โ† All CySA+ Test Flashcard Decks

CySA+ Performance Tracking and Feedback Flashcards

7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 CySA+ Performance Tracking and Feedback flashcards as text
  1. An analyst notices that the number of security alerts has tripled after deploying a new detection rule, but confirmed incidents have not increased. This most likely indicates:

    Answer: The new rule has a high false positive rate requiring tuning

    A spike in alerts without a corresponding increase in confirmed incidents strongly suggests the new rule is generating excessive false positives and needs refinement.

  2. Which continuous monitoring approach provides near-real-time feedback on the security posture of an organization's cloud environment?

    Answer: Cloud Security Posture Management (CSPM) with automated policy checks

    CSPM tools continuously evaluate cloud configurations against security policies and alert on deviations, providing near-real-time posture feedback.

  3. A purple team exercise concludes. Which output is most useful for improving detection KPIs?

    Answer: A list of attack techniques that were executed but NOT detected by existing controls

    Undetected techniques reveal gaps in detection coverage, directly informing rule improvements and KPI targets for future detection effectiveness.

  4. A security program measures 'security debt' over time. What does this metric represent?

    Answer: The accumulated backlog of unresolved vulnerabilities and control gaps

    Security debt quantifies the growing backlog of unaddressed vulnerabilities, misconfigurations, and control gaps that increase organizational risk over time.

  5. A CISO presents a risk heat map to leadership. What does the heat map primarily communicate?

    Answer: The likelihood and impact of identified risks, color-coded by severity

    A risk heat map visually plots risks on a likelihood-versus-impact matrix, using color coding to help leadership prioritize risk treatment decisions.

  6. Which practice best prevents metric gaming, where teams manipulate numbers to meet targets without improving actual security?

    Answer: Use multiple correlated metrics so that improving one in isolation is insufficient

    Correlated metrics create a system where gaming one measure is insufficient because related measures would reveal the manipulation or fail to improve together.

  7. After a tabletop exercise, the team identifies that communication between IT and legal during an incident was unclear. Which corrective action best addresses this as a performance improvement?

    Answer: Update the incident response plan to include defined communication protocols and escalation paths for legal

    Updating the IR plan with explicit communication protocols and escalation paths directly addresses the identified gap revealed by the exercise.