shows 'fail' while the 'From' header displays a legitimate corporate domain. What does this MOST likely indicate?
- The email is a spoofed phishing message sent from an unauthorized server (Correct answer)
- The email was forwarded through a third-party relay, causing SPF to fail
- The recipient's mail server has an outdated SPF implementation
- The email server is misconfigured and SPF records need updating
Correct answer: The email is a spoofed phishing message sent from an unauthorized server
An SPF fail means the sending mail server is not authorized to send on behalf of the domain in the From header, which is the primary indicator of email spoofing.
Question 24: An analyst notices outbound traffic to a domain registered 24 hours ago with a high entropy subdomain. Which threat technique does this MOST suggest?
- SQL Injection
- Pass-the-Hash
- ARP Spoofing
- Domain Generation Algorithm (DGA) (Correct answer)
Correct answer: Domain Generation Algorithm (DGA)
Newly registered domains with high-entropy subdomains are a hallmark of Domain Generation Algorithms used by malware to locate C2 infrastructure.
Question 25: What is multi-factor authentication (MFA)?
- Requiring two or more verification methods to confirm identity (Correct answer)
- Logging in from multiple devices
- Using multiple passwords
- Having multiple accounts
Correct answer: Requiring two or more verification methods to confirm identity
MFA combines two or more authentication factors (something you know, have, or are) for stronger identity verification.
Question 26: Which confidence scoring model is commonly used in threat intelligence reports to express the analyst's certainty about an assessment?
- Admiralty Code / Probabilistic language scale (Correct answer)
- OWASP Risk Rating
- DREAD model
- CVSS scoring
Correct answer: Admiralty Code / Probabilistic language scale
The Admiralty Code (source reliability + information credibility) and NATO/probabilistic language scales are standard ways to express confidence in intelligence assessments.
Question 27: Which CySA+ tool or technique would BEST help detect when a legitimate user account is exhibiting anomalous behavior such as logging in at unusual hours or accessing unusual resources?
- Static application security testing (SAST)
- Vulnerability scanner
- User and Entity Behavior Analytics (UEBA) (Correct answer)
- Network intrusion detection system (NIDS)
Correct answer: User and Entity Behavior Analytics (UEBA)
UEBA establishes behavioral baselines for users and entities, then flags deviations such as unusual login times or abnormal data access patterns that may indicate account compromise or insider threat.
Question 28: A penetration tester uses exploitation to confirm that a vulnerability scanner finding is truly exploitable. How does this differ from a vulnerability assessment?
- Penetration testing only uses automated tools, while vulnerability assessments are manual
- Penetration testing actively exploits vulnerabilities to confirm impact, while vulnerability assessment identifies and reports potential weaknesses (Correct answer)
- Vulnerability assessments require credentials, while penetration tests do not
- Penetration testing is performed externally only, while vulnerability assessments are internal
Correct answer: Penetration testing actively exploits vulnerabilities to confirm impact, while vulnerability assessment identifies and reports potential weaknesses
Penetration testing goes beyond identification by attempting to exploit vulnerabilities to demonstrate real-world impact, whereas vulnerability assessments enumerate and rate findings without exploitation.
Question 29: Which document formally records identified risks, their likelihood, impact, owner, and current treatment status?
- Risk register (Correct answer)
- Business Impact Analysis
- System Security Plan
- Vulnerability scan report
Correct answer: Risk register
A risk register is the central document that tracks all identified risks along with their attributes, owners, and treatment plans.
Question 30: During incident triage, what is the PRIMARY purpose of calculating an IOC's confidence score?
- To prioritize investigation efforts based on reliability of the threat indicator (Correct answer)
- To assign the incident to the correct analyst
- To calculate the time required for remediation
- To determine the financial impact of the incident
Correct answer: To prioritize investigation efforts based on reliability of the threat indicator
Confidence scores indicate how reliable an IOC is based on its source quality and corroboration, helping analysts focus on high-confidence indicators first.
CompTIA CySA+ (CS0-003)
The CompTIA Cybersecurity Analyst+ (CySA+) certification validates skills in applying behavioral analytics to networks and devices to prevent, detect, and combat cybersecurity threats through continuous security monitoring. It covers security operations, vulnerability management, incident response, and compliance reporting.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds