CySA+ Test CySA+ Evaluation Format and Question Types 3 — Questions and Answers
Question 1: Which of the following question formats on the CySA+ exam requires a candidate to analyze a dashboard or log output and select the correct finding?
- Matching question
- Exhibit-based multiple-choice question (Correct answer)
- Hot-spot question
- Drag-and-drop question
Correct answer: Exhibit-based multiple-choice question
Exhibit-based questions present a screenshot, log snippet, or chart and ask the candidate to interpret it before choosing the correct answer.
Question 2: The CySA+ exam blueprint lists four domains. Which domain covers threat intelligence and threat hunting?
- Security Operations (Correct answer)
- Vulnerability Management
- Incident Response
- Reporting and Communication
Correct answer: Security Operations
Threat intelligence lifecycle and threat hunting activities fall under the Security Operations domain of the CySA+ CS0-003 blueprint.
Question 3: How does CompTIA handle unscored (pretest) questions on the CySA+ exam?
- They are clearly labeled so candidates can skip them
- They appear randomly and are not distinguishable from scored questions (Correct answer)
- They are presented only at the end of the exam
- They are only included in beta exams
Correct answer: They appear randomly and are not distinguishable from scored questions
Pretest questions are embedded throughout the exam and look identical to scored questions; they do not affect the final score.
Question 4: A candidate receives a score report immediately after completing the CySA+ exam. The report shows 'FAIL' with a score of 710. What does this indicate?
- The candidate passed but needs to retake one domain
- The candidate scored below the 750 passing threshold (Correct answer)
- The exam scoring engine encountered an error
- The candidate did not complete all PBQs
Correct answer: The candidate scored below the 750 passing threshold
A score of 710 is below CompTIA's required passing score of 750 on the 100–900 scale, resulting in a failure.
Question 5: Which of the following BEST explains why the CySA+ exam includes performance-based questions?
- To increase exam length and difficulty artificially
- To assess practical skills that multiple-choice questions cannot measure (Correct answer)
- To comply with ISO 17024 scoring requirements
- To replace all traditional multiple-choice questions
Correct answer: To assess practical skills that multiple-choice questions cannot measure
PBQs evaluate hands-on competency — such as analyzing logs or configuring tools — that cannot be reliably measured with rote recall questions.
Question 6: What is the recommended approach when a candidate encounters a difficult PBQ near the beginning of the CySA+ exam?
- Submit a blank answer immediately to save time for other questions
- Spend as much time as needed before moving on
- Skip or minimally complete it and return if time allows (Correct answer)
- Ask the proctor for a hint
Correct answer: Skip or minimally complete it and return if time allows
Experts advise skipping time-consuming PBQs initially, completing the multiple-choice section, and returning with remaining time.
Question 7: The CySA+ certification is aligned with which NICE Cybersecurity Workforce Framework work roles?
- System Administrator and Network Engineer
- Cyber Defense Analyst and Vulnerability Analyst (Correct answer)
- Penetration Tester and Red Team Operator
- Security Architect and Risk Manager
Correct answer: Cyber Defense Analyst and Vulnerability Analyst
The CySA+ maps to NICE Framework roles such as Cyber Defense Analyst and Vulnerability Analyst, reflecting defensive and analytical duties.
Which of the following question formats on the CySA+ exam requires a candidate to analyze a dashboard or log output and select the correct finding?