โ† All CySA+ Test Flashcard Decks

Security Operations Flashcards

7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security Operations flashcards as text
  1. A security analyst is performing threat hunting and wants to find hosts that may have been compromised using fileless malware. Which data source is MOST valuable?

    Answer: PowerShell script block logging and process memory analysis

    Fileless malware operates in memory using scripting engines like PowerShell, making script block logs and memory analysis the primary sources for detection.

  2. Which SOAR capability directly reduces analyst workload by automatically executing predefined response actions when specific alert conditions are met?

    Answer: Playbook automation

    SOAR playbook automation triggers predefined response workflows automatically when alert criteria match, executing containment and enrichment without manual intervention.

  3. An analyst reviews HTTP logs and finds requests with unusually large cookie headers being sent to an internal server. What vulnerability might this indicate?

    Answer: Cookie-based buffer overflow or session fixation attack

    Abnormally large cookie values can indicate attempts to exploit buffer overflow vulnerabilities in cookie parsing or session fixation attacks manipulating session tokens.

  4. During incident triage, what is the PRIMARY purpose of calculating an IOC's confidence score?

    Answer: To prioritize investigation efforts based on reliability of the threat indicator

    Confidence scores indicate how reliable an IOC is based on its source quality and corroboration, helping analysts focus on high-confidence indicators first.

  5. A company's EDR platform flags a process executing with SYSTEM privileges that was launched by a user-level process. What attack technique does this suggest?

    Answer: Privilege escalation via local exploit or token impersonation

    A user-level process launching a SYSTEM-privileged child process indicates privilege escalation, either through vulnerability exploitation or Windows token manipulation techniques.

  6. Which approach BEST ensures that security alerts maintain relevance as the environment changes over time?

    Answer: Continuously reviewing and updating detection logic based on environmental changes and new TTPs

    Continuous detection engineering ensures rules reflect the current environment, emerging threats, and updated adversary TTPs rather than becoming stale or irrelevant.

  7. An analyst discovers that an attacker used valid administrative credentials to access systems without triggering any alerts. What security control gap does this reveal?

    Answer: Absence of user and entity behavior analytics (UEBA) to detect anomalous use of legitimate credentials

    UEBA establishes behavioral baselines for accounts and detects anomalies in how legitimate credentials are used, catching attackers who evade signature-based detection.