CySA+ Difficulty Level Flashcards
7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 CySA+ Difficulty Level flashcards as text
Which phase of the incident response lifecycle focuses on identifying lessons learned and updating playbooks?
Answer: Post-Incident Activity
Post-Incident Activity (also called Post-Incident Review) is the phase where lessons learned are documented and controls are updated.
An analyst notices outbound traffic to a domain registered 24 hours ago with a high entropy subdomain. Which threat technique does this MOST suggest?
Answer: Domain Generation Algorithm (DGA)
Newly registered domains with high-entropy subdomains are a hallmark of Domain Generation Algorithms used by malware to locate C2 infrastructure.
A CySA+ candidate struggles most with performance-based questions. What study approach is MOST effective?
Answer: Practicing with hands-on labs and scenario simulations
Performance-based questions require applied skills; hands-on lab practice and scenario simulations directly build the competencies tested.
Which tool would an analyst use to passively map the network topology without generating traffic?
Answer: Wireshark packet capture analysis
Analyzing existing Wireshark captures allows topology mapping without generating new probe traffic.
A newly discovered vulnerability has a CVSS base score of 9.8 but no public exploit exists yet. How should a CySA+ analyst BEST prioritize remediation?
Answer: Prioritize based on asset criticality and exploit likelihood
Risk-based prioritization weighs CVSS score alongside asset criticality and the likelihood of exploitation, not just severity alone.
Which network artifact would BEST help confirm data exfiltration over DNS?
Answer: Unusually large DNS TXT or NULL record responses
DNS tunneling encodes data in record types like TXT or NULL; abnormally large responses are a primary indicator.
What distinguishes threat hunting from traditional reactive incident response?
Answer: Threat hunting proactively searches for hidden threats before alerts fire
Threat hunting is a proactive, hypothesis-driven search for threats that have evaded existing detection controls.