โ† All CySA+ Test Flashcard Decks

CySA+ Difficulty Level Flashcards

7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 CySA+ Difficulty Level flashcards as text
  1. Which phase of the incident response lifecycle focuses on identifying lessons learned and updating playbooks?

    Answer: Post-Incident Activity

    Post-Incident Activity (also called Post-Incident Review) is the phase where lessons learned are documented and controls are updated.

  2. An analyst notices outbound traffic to a domain registered 24 hours ago with a high entropy subdomain. Which threat technique does this MOST suggest?

    Answer: Domain Generation Algorithm (DGA)

    Newly registered domains with high-entropy subdomains are a hallmark of Domain Generation Algorithms used by malware to locate C2 infrastructure.

  3. A CySA+ candidate struggles most with performance-based questions. What study approach is MOST effective?

    Answer: Practicing with hands-on labs and scenario simulations

    Performance-based questions require applied skills; hands-on lab practice and scenario simulations directly build the competencies tested.

  4. Which tool would an analyst use to passively map the network topology without generating traffic?

    Answer: Wireshark packet capture analysis

    Analyzing existing Wireshark captures allows topology mapping without generating new probe traffic.

  5. A newly discovered vulnerability has a CVSS base score of 9.8 but no public exploit exists yet. How should a CySA+ analyst BEST prioritize remediation?

    Answer: Prioritize based on asset criticality and exploit likelihood

    Risk-based prioritization weighs CVSS score alongside asset criticality and the likelihood of exploitation, not just severity alone.

  6. Which network artifact would BEST help confirm data exfiltration over DNS?

    Answer: Unusually large DNS TXT or NULL record responses

    DNS tunneling encodes data in record types like TXT or NULL; abnormally large responses are a primary indicator.

  7. What distinguishes threat hunting from traditional reactive incident response?

    Answer: Threat hunting proactively searches for hidden threats before alerts fire

    Threat hunting is a proactive, hypothesis-driven search for threats that have evaded existing detection controls.