โ† All CySA+ Test Flashcard Decks

CySA+ Performance Tracking and Feedback Flashcards

7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 CySA+ Performance Tracking and Feedback flashcards as text
  1. Which of the following best describes the purpose of a security scorecard presented to the board of directors?

    Answer: Translate technical security metrics into business-relevant risk language

    Security scorecards for executives translate technical findings into business risk terms that non-technical stakeholders can understand and act on.

  2. A team notices that alert volume spikes every Monday morning. What should the team investigate first?

    Answer: Correlate the spike with scheduled business processes like batch jobs or backups

    Recurring spikes often correlate with scheduled business events; correlating alert volume with known processes helps distinguish noise from true incidents.

  3. An analyst wants to determine whether a new threat-hunting playbook improved detection of lateral movement. Which comparison approach is most appropriate?

    Answer: Measure true-positive lateral movement detections before and after playbook deployment

    Measuring true-positive detections before and after deployment directly assesses whether the playbook improves detection accuracy for the targeted threat.

  4. A feedback loop in incident response ensures that lessons learned from one incident are used to improve future response. Which document formally captures this?

    Answer: Post-incident review (PIR) / after-action report (AAR)

    A Post-Incident Review or After-Action Report formally documents root causes, gaps, and recommended improvements to feed back into procedures.

  5. Which metric directly measures the efficiency of the vulnerability management process?

    Answer: Average days to remediate critical vulnerabilities

    Average days to remediate critical vulnerabilities measures how quickly the team resolves the highest-risk weaknesses, indicating process efficiency.

  6. An organization's false positive rate for its IDS is 40%. What is the primary business impact of this high rate?

    Answer: Analyst time wasted on non-threats, increasing MTTD for real incidents

    A high false positive rate consumes analyst time on non-threats, diverting resources and increasing the time needed to detect and respond to real incidents.

  7. Which feedback mechanism allows frontline SOC analysts to suggest improvements to detection rules based on daily experience?

    Answer: Continuous improvement process with analyst input channels

    A continuous improvement process with structured analyst input channels captures ground-level observations to refine detection rules and workflows iteratively.