CySA+ Test CySA+ Performance Tracking and Feedback 3 — Questions and Answers
Question 1: Which of the following best describes the purpose of a security scorecard presented to the board of directors?
- Provide raw SIEM logs for board review
- Translate technical security metrics into business-relevant risk language (Correct answer)
- List every CVE discovered in the quarter
- Detail firewall rule changes made during the period
Correct answer: Translate technical security metrics into business-relevant risk language
Security scorecards for executives translate technical findings into business risk terms that non-technical stakeholders can understand and act on.
Question 2: A team notices that alert volume spikes every Monday morning. What should the team investigate first?
- Replace the SIEM with a newer platform
- Correlate the spike with scheduled business processes like batch jobs or backups (Correct answer)
- Immediately escalate all Monday alerts to critical
- Disable alerting on Monday mornings to reduce noise
Correct answer: Correlate the spike with scheduled business processes like batch jobs or backups
Recurring spikes often correlate with scheduled business events; correlating alert volume with known processes helps distinguish noise from true incidents.
Question 3: An analyst wants to determine whether a new threat-hunting playbook improved detection of lateral movement. Which comparison approach is most appropriate?
- Compare raw log volumes before and after playbook deployment
- Measure true-positive lateral movement detections before and after playbook deployment (Correct answer)
- Count the number of playbook executions performed
- Survey analyst satisfaction with the new playbook
Correct answer: Measure true-positive lateral movement detections before and after playbook deployment
Measuring true-positive detections before and after deployment directly assesses whether the playbook improves detection accuracy for the targeted threat.
Question 4: A feedback loop in incident response ensures that lessons learned from one incident are used to improve future response. Which document formally captures this?
- Threat intelligence report
- Post-incident review (PIR) / after-action report (AAR) (Correct answer)
- Asset inventory
- Business continuity plan
Correct answer: Post-incident review (PIR) / after-action report (AAR)
A Post-Incident Review or After-Action Report formally documents root causes, gaps, and recommended improvements to feed back into procedures.
Question 5: Which metric directly measures the efficiency of the vulnerability management process?
- Number of threat intelligence feeds subscribed
- Average days to remediate critical vulnerabilities (Correct answer)
- Total number of assets scanned
- Firewall throughput in Gbps
Correct answer: Average days to remediate critical vulnerabilities
Average days to remediate critical vulnerabilities measures how quickly the team resolves the highest-risk weaknesses, indicating process efficiency.
Question 6: An organization's false positive rate for its IDS is 40%. What is the primary business impact of this high rate?
- Increased storage costs for log retention
- Analyst time wasted on non-threats, increasing MTTD for real incidents (Correct answer)
- Reduced bandwidth on the network segment
- Lower CVSS scores for detected vulnerabilities
Correct answer: Analyst time wasted on non-threats, increasing MTTD for real incidents
A high false positive rate consumes analyst time on non-threats, diverting resources and increasing the time needed to detect and respond to real incidents.
Question 7: Which feedback mechanism allows frontline SOC analysts to suggest improvements to detection rules based on daily experience?
- Automated patch deployment pipeline
- Continuous improvement process with analyst input channels (Correct answer)
- Annual penetration test report
- Executive risk committee review
Correct answer: Continuous improvement process with analyst input channels
A continuous improvement process with structured analyst input channels captures ground-level observations to refine detection rules and workflows iteratively.
Which of the following best describes the purpose of a security scorecard presented to the board of directors?