CySA+ Knowledge Areas Covered Flashcards
7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 CySA+ Knowledge Areas Covered flashcards as text
Which CySA+ domain includes reviewing security policies and performing gap analyses against frameworks like NIST CSF?
Answer: Compliance and Assessment
Gap analyses and framework alignment reviews are core activities in the Compliance and Assessment domain.
An analyst correlates endpoint telemetry with network flow data to detect a slow-and-low exfiltration. Which tool category supports this?
Answer: SIEM
SIEMs aggregate and correlate telemetry from multiple sources to detect complex, multi-stage attacks like slow exfiltration.
Which CySA+ concept involves proactively searching for threats that have evaded existing security controls?
Answer: Threat Hunting
Threat hunting is the proactive search for threats that have bypassed automated detection controls.
A security team uses sandboxing to detonate a suspicious email attachment. Which domain covers this technique?
Answer: Threat Intelligence
Dynamic malware analysis using sandboxes is a Threat Intelligence technique for understanding malware behavior.
Which CySA+ domain addresses proper handling and chain of custody for digital evidence?
Answer: Incident Response
Evidence collection, preservation, and chain of custody are Incident Response responsibilities under CySA+.
An analyst is using Shodan to identify exposed services on the organization's public IP ranges. This supports which activity?
Answer: Attack Surface Management
Using external scanning tools like Shodan to find exposed assets is an Attack Surface Management activity.
Which CySA+ knowledge area includes reviewing software development pipelines for security misconfigurations?
Answer: Software and Systems Security
Securing CI/CD pipelines and development environments falls within the Software and Systems Security domain.