โ† All CySA+ Test Flashcard Decks

CySA+ Difficulty Level Flashcards

7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 CySA+ Difficulty Level flashcards as text
  1. Which CySA+ domain requires analysts to evaluate the effectiveness of existing security controls against threat intelligence feeds?

    Answer: Threat Intelligence and Threat Hunting

    The Threat Intelligence and Threat Hunting domain specifically requires analysts to correlate threat intel with control effectiveness.

  2. A SOC analyst receives an alert that a host is beaconing to a known C2 server every 60 seconds. Which tactic in the MITRE ATT&CK framework best describes this behavior?

    Answer: Command and Control

    Regular callback intervals to a C2 server are classified under the Command and Control tactic in MITRE ATT&CK.

  3. On the CySA+ exam, scenario-based questions most frequently test which skill?

    Answer: Applying analytical reasoning to realistic security events

    CySA+ scenario questions are designed to assess whether candidates can apply analytical thinking to realistic, contextual security situations.

  4. Which log source would BEST help an analyst determine whether a Windows host has had its audit policy modified?

    Answer: Security Event Log (Event ID 4719)

    Event ID 4719 in the Windows Security Event Log records changes to system audit policy.

  5. An analyst is tasked with reducing alert fatigue in the SIEM. Which action addresses the root cause most effectively?

    Answer: Tuning detection rules to reduce false positives

    Tuning detection rules reduces false positives, which is the primary driver of alert fatigue.

  6. Which vulnerability scoring metric in CVSSv3 reflects how complex the conditions must be for an attacker to exploit the vulnerability?

    Answer: Attack Complexity

    Attack Complexity in CVSSv3 measures the conditions beyond the attacker's control that must exist for exploitation.

  7. During a purple team exercise, the blue team fails to detect a simulated lateral movement via PsExec. Which control gap does this MOST likely indicate?

    Answer: Missing detection logic for SMB-based admin tool execution

    PsExec operates over SMB using legitimate admin shares; the gap is missing behavioral detection for admin tool abuse, not AV signatures.