CySA+ Test CySA+ Knowledge Areas Covered 3 — Questions and Answers
Question 1: Which CySA+ domain includes reviewing security policies and performing gap analyses against frameworks like NIST CSF?
- Threat Intelligence
- Incident Response
- Compliance and Assessment (Correct answer)
- Security Operations and Monitoring
Correct answer: Compliance and Assessment
Gap analyses and framework alignment reviews are core activities in the Compliance and Assessment domain.
Question 2: An analyst correlates endpoint telemetry with network flow data to detect a slow-and-low exfiltration. Which tool category supports this?
- SIEM (Correct answer)
- IDS
- Firewall
- Vulnerability Scanner
Correct answer: SIEM
SIEMs aggregate and correlate telemetry from multiple sources to detect complex, multi-stage attacks like slow exfiltration.
Question 3: Which CySA+ concept involves proactively searching for threats that have evaded existing security controls?
- Vulnerability Scanning
- Penetration Testing
- Threat Hunting (Correct answer)
- Incident Response
Correct answer: Threat Hunting
Threat hunting is the proactive search for threats that have bypassed automated detection controls.
Question 4: A security team uses sandboxing to detonate a suspicious email attachment. Which domain covers this technique?
- Compliance and Assessment
- Threat Intelligence (Correct answer)
- Incident Response
- Vulnerability Management
Correct answer: Threat Intelligence
Dynamic malware analysis using sandboxes is a Threat Intelligence technique for understanding malware behavior.
Question 5: Which CySA+ domain addresses proper handling and chain of custody for digital evidence?
- Security Operations and Monitoring
- Compliance and Assessment
- Incident Response (Correct answer)
- Threat Intelligence
Correct answer: Incident Response
Evidence collection, preservation, and chain of custody are Incident Response responsibilities under CySA+.
Question 6: An analyst is using Shodan to identify exposed services on the organization's public IP ranges. This supports which activity?
- Attack Surface Management (Correct answer)
- Incident Response
- Policy Review
- Threat Categorization
Correct answer: Attack Surface Management
Using external scanning tools like Shodan to find exposed assets is an Attack Surface Management activity.
Question 7: Which CySA+ knowledge area includes reviewing software development pipelines for security misconfigurations?
- Compliance and Assessment
- Software and Systems Security (Correct answer)
- Threat Intelligence
- Security Operations
Correct answer: Software and Systems Security
Securing CI/CD pipelines and development environments falls within the Software and Systems Security domain.
Which CySA+ domain includes reviewing security policies and performing gap analyses against frameworks like NIST CSF?