โ† All CySA+ Test Flashcard Decks

Security Operations Flashcards

7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security Operations flashcards as text
  1. A CySA+ analyst reviews a Windows Security event log and sees Event ID 4688 repeatedly for cmd.exe spawned by a Word process. What does this most likely indicate?

    Answer: A macro-based malware execution chain

    cmd.exe spawned by Office processes is a common indicator of malicious macro execution, a known technique used in document-based phishing attacks.

  2. Which framework provides a structured taxonomy of adversary tactics and techniques used primarily for threat detection and hunt operations?

    Answer: MITRE ATT&CK

    MITRE ATT&CK catalogs real-world adversary TTPs organized by tactic phases, making it the standard reference for detection engineering and threat hunting.

  3. An organization's WAF is generating thousands of alerts daily. The security team cannot investigate each one. What is the BEST approach to reduce noise while maintaining coverage?

    Answer: Tune WAF rules by analyzing false positives and adjusting thresholds

    Tuning detection rules based on false positive analysis reduces alert fatigue without sacrificing detection coverage for real threats.

  4. During a forensic investigation, an analyst discovers that log files covering a critical time window have been deleted. What should be checked to recover evidence?

    Answer: A centralized SIEM or remote syslog server

    Centralized SIEM and remote syslog servers store copies of logs off-system, making them recoverable even after local log tampering or deletion.

  5. Which indicator type is considered MOST actionable for immediate blocking because it has the shortest useful lifespan in threat intelligence?

    Answer: IP addresses

    IP addresses are immediately blockable but change frequently as attackers rotate infrastructure, making them short-lived but operationally useful.

  6. A company wants to test whether its monitoring tools can detect a real-world attack simulation without risking production systems. What exercise should they conduct?

    Answer: Purple team exercise

    A purple team exercise combines red team attack simulation with blue team detection monitoring, measuring actual detection and response capabilities collaboratively.

  7. An analyst receives a threat intelligence report listing IOCs from an attack campaign. What should be done FIRST before ingesting IOCs into the SIEM?

    Answer: Validate the IOCs for accuracy and relevance to your environment

    Validating IOC relevance and accuracy prevents false positives, ensures the intelligence applies to your technology stack, and avoids blocking legitimate traffic.