CompTIA CySA+ (CS0-003) — Questions and Answers
Question 1: Which of the following BEST describes the concept of 'attack surface reduction' as a vulnerability management strategy?
- Limiting scanner access to reduce scan scope
- Reducing CVSS scores by applying patches
- Eliminating unnecessary services, ports, and software to minimize the number of exploitable entry points (Correct answer)
- Reducing the number of vulnerability reports sent to the IT team
Correct answer: Eliminating unnecessary services, ports, and software to minimize the number of exploitable entry points
Attack surface reduction removes unused services, disables default accounts, and uninstalls unnecessary software to shrink the number of vectors an attacker can leverage.
Question 2: What is encryption?
- Converting data into coded format to prevent unauthorized access (Correct answer)
- Compressing files
- Backing up data
- Deleting data
Correct answer: Converting data into coded format to prevent unauthorized access
Encryption transforms readable data into unreadable ciphertext using algorithms and keys, ensuring only authorized parties can access the information.
Question 3: During forensic triage, an analyst must prioritize which data to collect first based on volatility. Which represents the CORRECT order from most to least volatile?
- RAM → CPU registers → Disk image → Network state
- Network connections → RAM → CPU registers → Disk image
- Disk image → RAM → Network state → CPU registers
- CPU registers → RAM → Network connections → Disk image (Correct answer)
Correct answer: CPU registers → RAM → Network connections → Disk image
The RFC 3227 order of volatility goes from CPU registers (lost on context switch) to RAM to network state to disk, as each level persists longer.
Question 4: What is the primary purpose of credentialed scanning versus unauthenticated scanning?
- Credentialed scans run faster and produce fewer false positives
- Unauthenticated scans require more network bandwidth
- Credentialed scans only work on Windows systems
- Credentialed scans can enumerate installed software, patch levels, and local configuration without relying on exposed network services (Correct answer)
Correct answer: Credentialed scans can enumerate installed software, patch levels, and local configuration without relying on exposed network services
Providing scanner credentials allows it to log into hosts and inspect installed packages, registry settings, and configuration files, producing far more comprehensive and accurate results.
Question 5: A threat hunter notices recurring outbound SMB (port 445) connections from a workstation to an internet IP. Why is this significant from a CySA+ perspective?
- This indicates Windows Update traffic being misclassified
- SMB over the internet is common for cloud file sharing
- SMB should never traverse the internet; this suggests a firewall misconfiguration or active attack (Correct answer)
- SMB is only used for printer sharing and is low risk
Correct answer: SMB should never traverse the internet; this suggests a firewall misconfiguration or active attack
SMB is an internal protocol that should never appear as outbound internet traffic; its presence indicates either a firewall gap, malware lateral movement preparation, or active exploitation.
Question 6: During an investigation, an analyst finds that an attacker used legitimate admin credentials to move laterally. Which log would BEST help reconstruct this activity timeline?
- Windows Security Event Logs with authentication events (Correct answer)
- DHCP server logs
- Application crash logs
- Email server delivery logs
Correct answer: Windows Security Event Logs with authentication events
Windows Security Event Logs capturing authentication events (logon/logoff, credential use) provide the best timeline reconstruction for lateral movement using legitimate credentials.
Question 7: An organization must notify affected customers within 72 hours of discovering a data breach. Which regulation MOST likely mandates this requirement?
- HIPAA
- SOX
- PCI DSS
- GDPR (Correct answer)
Correct answer: GDPR
GDPR (General Data Protection Regulation) mandates that organizations notify supervisory authorities within 72 hours of becoming aware of a personal data breach.
Question 8: A newly discovered vulnerability has a CVSS base score of 9.8 but no public exploit exists yet. How should a CySA+ analyst BEST prioritize remediation?
- Wait for vendor guidance before acting
- Deprioritize it since no exploit exists
- Prioritize based on asset criticality and exploit likelihood (Correct answer)
- Patch immediately regardless of asset criticality
Correct answer: Prioritize based on asset criticality and exploit likelihood
Risk-based prioritization weighs CVSS score alongside asset criticality and the likelihood of exploitation, not just severity alone.
Question 9: An organization scans its environment weekly but new vulnerabilities are continuously introduced through software deployments. Which process BEST addresses this gap?
- Requiring manual code reviews for all deployments
- Disabling automatic deployments until weekly scans complete
- Increasing scan frequency to daily
- Integrating vulnerability scanning into the CI/CD pipeline (Correct answer)
Correct answer: Integrating vulnerability scanning into the CI/CD pipeline
Embedding scanning into CI/CD pipelines ensures every build is tested before it reaches production, addressing the gap that periodic scans miss newly deployed code.
Question 10: A penetration tester uses exploitation to confirm that a vulnerability scanner finding is truly exploitable. How does this differ from a vulnerability assessment?
- Penetration testing only uses automated tools, while vulnerability assessments are manual
- Vulnerability assessments require credentials, while penetration tests do not
- Penetration testing actively exploits vulnerabilities to confirm impact, while vulnerability assessment identifies and reports potential weaknesses (Correct answer)
- Penetration testing is performed externally only, while vulnerability assessments are internal
Correct answer: Penetration testing actively exploits vulnerabilities to confirm impact, while vulnerability assessment identifies and reports potential weaknesses
Penetration testing goes beyond identification by attempting to exploit vulnerabilities to demonstrate real-world impact, whereas vulnerability assessments enumerate and rate findings without exploitation.
Question 11: A CySA+ analyst needs to prioritize hundreds of vulnerabilities. Which combination of factors BEST represents an effective risk-based prioritization model?
- Number of affected hosts and time since last scan
- CVSS base score, asset criticality, and exploitability in the wild (Correct answer)
- Patch availability and OS platform type
- CVE publication date and vendor severity rating
Correct answer: CVSS base score, asset criticality, and exploitability in the wild
Effective prioritization combines the technical severity (CVSS), business value of the asset, and whether active exploitation is occurring to focus remediation effort on the highest real-world risk.
Question 12: An analyst discovers that an IOC flagged in their SIEM was published three years ago and has not appeared in any recent feeds. How should the analyst treat this IOC?
- Remove it from the SIEM permanently
- Immediately escalate as a critical incident
- Treat it as high confidence because it has been validated over time
- Consider it potentially stale and verify its current relevance (Correct answer)
Correct answer: Consider it potentially stale and verify its current relevance
IOCs have a limited lifespan; old indicators may represent infrastructure no longer used by adversaries, requiring freshness validation before acting on them.
Question 13: A forensic analyst is examining browser artifacts on a Windows system. Which SQLite database file stores Chrome browsing history?
- C:\Users\<user>\AppData\Local\Google\Chrome\User Data\Default\History (Correct answer)
- C:\Users\<user>\AppData\Local\Google\Chrome\cache.db
- C:\Users\<user>\AppData\Roaming\Google\Chrome\history.db
- C:\ProgramData\Google\Chrome\browsing.sqlite
Correct answer: C:\Users\<user>\AppData\Local\Google\Chrome\User Data\Default\History
Chrome stores browsing history in a SQLite database named 'History' located in the user's Chrome Default profile directory.
Question 14: Which NetFlow field is MOST useful for identifying lateral movement between internal hosts?
- DSCP markings
- TCP window size
- Source and destination IP pairs with byte counts (Correct answer)
- Source and destination AS numbers
Correct answer: Source and destination IP pairs with byte counts
Internal source/destination IP pairs with associated byte counts reveal east-west traffic patterns indicative of lateral movement.
Question 15: A financial institution must comply with the Gramm-Leach-Bliley Act (GLBA). Which safeguard rule element requires designation of a qualified individual to oversee the information security program?
- Encryption requirement
- Risk assessment requirement
- Penetration testing mandate
- Qualified Individual designation (Correct answer)
Correct answer: Qualified Individual designation
The FTC Safeguards Rule under GLBA requires financial institutions to designate a qualified individual responsible for overseeing and implementing the information security program.
Question 16: A security analyst is reviewing a third-party vendor's SOC 2 Type II report. The report covers availability and confidentiality criteria. What are these criteria formally called?
- Trust Service Criteria (TSC) (Correct answer)
- Control objectives
- COSO principles
- Common Criteria
Correct answer: Trust Service Criteria (TSC)
AICPA defines the five Trust Service Criteria (security, availability, processing integrity, confidentiality, privacy) used in SOC 2 engagements.
Question 17: Which IAM principle ensures that users are granted only the minimum permissions necessary to perform their job functions?
- Least privilege (Correct answer)
- Separation of duties
- Need to know
- Role rotation
Correct answer: Least privilege
The principle of least privilege limits user access rights to only what is strictly required for their role, reducing the attack surface if credentials are compromised.
Question 18: A forensic examiner must analyze a disk image without altering it. Which command correctly mounts the image as read-only on Linux?
- mount -t ntfs disk.img /mnt/evidence
- losetup -f disk.img && mount /dev/loop0 /mnt/evidence
- dd if=disk.img of=/dev/sdb bs=4M
- mount -o ro,loop disk.img /mnt/evidence (Correct answer)
Correct answer: mount -o ro,loop disk.img /mnt/evidence
The `-o ro,loop` flags mount the image as read-only using a loop device, preserving forensic integrity.
Question 19: During a PCI DSS assessment, the QSA finds that the organization uses multi-factor authentication only for remote access. According to PCI DSS v4.0, where else is MFA now required?
- For all non-console administrative access into the CDE (Correct answer)
- Only for service accounts accessing cardholder databases
- Solely for external-facing web applications
- Only for privileged accounts accessing the CDE remotely
Correct answer: For all non-console administrative access into the CDE
PCI DSS v4.0 Requirement 8.4.2 requires MFA for all non-console administrative access into the CDE, expanding beyond just remote access.
Question 20: What is a firewall?
- A fire-resistant building component
- A password manager
- An antivirus program
- A security device that monitors and controls network traffic based on rules (Correct answer)
Correct answer: A security device that monitors and controls network traffic based on rules
Firewalls filter incoming and outgoing network traffic based on security rules, creating a barrier between trusted and untrusted networks.
Question 21: An analyst observes that malware deletes Volume Shadow Copies. Which type of malware MOST commonly uses this technique?
- Ransomware (Correct answer)
- Spyware
- Rootkit
- Adware
Correct answer: Ransomware
Ransomware deletes Volume Shadow Copies to prevent victims from restoring encrypted files from local backups.
Question 22: Which NIST CSF v2.0 function was newly added compared to the original five functions?
- Communicate
- Govern (Correct answer)
- Assure
- Recover
Correct answer: Govern
NIST CSF v2.0 added the Govern function to address cybersecurity risk governance, strategy, and supply chain risk management at the organizational level.
Question 23: What is the primary security concern when an organization uses a shared service account with a static password for multiple automated processes?
- Accountability is lost and the password may never be rotated, increasing risk of undetected compromise (Correct answer)
- Shared accounts cannot be enrolled in directory services
- The account will be locked out due to concurrent logins
- Multi-factor authentication cannot be applied to service accounts
Correct answer: Accountability is lost and the password may never be rotated, increasing risk of undetected compromise
Shared service accounts lack individual accountability, and static passwords are rarely rotated, creating long windows of exposure if the credential is compromised without detection.
Question 24: During incident response, a SOC analyst uses Zeek (formerly Bro) logs. Which Zeek log file is MOST useful for identifying exfiltration via HTTP?
- dns.log
- http.log (Correct answer)
- ssl.log
- conn.log
Correct answer: http.log
Zeek's http.log captures request/response details including URIs, methods, host headers, response bodies, and data sizes, making it ideal for identifying HTTP-based exfiltration.
Question 25: A security analyst uses the Cyber Kill Chain to map an attacker's actions post-compromise. Which stage involves establishing persistence?
- Weaponization
- Installation (Correct answer)
- Delivery
- Command and Control
Correct answer: Installation
In the Cyber Kill Chain, the Installation stage is where attackers establish persistence through backdoors or trojans.
Question 26: An analyst is using Shodan to identify exposed services on the organization's public IP ranges. This supports which activity?
- Incident Response
- Attack Surface Management (Correct answer)
- Threat Categorization
- Policy Review
Correct answer: Attack Surface Management
Using external scanning tools like Shodan to find exposed assets is an Attack Surface Management activity.
Question 27: A CySA+ analyst is evaluating a network where every access request is verified regardless of whether the user is inside or outside the network perimeter. Which model is this?
- Defense in depth
- Perimeter security
- Zero trust (Correct answer)
- DMZ model
Correct answer: Zero trust
Zero trust operates on the principle of 'never trust, always verify,' requiring continuous authentication and authorization for every access request.
Question 28: Which file system artifact on NTFS records the last 26 characters typed into the Windows Run dialog, even after a user clears the run history?
- LNK files in Recent folder
- Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU (Correct answer)
- Windows.edb search index
- NTFS $LogFile
Correct answer: Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU
The RunMRU registry key stores the most recently used commands entered in the Windows Run dialog and persists until explicitly deleted.
Question 29: Which document formally records that an organization has acknowledged a vulnerability and chosen not to remediate it based on business justification?
- Remediation ticket
- Vulnerability exception request
- Scan configuration baseline
- Risk register entry with accepted risk notation (Correct answer)
Correct answer: Risk register entry with accepted risk notation
Accepted risks are documented in the risk register with the business owner's sign-off, providing an audit trail for why known vulnerabilities were not remediated.
Question 30: What is the CIA triad in information security?
- Central Intelligence Agency
- Confidentiality, Integrity, Availability (Correct answer)
- Certified Information Auditor
- Cybersecurity Infrastructure Act
Correct answer: Confidentiality, Integrity, Availability
The CIA triad represents three core security principles: Confidentiality (keeping data private), Integrity (data accuracy), Availability (systems accessible when needed).
Question 31: The CySA+ exam blueprint lists four domains. Which domain covers threat intelligence and threat hunting?
- Security Operations (Correct answer)
- Reporting and Communication
- Incident Response
- Vulnerability Management
Correct answer: Security Operations
Threat intelligence lifecycle and threat hunting activities fall under the Security Operations domain of the CySA+ CS0-003 blueprint.
Question 32: Which tool is BEST suited for capturing and analyzing volatile memory from a compromised Windows system?
- Volatility (Correct answer)
- Wireshark
- Nmap
- Autopsy
Correct answer: Volatility
Volatility is a memory forensics framework specifically designed to analyze RAM dumps from Windows (and other) systems for malicious artifacts.
Question 33: What is the CIA triad in information security?
- Confidentiality, Integrity, Availability (Correct answer)
- Certified Information Auditor
- Cybersecurity Infrastructure Act
- Central Intelligence Agency
Correct answer: Confidentiality, Integrity, Availability
The CIA triad represents three core security principles: Confidentiality (keeping data private), Integrity (data accuracy), Availability (systems accessible when needed).
Question 34: A security analyst notices that a host is sending beaconing traffic to an external IP every 60 seconds. Which CySA+ domain does this investigation fall under?
- Compliance and Assessment
- Security Operations and Monitoring (Correct answer)
- Vulnerability Management
- Threat and Vulnerability Management
Correct answer: Security Operations and Monitoring
Identifying and investigating beaconing behavior is a core Security Operations and Monitoring activity in CySA+.
Question 35: Which metric within the CVSS v3 Temporal Score group reflects whether a working exploit code is publicly available?
- Attack Vector
- Remediation Level
- Report Confidence
- Exploit Code Maturity (Correct answer)
Correct answer: Exploit Code Maturity
Exploit Code Maturity (E) in the Temporal group indicates the current state of available exploit techniques, ranging from unproven to functional to weaponized.
Question 36: Which practice best prevents metric gaming, where teams manipulate numbers to meet targets without improving actual security?
- Allow teams to self-report all performance data without audit
- Reduce the number of metrics tracked to one
- Set targets so high that they are never reached
- Use multiple correlated metrics so that improving one in isolation is insufficient (Correct answer)
Correct answer: Use multiple correlated metrics so that improving one in isolation is insufficient
Correlated metrics create a system where gaming one measure is insufficient because related measures would reveal the manipulation or fail to improve together.
Question 37: During the containment phase of incident response, a security analyst isolates an infected workstation from the network. Which action should be taken NEXT?
- Wipe and reimage the system immediately
- Restore from the most recent backup
- Notify all users about the breach
- Preserve forensic evidence before any remediation (Correct answer)
Correct answer: Preserve forensic evidence before any remediation
Preserving forensic evidence before remediation ensures that volatile data and artifacts needed for investigation are not lost.
Question 38: What is phishing?
- A type of firewall
- A network scanning tool
- A backup system
- A social engineering attack using fraudulent communications to steal sensitive data (Correct answer)
Correct answer: A social engineering attack using fraudulent communications to steal sensitive data
Phishing uses deceptive emails, websites, or messages that appear legitimate to trick victims into revealing passwords, credit cards, or personal information.
Question 39: What is multi-factor authentication (MFA)?
- Having multiple accounts
- Requiring two or more verification methods to confirm identity (Correct answer)
- Using multiple passwords
- Logging in from multiple devices
Correct answer: Requiring two or more verification methods to confirm identity
MFA combines two or more authentication factors (something you know, have, or are) for stronger identity verification.
Question 40: Which NIST SP 800-37 step involves authorizing the system to operate based on acceptable risk?
- Categorize
- Monitor
- Authorize (Correct answer)
- Select
Correct answer: Authorize
The Authorize step in the RMF requires an authorizing official to make a risk-based decision to operate the system based on evaluated controls and residual risk.
Question 41: A company wants to test whether its monitoring tools can detect a real-world attack simulation without risking production systems. What exercise should they conduct?
- Compliance audit
- Purple team exercise (Correct answer)
- Tabletop exercise
- Business continuity drill
Correct answer: Purple team exercise
A purple team exercise combines red team attack simulation with blue team detection monitoring, measuring actual detection and response capabilities collaboratively.
Question 42: Which term describes a security weakness introduced by a developer leaving debugging code, hardcoded credentials, or undocumented functions in production software?
- Backdoor / developer backdoor (Correct answer)
- Race condition
- Logic error
- Zero-day vulnerability
Correct answer: Backdoor / developer backdoor
Backdoors or developer backdoors are unintended or intentional access mechanisms left in production code that bypass normal authentication or authorization controls.
Question 43: An analyst uses NetFlow data to establish a baseline and then detects anomalies. This technique is part of which domain?
- Threat Intelligence
- Incident Response
- Compliance
- Security Operations and Monitoring (Correct answer)
Correct answer: Security Operations and Monitoring
Baselining network behavior and detecting anomalies via NetFlow is a Security Operations and Monitoring technique.
Question 44: When assessing vulnerabilities in a cloud IaaS environment, which responsibility typically remains with the customer rather than the cloud provider?
- Network backbone maintenance
- Guest OS and application-level vulnerabilities (Correct answer)
- Physical host hardware patching
- Hypervisor security
Correct answer: Guest OS and application-level vulnerabilities
Under the shared responsibility model in IaaS, the customer owns the guest OS, middleware, and applications — including patching them for vulnerabilities.
Question 45: Which type of vulnerability scan examines whether web application inputs are sanitized to prevent injection attacks without requiring source-code access?
- Dynamic application security testing (DAST) (Correct answer)
- Software composition analysis (SCA)
- Static application security testing (SAST)
- Network-based scan
Correct answer: Dynamic application security testing (DAST)
DAST tests a running application from the outside by sending malicious inputs to find injection, authentication, and configuration flaws.
Question 46: The CySA+ CS0-003 Incident Response domain accounts for what percentage of exam content?
- 27% (Correct answer)
- 17%
- 33%
- 22%
Correct answer: 27%
Incident Response represents 27% of the CySA+ CS0-003 exam, making it the second-largest domain after Security Operations.
Question 47: Which of the following BEST explains why the CySA+ exam includes performance-based questions?
- To assess practical skills that multiple-choice questions cannot measure (Correct answer)
- To replace all traditional multiple-choice questions
- To increase exam length and difficulty artificially
- To comply with ISO 17024 scoring requirements
Correct answer: To assess practical skills that multiple-choice questions cannot measure
PBQs evaluate hands-on competency — such as analyzing logs or configuring tools — that cannot be reliably measured with rote recall questions.
Question 48: Which directory protocol is most commonly used by enterprises to centrally store and manage user identities, credentials, and group memberships?
- Kerberos
- RADIUS
- LDAP (Correct answer)
- TACACS+
Correct answer: LDAP
LDAP (Lightweight Directory Access Protocol) is the standard protocol for querying and modifying directory services such as Microsoft Active Directory where user identities and attributes are stored.
Question 49: A CySA+ analyst reviews a memory dump and finds a process named 'svchost.exe' running from C:\Users\Public\svchost.exe. Why is this suspicious?
- svchost.exe should not appear in memory dumps
- Multiple svchost.exe instances indicate a DDoS attack
- svchost.exe should only run on 64-bit systems
- Legitimate svchost.exe always runs from C:\Windows\System32 (Correct answer)
Correct answer: Legitimate svchost.exe always runs from C:\Windows\System32
Legitimate svchost.exe processes always originate from C:\Windows\System32; a process using the same name from a different path is a masquerading technique.
Question 50: What is encryption?
- Deleting data
- Compressing files
- Converting data into coded format to prevent unauthorized access (Correct answer)
- Backing up data
Correct answer: Converting data into coded format to prevent unauthorized access
Encryption transforms readable data into unreadable ciphertext using algorithms and keys, ensuring only authorized parties can access the information.
Question 51: Which regulation requires organizations to perform a Data Protection Impact Assessment (DPIA) before processing that is 'likely to result in a high risk'?
- HIPAA
- CCPA
- GDPR (Correct answer)
- SOX
Correct answer: GDPR
GDPR Article 35 mandates a DPIA for processing activities likely to result in high risk to individuals' rights and freedoms, particularly with new technologies.
Question 52: A security analyst is reviewing a vulnerability report and sees the term 'locally exploitable with high privileges required.' How should this affect prioritization compared to a remotely exploitable, no-privileges-required vulnerability?
- Local vulnerabilities are always more dangerous than remote ones
- Both vulnerabilities carry equal risk regardless of attack vector
- It should generally be deprioritized relative to the remote, no-auth vulnerability because exploitation requires greater attacker access (Correct answer)
- It should be prioritized higher because local access is more targeted
Correct answer: It should generally be deprioritized relative to the remote, no-auth vulnerability because exploitation requires greater attacker access
Remote, unauthenticated vulnerabilities present a much wider attack surface and lower barrier to exploitation than local vulnerabilities requiring privileged access.
Question 53: A security analyst notices that a terminated employee's account is still active in Active Directory two weeks after their departure. Which IAM process failed?
- Authentication
- De-provisioning (off-boarding) (Correct answer)
- Role-based access review
- Provisioning
Correct answer: De-provisioning (off-boarding)
De-provisioning is the process of removing access rights when an employee leaves; failure to perform this step leaves orphaned accounts that can be exploited.
Question 54: A SIEM correlation rule fires when more than 10 failed logins occur for one account within 5 minutes. An analyst reviews alerts and finds 9 failed logins followed by success. What should the analyst do FIRST?
- Block the source IP immediately
- Investigate the successful login for signs of compromise (Correct answer)
- Close the alert as below threshold
- Tune the rule threshold to 8
Correct answer: Investigate the successful login for signs of compromise
A successful login immediately following multiple failures strongly suggests a successful brute-force and warrants immediate investigation of that session.
Question 55: An analyst discovers that a critical vulnerability on a legacy PLC cannot be patched due to vendor support constraints. What is the MOST appropriate response?
- Decommission the system immediately
- Accept the risk and document it with no further action
- Implement network segmentation and enhanced monitoring as compensating controls (Correct answer)
- Run daily vulnerability scans against the device
Correct answer: Implement network segmentation and enhanced monitoring as compensating controls
When patching is not feasible, isolating the system via network segmentation and increasing monitoring reduces the attack surface and detection time.
Question 56: What does a 'false negative' mean in the context of vulnerability scanning?
- The scanner crashes during the scan
- The scanner reports a vulnerability that does not actually exist
- The scanner fails to detect a vulnerability that is actually present (Correct answer)
- The scanner reports a vulnerability with the wrong CVSS score
Correct answer: The scanner fails to detect a vulnerability that is actually present
A false negative is a missed detection — the real vulnerability exists on the target but the scanner does not flag it, often due to scan limitations or evasion.
Question 57: An analyst receives an alert that a vulnerable version of Apache Struts is running on a production server. The CVE has a known weaponized exploit. What is the MOST urgent first step?
- File a remediation ticket for the next patch cycle
- Notify users of potential downtime
- Increase logging verbosity on the server
- Immediately isolate the server and apply emergency patch procedures while monitoring for exploitation (Correct answer)
Correct answer: Immediately isolate the server and apply emergency patch procedures while monitoring for exploitation
A known weaponized exploit on a production system with network exposure demands immediate containment and emergency patching to prevent active exploitation.
Question 58: During post-incident analysis, the team discovers the attacker maintained persistence for 90 days before detection. Which term describes this period?
- Mean time to respond
- Dwell time (Correct answer)
- Recovery time
- Detection lag
Correct answer: Dwell time
Dwell time refers to the duration an attacker remains undetected within a compromised environment after initial intrusion.
Question 59: An analyst notices that the vulnerability scanner is flagging a particular finding on a host every week despite a patch being applied a month ago. What should the analyst suspect?
- The CVE score has been revised upward
- The scanner's plugin is outdated
- The patch was not successfully applied or was rolled back (Correct answer)
- The scanner is configured to report informational items
Correct answer: The patch was not successfully applied or was rolled back
Persistent findings after patching most commonly indicate the patch did not apply correctly, was reverted, or the scan is targeting a different instance of the software.
Question 60: What is the PRIMARY purpose of conducting a risk assessment before implementing new security controls?
- To document all known vulnerabilities in the environment
- To fulfill regulatory compliance requirements
- To prioritize controls based on the greatest risk reduction per dollar spent (Correct answer)
- To satisfy auditor requests for evidence
Correct answer: To prioritize controls based on the greatest risk reduction per dollar spent
Risk assessments enable organizations to allocate limited security resources to controls that provide the greatest reduction in overall risk relative to their cost.
Question 61: Which framework specifically maps adversary behaviors to pre-ATT&CK stages, covering actions from reconnaissance through actions on objectives, and was developed by Lockheed Martin?
- MITRE ATT&CK
- NIST CSF
- Diamond Model
- Cyber Kill Chain (Correct answer)
Correct answer: Cyber Kill Chain
The Cyber Kill Chain, developed by Lockheed Martin, defines seven stages of an attack from reconnaissance to actions on objectives.
Question 62: An analyst is reviewing a memory dump and finds injected shellcode in a legitimate svchost.exe process. Which attack technique does this represent?
- DLL side-loading
- Process hollowing or process injection (Correct answer)
- Firmware implant
- Rootkit installation
Correct answer: Process hollowing or process injection
Injecting shellcode into a legitimate process like svchost.exe is a process injection technique used to evade detection.
Question 63: In the context of CIS Controls v8, what distinguishes Implementation Group 1 (IG1) from IG2 and IG3?
- IG1 is optional while IG2 and IG3 are mandatory
- IG1 represents essential cyber hygiene for all organizations, especially smaller ones (Correct answer)
- IG1 includes all 18 controls while IG2 and IG3 add supplemental guidance
- IG1 applies only to government organizations
Correct answer: IG1 represents essential cyber hygiene for all organizations, especially smaller ones
IG1 is the minimum standard of cyber hygiene applicable to all organizations, particularly those with limited resources and cybersecurity expertise.
Question 64: Which metric in CVSSv3 indicates that an attacker must be on the same logical or physical network as the vulnerable system to exploit it?
- Attack Vector: Network
- Attack Vector: Adjacent (Correct answer)
- Attack Vector: Local
- Attack Vector: Physical
Correct answer: Attack Vector: Adjacent
The Adjacent (A) attack vector requires the attacker to be on the same network segment or broadcast domain as the target.
Question 65: Which IAM solution is specifically designed to manage, monitor, and control access to privileged accounts such as domain administrators and service accounts?
- Directory Services (LDAP)
- Privileged Access Management (PAM) (Correct answer)
- Identity Federation Service
- Identity Governance and Administration (IGA)
Correct answer: Privileged Access Management (PAM)
PAM solutions provide vaulting, session recording, just-in-time access, and fine-grained controls over privileged accounts, which are the highest-value targets for attackers.
Question 66: Which SIEM correlation rule would BEST detect lateral movement after an initial compromise?
- New user account creation outside business hours
- Multiple failed logins from one source
- High volume outbound traffic to a single IP
- Successful login from a new host to multiple internal systems in a short timeframe (Correct answer)
Correct answer: Successful login from a new host to multiple internal systems in a short timeframe
Lateral movement involves an attacker using a foothold to authenticate across multiple internal systems, making cross-host successful logins the strongest indicator.
Question 67: When building a vulnerability management dashboard for executive reporting, which KPI MOST directly demonstrates program effectiveness over time?
- Total number of scans performed per month
- Percentage of assets running antivirus software
- Number of unique CVEs in the NVD added this quarter
- Trend in mean time to remediate (MTTR) critical and high vulnerabilities (Correct answer)
Correct answer: Trend in mean time to remediate (MTTR) critical and high vulnerabilities
MTTR trend directly measures how quickly the organization closes critical risks, making it the most relevant indicator of vulnerability management program effectiveness for executives.
Question 68: Which vulnerability remediation strategy involves deploying a temporary measure to reduce risk while a permanent patch is being developed or tested?
- Risk acceptance
- Compensating control (Correct answer)
- Patch management
- Vulnerability suppression
Correct answer: Compensating control
A compensating control (e.g., WAF rule, network ACL) reduces exploitability temporarily until a proper fix is available.
Question 69: Which SIEM use case BEST helps detect beaconing behavior from malware C2 communications?
- Correlate periodic outbound connections to the same external IP at regular intervals (Correct answer)
- Alert on high-volume data transfers over HTTP
- Alert when DNS TTL exceeds 3600 seconds
- Block all outbound traffic on non-standard ports
Correct answer: Correlate periodic outbound connections to the same external IP at regular intervals
Malware beaconing is characterized by regular, periodic outbound connections to a C2 server, which correlation rules can identify by timing patterns.
Question 70: A SOC analyst identifies a process injecting code into a legitimate Windows process (e.g., svchost.exe). Which MITRE ATT&CK technique does this represent?
- Process injection (Correct answer)
- DLL side-loading
- Credential dumping
- Scheduled task abuse
Correct answer: Process injection
Process injection is a MITRE ATT&CK technique where adversaries inject malicious code into legitimate running processes to evade detection.
Question 71: An analyst uses the Delphi technique during a risk assessment. What is the PRIMARY characteristic of this method?
- Anonymous iterative expert consensus building (Correct answer)
- Financial modeling using asset replacement costs
- Statistical sampling of user behavior
- Automated vulnerability scanning across all network segments
Correct answer: Anonymous iterative expert consensus building
The Delphi technique gathers anonymous input from multiple experts across multiple rounds until consensus is reached, reducing groupthink bias.
Question 72: A vulnerability scanner returns a finding with a CVSS base score of 9.8. Before prioritizing remediation, which contextual factor should a security analyst evaluate FIRST?
- Whether the CVE was published in the last 30 days
- Whether the affected asset is internet-facing and stores sensitive data (Correct answer)
- Whether the vendor has released a patch
- Whether the finding has a public proof-of-concept exploit
Correct answer: Whether the affected asset is internet-facing and stores sensitive data
Asset criticality and exposure context determine true business risk; a high CVSS score on an isolated, non-critical system may rank lower than a moderate score on an internet-facing critical asset.
Question 73: Which type of malware analysis involves running a suspicious file in an isolated environment to observe its behavior without risking production systems?
- Static analysis
- Signature scanning
- Reverse engineering
- Dynamic analysis (Correct answer)
Correct answer: Dynamic analysis
Dynamic analysis executes malware in a sandboxed environment to observe real-time behaviors such as network connections, file creation, and registry changes.
Question 74: A forensic analyst extracts strings from a malware sample and finds Base64-encoded content that, when decoded, reveals a PowerShell script. This technique is BEST described as:
- Fileless malware persistence
- Process injection
- Privilege escalation via LOLBins
- Obfuscation to evade signature-based detection (Correct answer)
Correct answer: Obfuscation to evade signature-based detection
Encoding payloads in Base64 is a common obfuscation technique used to evade static signature detection by antivirus and IDS tools.
Question 75: During an incident investigation, an analyst finds evidence that data was exfiltrated via DNS queries. Which technique was likely used?
- DNS zone transfer abuse
- DNS tunneling (Correct answer)
- DNS amplification attack
- DNS cache poisoning
Correct answer: DNS tunneling
DNS tunneling encodes data within DNS query and response packets to covertly exfiltrate information through DNS protocol.
Question 76: When a CySA+ analyst uses the Diamond Model to analyze an attack, which domain is primarily being applied?
- Incident Response
- Threat and Vulnerability Management
- Threat Intelligence (Correct answer)
- Security Operations
Correct answer: Threat Intelligence
The Diamond Model is a threat intelligence framework used to analyze adversary operations and attribution.
Question 77: A risk analyst identifies that purchasing cyber liability insurance best addresses which risk treatment approach?
- Risk transference (Correct answer)
- Risk avoidance
- Risk mitigation
- Risk acceptance
Correct answer: Risk transference
Cyber liability insurance transfers the financial consequences of a risk event to the insurance provider.
Question 78: In a risk assessment, the Exposure Factor (EF) is defined as:
- The percentage of an asset's value lost in a single threat event (Correct answer)
- The number of vulnerabilities per asset
- The total cost of recovering from an incident
- The annualized frequency of a threat occurring
Correct answer: The percentage of an asset's value lost in a single threat event
Exposure Factor is the percentage of an asset's value that would be lost if a specific threat successfully exploits a vulnerability.
Question 79: During a vulnerability assessment, the analyst finds an open service on port 8080 returning a banner that identifies an outdated web server version. What is the analyst's next BEST action?
- Immediately shut down the service
- Correlate the version with known CVEs and assess exploitability in context (Correct answer)
- Report it as critical without further investigation
- Rescan the port to confirm the banner is accurate
Correct answer: Correlate the version with known CVEs and assess exploitability in context
Banner information identifies software version; the analyst should look up CVEs for that version and evaluate whether the vulnerability is exploitable given the environment.
Question 80: During vulnerability triage, an analyst identifies a vulnerability marked as 'informational' by the scanner. How should this be handled?
- Informational findings are always false positives
- Informational findings reveal configuration or enumeration data that may aid attackers and should be reviewed for risk in context (Correct answer)
- Informational findings can always be closed without review
- Informational findings should be patched immediately as they indicate critical flaws
Correct answer: Informational findings reveal configuration or enumeration data that may aid attackers and should be reviewed for risk in context
Informational findings do not indicate a directly exploitable flaw but can expose system details useful for reconnaissance; analysts should assess whether they increase overall risk.
Question 81: A healthcare organization uses a third-party billing company that accesses PHI. What agreement must be in place under HIPAA?
- Business Associate Agreement (BAA) (Correct answer)
- Non-Disclosure Agreement (NDA)
- Data Processing Agreement (DPA)
- Service Level Agreement (SLA)
Correct answer: Business Associate Agreement (BAA)
HIPAA requires a Business Associate Agreement with any third party that creates, receives, maintains, or transmits PHI on behalf of a covered entity.
Question 82: What is phishing?
- A type of firewall
- A network scanning tool
- A backup system
- A social engineering attack using fraudulent communications to steal sensitive data (Correct answer)
Correct answer: A social engineering attack using fraudulent communications to steal sensitive data
Phishing uses deceptive emails, websites, or messages that appear legitimate to trick victims into revealing passwords, credit cards, or personal information.
Question 83: During an investigation, an analyst needs to recover deleted files from an ext4 Linux filesystem. Which tool is MOST appropriate for carving files based on known file signatures?
- Foremost or Scalpel (Correct answer)
- strings
- dd
- Autopsy/Sleuth Kit
Correct answer: Foremost or Scalpel
Foremost and Scalpel are file carving tools that scan raw disk images for file header/footer signatures to recover deleted files regardless of filesystem metadata.
Question 84: Which hashing algorithm is MOST appropriate for generating forensic integrity checksums of evidence files today, given known weaknesses in older algorithms?
- SHA-1
- SHA-256 (Correct answer)
- MD5
- CRC32
Correct answer: SHA-256
SHA-256 is the recommended standard for forensic hashing as MD5 and SHA-1 have known collision vulnerabilities that could undermine evidence integrity.
Question 85: Which CVSS v3 metric describes the conditions beyond the attacker's control that must exist for a vulnerability to be exploited, such as a race condition or a specific system state?
- User Interaction
- Scope
- Attack Complexity (Correct answer)
- Privileges Required
Correct answer: Attack Complexity
Attack Complexity (AC) captures prerequisite conditions outside attacker control — High AC means the attacker must meet additional circumstances like timing or configuration.
CompTIA CySA+ (CS0-003)
The CompTIA Cybersecurity Analyst+ (CySA+) certification validates skills in applying behavioral analytics to networks and devices to prevent, detect, and combat cybersecurity threats through continuous security monitoring. It covers security operations, vulnerability management, incident response, and compliance reporting.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds