← All CySA+ Test Flashcard Decks

Mixed Deck — All CySA+ Test Topics Flashcards

100 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Mixed Deck — All CySA+ Test Topics flashcards as text
  1. During a purple team exercise, the blue team fails to detect a simulated lateral movement via PsExec. Which control gap does this MOST likely indicate?

    Answer: Missing detection logic for SMB-based admin tool execution

    PsExec operates over SMB using legitimate admin shares; the gap is missing behavioral detection for admin tool abuse, not AV signatures.

  2. A vulnerability management program reports that mean time to remediate (MTTR) critical vulnerabilities has increased from 7 days to 21 days over the past quarter. What is the MOST likely root cause to investigate first?

    Answer: The patch deployment process or change management workflow has a bottleneck

    An increasing MTTR typically signals a bottleneck in the patching or change management process — approvals, testing cycles, or resource constraints are slowing remediation.

  3. A security analyst wants to determine whether a suspicious file is malicious without executing it in production. What analysis method should be used FIRST?

    Answer: Static analysis of the file's hash, strings, and metadata

    Static analysis examines a file's properties without executing it, providing initial triage information quickly with no risk of detonating the payload.

  4. A candidate with network security experience but limited scripting exposure should focus exam preparation on which CySA+ skill area?

    Answer: Reading and interpreting scripts/code for malicious activity indicators

    CySA+ tests the ability to read and interpret code/scripts for indicators of malicious behavior, not to write production code.

  5. A threat hunter notices recurring outbound SMB (port 445) connections from a workstation to an internet IP. Why is this significant from a CySA+ perspective?

    Answer: SMB should never traverse the internet; this suggests a firewall misconfiguration or active attack

    SMB is an internal protocol that should never appear as outbound internet traffic; its presence indicates either a firewall gap, malware lateral movement preparation, or active exploitation.

  6. FISMA requires federal agencies to categorize information systems using which standard?

    Answer: FIPS 199

    FIPS 199 provides the standards for security categorization of federal information and information systems based on potential impact.

  7. A threat actor compromises a domain controller and forges a Kerberos ticket-granting ticket (TGT) with a custom lifetime of 10 years using the KRBTGT hash. What type of attack is this?

    Answer: Golden Ticket attack

    A Golden Ticket attack uses the compromised KRBTGT account hash to forge valid Kerberos TGTs, granting the attacker persistent, domain-wide access that persists even after password resets.

  8. What is a zero-day vulnerability?

    Answer: A security flaw unknown to the vendor with no available patch

    Zero-day vulnerabilities are newly discovered security flaws that the vendor doesn't know about yet, giving them 'zero days' to fix it before potential exploitation.

  9. Which domain represents the LARGEST percentage of the CySA+ CS0-003 exam content?

    Answer: Security Operations

    Security Operations accounts for 33% of the CySA+ CS0-003 exam, making it the largest single domain.

  10. A SOC detects outbound DNS requests with unusually long subdomains containing random-looking character strings. What attack technique does this suggest?

    Answer: DNS tunneling for data exfiltration

    Long encoded subdomains in DNS queries are characteristic of DNS tunneling, where data is exfiltrated by embedding it in DNS request subdomains.

  11. What is multi-factor authentication (MFA)?

    Answer: Requiring two or more verification methods to confirm identity

    MFA combines two or more authentication factors (something you know, have, or are) for stronger identity verification.

  12. Which NetFlow field is MOST useful for identifying lateral movement between internal hosts?

    Answer: Source and destination IP pairs with byte counts

    Internal source/destination IP pairs with associated byte counts reveal east-west traffic patterns indicative of lateral movement.

  13. An organization wants to allow employees to log in to multiple internal applications using a single set of credentials. Which technology best supports this requirement?

    Answer: Single Sign-On (SSO)

    SSO allows users to authenticate once and gain access to multiple applications without re-entering credentials, improving usability while centralizing authentication control.

  14. A feedback loop in incident response ensures that lessons learned from one incident are used to improve future response. Which document formally captures this?

    Answer: Post-incident review (PIR) / after-action report (AAR)

    A Post-Incident Review or After-Action Report formally documents root causes, gaps, and recommended improvements to feed back into procedures.

  15. A threat intelligence program tracks 'indicator sharing timeliness.' What does this metric measure?

    Answer: The time elapsed between receiving a threat indicator and sharing it with trusted partners

    Indicator sharing timeliness measures how quickly the organization disseminates actionable threat indicators to partners after receiving them, impacting collective defense.

  16. During threat hunting, an analyst uses the hypothesis: 'An adversary has established persistence using scheduled tasks.' Which ATT&CK technique should they investigate first?

    Answer: T1053 – Scheduled Task/Job

    T1053 (Scheduled Task/Job) directly maps to persistence via scheduled tasks and should be the starting point for this hypothesis.

  17. During network monitoring, an analyst identifies TCP sessions with the SYN flag set but no corresponding SYN-ACK responses from the destination. What does this pattern MOST likely indicate?

    Answer: SYN scan (half-open scan) reconnaissance

    A SYN scan sends SYN packets but never completes the handshake; unanswered SYNs are characteristic of port scanning with half-open connections.

  18. Which MITRE ATT&CK tactic describes an adversary's attempts to steal credentials to gain access to systems?

    Answer: Credential Access

    Credential Access is the ATT&CK tactic covering techniques like keylogging, credential dumping, and brute forcing to obtain account credentials.

  19. Which security design principle recommends using multiple overlapping security controls so that the failure of one does not compromise the entire system?

    Answer: Defense in depth

    Defense in depth layers multiple security controls so that if one layer fails, additional layers continue to protect assets.

  20. What is encryption?

    Answer: Converting data into coded format to prevent unauthorized access

    Encryption transforms readable data into unreadable ciphertext using algorithms and keys, ensuring only authorized parties can access the information.