CySA+ Test CySA+ Knowledge Areas Covered 2 — Questions and Answers
Question 1: A security analyst notices that a host is sending beaconing traffic to an external IP every 60 seconds. Which CySA+ domain does this investigation fall under?
- Vulnerability Management
- Threat and Vulnerability Management
- Security Operations and Monitoring (Correct answer)
- Compliance and Assessment
Correct answer: Security Operations and Monitoring
Identifying and investigating beaconing behavior is a core Security Operations and Monitoring activity in CySA+.
Question 2: Which CySA+ knowledge area covers the use of YARA rules for identifying malware samples?
- Threat Intelligence (Correct answer)
- Incident Response
- Security Architecture
- Compliance and Assessment
Correct answer: Threat Intelligence
Creating and applying YARA rules to identify malware is part of the Threat Intelligence knowledge area in CySA+.
Question 3: When a CySA+ analyst uses the Diamond Model to analyze an attack, which domain is primarily being applied?
- Incident Response
- Threat and Vulnerability Management
- Threat Intelligence (Correct answer)
- Security Operations
Correct answer: Threat Intelligence
The Diamond Model is a threat intelligence framework used to analyze adversary operations and attribution.
Question 4: A company wants to ensure its web application controls align with OWASP Top 10. Which CySA+ domain is most relevant?
- Threat Intelligence
- Software and Systems Security (Correct answer)
- Compliance and Assessment
- Security Operations and Monitoring
Correct answer: Software and Systems Security
Evaluating and securing applications against OWASP Top 10 falls under the Software and Systems Security domain.
Question 5: An analyst is reviewing firewall logs to detect lateral movement after a phishing attack. This activity primarily supports which phase?
- Eradication
- Containment
- Identification (Correct answer)
- Recovery
Correct answer: Identification
Reviewing logs to determine the scope and path of an attack is part of the Identification phase of incident response.
Question 6: Which CySA+ concept describes grouping related threat actor behaviors using a shared taxonomy like ATT&CK?
- Threat Hunting
- Threat Modeling
- Adversary Emulation
- Threat Categorization (Correct answer)
Correct answer: Threat Categorization
Threat categorization organizes behaviors and techniques using frameworks like MITRE ATT&CK to structure analysis.
Question 7: A CySA+ analyst is tasked with reducing the attack surface of cloud-hosted workloads. Which domain does this align with?
- Compliance and Assessment
- Threat Intelligence
- Software and Systems Security (Correct answer)
- Security Operations and Monitoring
Correct answer: Software and Systems Security
Hardening cloud workloads and reducing attack surface are Software and Systems Security responsibilities in CySA+.
A security analyst notices that a host is sending beaconing traffic to an external IP every 60 seconds.
Which CySA+ domain does this investigation fall under?