Performance-Based Questions (PBQs)
Interactive questions requiring practical application of skills in a simulated environment.
Getting Started: How the CySA+ Exam Works
Free knowledge base
Everything from the course in one searchable place: 236 entries. Use it to review before a practice test or look up a word you forgot.
236 results
Interactive questions requiring practical application of skills in a simulated environment.
Getting Started: How the CySA+ Exam Works
Standard questions with a list of options, where one or more may be correct.
Getting Started: How the CySA+ Exam Works
A raw score converted to a standardized scale (e.g., 100-900) to ensure fairness across exam versions.
Getting Started: How the CySA+ Exam Works
A major content area or topic covered by the certification exam.
Getting Started: How the CySA+ Exam Works
A cybersecurity professional focused on defending an organization's assets against threats.
Getting Started: How the CySA+ Exam Works
The process of identifying, assessing, and remediating security weaknesses.
Getting Started: How the CySA+ Exam Works
The organized approach to addressing and managing a security breach or cyberattack.
Getting Started: How the CySA+ Exam Works
To remember the top three domains by weight: 'S.V.I.' - Security Operations, Vulnerability Management, Incident Response. Think of a 'Security V.I.P.'
Getting Started: How the CySA+ Exam Works
The CySA+ CS0-003 exam has a maximum of 85 questions and a time limit of 165 minutes. The passing score is 750 on a scale of 100-900. Memorize these specific numbers.
Getting Started: How the CySA+ Exam Works
Underestimating the importance of Performance-Based Questions (PBQs) and not practicing hands-on scenarios.
Getting Started: How the CySA+ Exam Works
Focusing too much on low-weighted domains while neglecting the higher-weighted core areas.
Getting Started: How the CySA+ Exam Works
Not managing time effectively during the exam, especially on PBQs which can take longer.
Getting Started: How the CySA+ Exam Works
A simulated environment for practicing cybersecurity tasks.
Getting Started: How the CySA+ Exam Works
Security Information and Event Management; centralizes logs.
Getting Started: How the CySA+ Exam Works
Information about current and potential threats and adversaries.
Getting Started: How the CySA+ Exam Works
An alert indicating a threat where none exists.
Getting Started: How the CySA+ Exam Works
Defensive security professionals protecting an organization's assets.
Getting Started: How the CySA+ Exam Works
A popular network protocol analyzer for traffic inspection.
Getting Started: How the CySA+ Exam Works
Ongoing acquisition of knowledge and skills throughout a career.
Getting Started: How the CySA+ Exam Works
To remember the study strategy: 'L.A.P.S.' - Labs, Analysis (of practice tests), Practice (more tests), Stay current (continuous learning).
Getting Started: How the CySA+ Exam Works
The CySA+ exam objectives frequently use action verbs like 'analyze,' 'implement,' and 'troubleshoot.' These indicate that you'll need to do more than just recall facts; you'll need to apply your knowledge, often in a simulated environment. Pay close attention to labs and practice questions that test these application skills.
Getting Started: How the CySA+ Exam Works
Only memorizing facts without understanding the underlying concepts or how to apply them.
Getting Started: How the CySA+ Exam Works
Skipping hands-on labs, which are crucial for performance-based questions.
Getting Started: How the CySA+ Exam Works
Taking practice tests without reviewing incorrect answers and understanding the 'why' behind them.
Getting Started: How the CySA+ Exam Works
Arrangement of network devices.
Security Operations: Monitoring, Logs, and Threat Hunting
Connects different networks, forwards IP packets.
Security Operations: Monitoring, Logs, and Threat Hunting
Connects devices within a LAN, forwards MAC frames.
Security Operations: Monitoring, Logs, and Threat Hunting
Enforces network security policies.
Security Operations: Monitoring, Logs, and Threat Hunting
IT infrastructure located within the organization.
Security Operations: Monitoring, Logs, and Threat Hunting
IT resources hosted by a third-party provider.
Security Operations: Monitoring, Logs, and Threat Hunting
Divides security tasks between cloud provider and customer.
Security Operations: Monitoring, Logs, and Threat Hunting
Combines on-premises and cloud resources.
Security Operations: Monitoring, Logs, and Threat Hunting
To remember network devices: 'R-S-F-I' - Routers Separate, Switches Connect, Firewalls Filter, IDS/IPS Inspect.
Security Operations: Monitoring, Logs, and Threat Hunting
The exam often tests your ability to identify the function of a specific network device or architectural component. Pay close attention to what each device (router, switch, firewall, IDS/IPS) *does* and where it typically sits in a network diagram. Also, know the core differences in responsibility for on-premises vs. cloud security.
Security Operations: Monitoring, Logs, and Threat Hunting
Confusing the function of a router (inter-network) with a switch (intra-network).
Security Operations: Monitoring, Logs, and Threat Hunting
Underestimating the organization's security responsibility in cloud deployments (shared responsibility model).
Security Operations: Monitoring, Logs, and Threat Hunting
Not understanding that logs from different devices provide unique security insights.
Security Operations: Monitoring, Logs, and Threat Hunting
A record of events occurring within a system or network.
Security Operations: Monitoring, Logs, and Threat Hunting
Collecting logs from various sources into one central location.
Security Operations: Monitoring, Logs, and Threat Hunting
Converting diverse log formats into a standardized, common format.
Security Operations: Monitoring, Logs, and Threat Hunting
Linking related events across different logs to identify patterns.
Security Operations: Monitoring, Logs, and Threat Hunting
A unique identifier for a specific type of event in a log.
Security Operations: Monitoring, Logs, and Threat Hunting
A standard protocol for sending system log messages.
Security Operations: Monitoring, Logs, and Threat Hunting
To remember SIEM functions: 'CAN-DO' - Collect, Aggregate, Normalize, Detect, Orchestrate (or Output).
Security Operations: Monitoring, Logs, and Threat Hunting
The exam often tests your understanding of what a SIEM does (collection, aggregation, normalization, correlation, alerting) and common log sources (Windows Event Logs, firewall logs, web server logs). Be prepared to identify the purpose of specific log entries or event IDs (e.g., 4625 for failed logon).
Security Operations: Monitoring, Logs, and Threat Hunting
Ignoring logs or failing to collect them centrally, making incident response slow and difficult.
Security Operations: Monitoring, Logs, and Threat Hunting
Not normalizing logs, which hinders correlation and makes analysis inefficient.
Security Operations: Monitoring, Logs, and Threat Hunting
Over-relying on default SIEM rules without tuning them for the specific environment, leading to alert fatigue or missed threats.
Security Operations: Monitoring, Logs, and Threat Hunting
Forensic data that suggests a system or network has been breached.
Security Operations: Monitoring, Logs, and Threat Hunting
Establishing a normal pattern of behavior to detect deviations.
Security Operations: Monitoring, Logs, and Threat Hunting
Identifying deviations from established baselines or normal behavior.
Security Operations: Monitoring, Logs, and Threat Hunting
Server used by attackers to remotely control compromised systems.
Security Operations: Monitoring, Logs, and Threat Hunting
Unauthorized transfer of data from a computer or network.
Security Operations: Monitoring, Logs, and Threat Hunting
Gaining unauthorized higher-level access or permissions.
Security Operations: Monitoring, Logs, and Threat Hunting
Reviewing records of events for security incidents or anomalies.
Security Operations: Monitoring, Logs, and Threat Hunting
To remember IOCs, think 'I Observe Compromise': I for IP addresses, O for Outbound connections, C for C2 traffic, O for Odd processes, M for Malicious files, P for Privilege changes, R for Rogue accounts, O for Odd logins, M for Malicious domains, I for Infiltration attempts, S for Suspicious emails, E for Exfiltration.
Security Operations: Monitoring, Logs, and Threat Hunting
For the CySA+ exam, memorize common event IDs for critical security events in Windows (e.g., 4624 for successful logon, 4625 for failed logon, 4688 for process creation, 4728 for group membership changes) and their Linux equivalents. Understand that baselining is crucial for distinguishing normal from anomalous behavior.
Security Operations: Monitoring, Logs, and Threat Hunting
Ignoring minor anomalies: Small, seemingly insignificant deviations can be early indicators of a larger attack.
Security Operations: Monitoring, Logs, and Threat Hunting
Lack of baselining: Without knowing what's normal, everything looks suspicious, leading to alert fatigue.
Security Operations: Monitoring, Logs, and Threat Hunting
Focusing only on known IOCs: Attackers constantly evolve, so look for behavioral anomalies, not just signatures.
Security Operations: Monitoring, Logs, and Threat Hunting
Evidence-based knowledge about existing or emerging cyber threats.
Security Operations: Monitoring, Logs, and Threat Hunting
Patterns of behavior and methods used by threat actors.
Security Operations: Monitoring, Logs, and Threat Hunting
Proactive and iterative search for threats not detected by security tools.
Security Operations: Monitoring, Logs, and Threat Hunting
Open-Source Intelligence; publicly available information used for TI.
Security Operations: Monitoring, Logs, and Threat Hunting
Information Sharing and Analysis Center/Organization for threat data exchange.
Security Operations: Monitoring, Logs, and Threat Hunting
Hunting method based on forming and testing assumptions about threats.
Security Operations: Monitoring, Logs, and Threat Hunting
Globally accessible knowledge base of adversary tactics and techniques.
Security Operations: Monitoring, Logs, and Threat Hunting
To remember the key characteristics of good TI, think of CAR: Contextual, Actionable, Relevant.
Security Operations: Monitoring, Logs, and Threat Hunting
The CySA+ exam expects you to differentiate between strategic, operational, and tactical threat intelligence. Strategic TI informs high-level decisions, operational TI focuses on adversary TTPs, and tactical TI provides specific IOCs for immediate action.
Security Operations: Monitoring, Logs, and Threat Hunting
Treating all threat intelligence as equally relevant; always prioritize based on your organization's specific risk profile.
Security Operations: Monitoring, Logs, and Threat Hunting
Hunting without a clear hypothesis or goal, leading to aimless searching and wasted resources.
Security Operations: Monitoring, Logs, and Threat Hunting
Failing to feed hunting discoveries back into security controls and threat intelligence platforms, missing opportunities for improvement.
Security Operations: Monitoring, Logs, and Threat Hunting
Inspecting network traffic data to understand communication.
Security Operations: Monitoring, Logs, and Threat Hunting
Rules in Wireshark to show only specific packets.
Security Operations: Monitoring, Logs, and Threat Hunting
An isolated environment for safely executing suspicious code.
Security Operations: Monitoring, Logs, and Threat Hunting
Security Orchestration, Automation, and Response platform.
Security Operations: Monitoring, Logs, and Threat Hunting
A predefined, automated sequence of actions for incident response.
Security Operations: Monitoring, Logs, and Threat Hunting
Evidence on a network or system indicating intrusion.
Security Operations: Monitoring, Logs, and Threat Hunting
Imagine a 'SOARing' eagle, orchestrating all the little 'PACKETS' of information below, then putting them in a 'SANDBOX' to play safely.
Security Operations: Monitoring, Logs, and Threat Hunting
The exam often tests your ability to identify common Wireshark filters and their purpose. Memorize basic filter syntax for IP addresses, ports, and protocols. Also, understand the core function of sandboxing (safe execution) and SOAR (automation/orchestration).
Security Operations: Monitoring, Logs, and Threat Hunting
Not using specific enough Wireshark filters, leading to overwhelming amounts of data.
Security Operations: Monitoring, Logs, and Threat Hunting
Executing suspicious files directly on your analysis machine instead of in a sandbox.
Security Operations: Monitoring, Logs, and Threat Hunting
Believing SOAR replaces human analysts entirely; it's a force multiplier, not a replacement.
Security Operations: Monitoring, Logs, and Threat Hunting
Process of identifying all hardware, software, and data within a network.
Vulnerability Management: Discovery to Remediation
A comprehensive, documented list of all IT assets in an organization.
Vulnerability Management: Discovery to Remediation
Configuration Management Database; stores information about IT assets and their relationships.
Vulnerability Management: Discovery to Remediation
Hardware or software used within an organization without official approval or knowledge.
Vulnerability Management: Discovery to Remediation
Identifying assets by sending probes or requests to devices on the network.
Vulnerability Management: Discovery to Remediation
Identifying assets by monitoring network traffic and existing logs without direct interaction.
Vulnerability Management: Discovery to Remediation
Network Mapper; a free and open-source utility for network discovery and security auditing.
Vulnerability Management: Discovery to Remediation
To remember Active vs. Passive: 'Active' means you 'Act' on the network (send probes). 'Passive' means you 'Passively' listen (monitor traffic).
Vulnerability Management: Discovery to Remediation
The CySA+ exam expects you to differentiate between active and passive discovery methods. Look for keywords like 'scanning,' 'probes,' or 'agents' for active, and 'monitoring traffic,' 'logs,' or 'sniffing' for passive.
Vulnerability Management: Discovery to Remediation
Failing to include cloud assets or IoT devices in the asset inventory.
Vulnerability Management: Discovery to Remediation
Relying solely on manual processes for asset discovery, leading to outdated inventories.
Vulnerability Management: Discovery to Remediation
Not performing regular audits of the asset inventory against actual network devices.
Vulnerability Management: Discovery to Remediation
Automated process to identify security weaknesses in systems.
Vulnerability Management: Discovery to Remediation
Scan performed with authenticated access to the target system.
Vulnerability Management: Discovery to Remediation
Scan performed without authenticated access, mimicking an external attacker.
Vulnerability Management: Discovery to Remediation
Assesses vulnerabilities visible from the network, targeting devices and services.
Vulnerability Management: Discovery to Remediation
Runs directly on a target system to inspect local configurations and software.
Vulnerability Management: Discovery to Remediation
Specifically targets web applications for common vulnerabilities like XSS or SQLi.
Vulnerability Management: Discovery to Remediation
A set of rules and checks that a vulnerability scanner will perform.
Vulnerability Management: Discovery to Remediation
Think 'C' for Credentialed, 'C' for Comprehensive. If you have credentials, you get a much more comprehensive view inside the system.
Vulnerability Management: Discovery to Remediation
CompTIA CySA+ (CS0-003) candidates must distinguish between credentialed and non-credentialed scans, understanding their use cases and the depth of information each provides. Be prepared to identify the appropriate scan type for various scenarios, such as internal network assessments versus external perimeter testing.
Vulnerability Management: Discovery to Remediation
Relying solely on non-credentialed scans for internal systems, missing critical internal vulnerabilities.
Vulnerability Management: Discovery to Remediation
Not configuring scan policies correctly, leading to incomplete or irrelevant results.
Vulnerability Management: Discovery to Remediation
Ignoring false positives, causing unnecessary remediation efforts.
Vulnerability Management: Discovery to Remediation
Common Vulnerability Scoring System; open standard for vulnerability severity.
Vulnerability Management: Discovery to Remediation
Intrinsic characteristics of a vulnerability; constant over time.
Vulnerability Management: Discovery to Remediation
Adjusts Base Score based on time-dependent factors (e.g., exploit).
Vulnerability Management: Discovery to Remediation
Customizes score based on organizational context and asset criticality.
Vulnerability Management: Discovery to Remediation
How a vulnerability can be exploited (e.g., Network, Local).
Vulnerability Management: Discovery to Remediation
Impact on data secrecy if vulnerability is exploited.
Vulnerability Management: Discovery to Remediation
Impact on data trustworthiness if vulnerability is exploited.
Vulnerability Management: Discovery to Remediation
Impact on system access/uptime if vulnerability is exploited.
Vulnerability Management: Discovery to Remediation
BTE: Base, Temporal, Environmental. Remember 'Be The Expert' to recall the three CVSS metric groups.
Vulnerability Management: Discovery to Remediation
The CySA+ exam expects you to understand the three CVSS metric groups (Base, Temporal, Environmental) and their purpose. Be able to interpret what a high or low score implies for each metric, and how they collectively contribute to prioritization.
Vulnerability Management: Discovery to Remediation
Only relying on the Base Score for prioritization without considering Temporal and Environmental factors.
Vulnerability Management: Discovery to Remediation
Treating all vulnerabilities with the same CVSS score as equally critical, regardless of the affected asset.
Vulnerability Management: Discovery to Remediation
Not understanding that CVSS is a tool for assessment, not a complete risk management solution on its own.
Vulnerability Management: Discovery to Remediation
Seven-stage model outlining the typical phases of a cyberattack.
Vulnerability Management: Discovery to Remediation
Framework for intrusion analysis focusing on Adversary, Capability, Infrastructure, Victim.
Vulnerability Management: Discovery to Remediation
The 'why' of an adversary's action in MITRE ATT&CK (e.g., Execution, Persistence).
Vulnerability Management: Discovery to Remediation
The 'how' of an adversary's action in MITRE ATT&CK (e.g., PowerShell, Scheduled Task).
Vulnerability Management: Discovery to Remediation
To remember the Diamond Model's core features: 'A C I V' - 'A'll 'C'yber 'I'ntrusions 'V'ary.
Vulnerability Management: Discovery to Remediation
The exam often tests your ability to differentiate between the frameworks and apply them to specific scenarios. Pay close attention to the number of stages in the Cyber Kill Chain (seven) and the four core features of the Diamond Model.
Vulnerability Management: Discovery to Remediation
Confusing the stages of the Cyber Kill Chain or the components of the Diamond Model.
Vulnerability Management: Discovery to Remediation
Applying a framework that doesn't best fit the specific analysis need (e.g., using Kill Chain for granular technique detail).
Vulnerability Management: Discovery to Remediation
Not understanding that these frameworks are complementary and can be used together.
Vulnerability Management: Discovery to Remediation
Reducing the impact or likelihood of a vulnerability.
Vulnerability Management: Discovery to Remediation
Applying vendor-supplied updates to fix software flaws.
Vulnerability Management: Discovery to Remediation
An alternative security measure to reduce risk.
Vulnerability Management: Discovery to Remediation
Securing a system by reducing its attack surface.
Vulnerability Management: Discovery to Remediation
Integrating security into every phase of software development.
Vulnerability Management: Discovery to Remediation
Ensuring user-supplied data is safe and expected.
Vulnerability Management: Discovery to Remediation
Only allowing explicitly approved input.
Vulnerability Management: Discovery to Remediation
A secure way to execute SQL queries with user input.
Vulnerability Management: Discovery to Remediation
To remember SSDLC phases: **R**eally **D**esigned **D**evelopers **T**est **D**eploy **M**aintain.
Vulnerability Management: Discovery to Remediation
The exam often tests your knowledge of the SSDLC phases and the importance of secure coding practices, especially input validation. Be prepared to identify which phase a security activity belongs to (e.g., threat modeling in design) and common vulnerabilities prevented by input validation (e.g., SQLi, XSS).
Vulnerability Management: Discovery to Remediation
Relying solely on client-side input validation; it's easily bypassed.
Vulnerability Management: Discovery to Remediation
Delaying patching critical vulnerabilities, increasing exposure time.
Vulnerability Management: Discovery to Remediation
Treating security as an afterthought, rather than integrating it into development.
Vulnerability Management: Discovery to Remediation
A structured approach to managing security incidents.
Incident Response and Management Essentials
The initial phase of IR, establishing plans and resources.
Incident Response and Management Essentials
A documented guide for handling security incidents.
Incident Response and Management Essentials
A dedicated group responsible for executing the IRP.
Incident Response and Management Essentials
Computer Security Incident Response Team, another name for IRT.
Incident Response and Management Essentials
A discussion-based drill simulating an incident.
Incident Response and Management Essentials
P-I-C-E-R-L: **P**eople **I**n **C**ybersecurity **E**verywhere **R**eally **L**ike security! (Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned)
Incident Response and Management Essentials
The CySA+ exam heavily emphasizes the NIST Incident Response Lifecycle (SP 800-61). Memorize the six phases and understand the key activities within each, especially 'preparation' as it sets the stage for everything else.
Incident Response and Management Essentials
Skipping the preparation phase, leading to chaotic and ineffective responses.
Incident Response and Management Essentials
Failing to regularly update and test the Incident Response Plan (IRP).
Incident Response and Management Essentials
Not providing adequate training or resources for the Incident Response Team (IRT).
Incident Response and Management Essentials
Isolating compromised systems to prevent further incident spread.
Incident Response and Management Essentials
Removing the root cause and all traces of an incident.
Incident Response and Management Essentials
Restoring systems and data to normal, secure operation.
Incident Response and Management Essentials
Dividing a network into smaller, isolated segments.
Incident Response and Management Essentials
Disconnecting or quarantining a single compromised system.
Incident Response and Management Essentials
Implementing security improvements after an incident.
Incident Response and Management Essentials
Remember the C-E-R order: 'Cats Eat Rodents' (Contain, Eradicate, Recover).
Incident Response and Management Essentials
The CySA+ exam expects you to know the specific steps of containment, eradication, and recovery and understand the rationale behind each. Look for keywords like 'isolate,' 'remove,' 'restore,' and 'verify' to identify the correct phase.
Incident Response and Management Essentials
Skipping containment in an effort to immediately eradicate, leading to wider infection.
Incident Response and Management Essentials
Failing to identify and remove the root cause during eradication, resulting in re-infection.
Incident Response and Management Essentials
Restoring systems from compromised backups, reintroducing the threat.
Incident Response and Management Essentials
Documented history of evidence handling from collection to disposition.
Incident Response and Management Essentials
Information lost when a system is powered off (e.g., RAM contents).
Incident Response and Management Essentials
Information that remains after power-off (e.g., hard drive contents).
Incident Response and Management Essentials
Methods that preserve the integrity and authenticity of evidence.
Incident Response and Management Essentials
Hardware or software that prevents data modification on storage devices.
Incident Response and Management Essentials
A unique digital fingerprint used to verify data integrity.
Incident Response and Management Essentials
Security bag designed to show if it has been opened or altered.
Incident Response and Management Essentials
Remember 'CVPD' for the order of collection: Cache, Volatile memory, Persistent storage, Disk images. Or 'Can Very Patient Detectives'!
Incident Response and Management Essentials
The CySA+ exam frequently tests the order of volatility for data collection. Memorize that RAM, cache, and network connections are highly volatile and should be collected before disk images or logs. Also, know that cryptographic hashes (MD5, SHA1) are used to verify evidence integrity.
Incident Response and Management Essentials
Failing to document every transfer of evidence, leading to a broken chain of custody.
Incident Response and Management Essentials
Collecting persistent data before volatile data, resulting in the loss of critical information.
Incident Response and Management Essentials
Not using write-blockers or creating hashes, which can lead to evidence being deemed unreliable.
Incident Response and Management Essentials
Meeting to analyze an incident, identify root causes, and learn from it.
Incident Response and Management Essentials
Actionable insights and recommendations derived from a PIR.
Incident Response and Management Essentials
Process of identifying the fundamental reason for an incident.
Incident Response and Management Essentials
Mean Time To Detect: average time to identify an incident.
Incident Response and Management Essentials
Mean Time To Recover: average time to restore normal operations.
Incident Response and Management Essentials
Mean Time To Contain: average time to stop an incident's spread.
Incident Response and Management Essentials
Ongoing effort to enhance processes, products, or services.
Incident Response and Management Essentials
PIRATES: Post-Incident Review Analyzes The Entire Situation, Resulting in Actionable Takeaways, Enhancing Security.
Incident Response and Management Essentials
The exam expects you to know the purpose of a Post-Incident Review and how lessons learned contribute to organizational security posture. Keywords to look for include 'root cause analysis,' 'continuous improvement,' and 'metrics' like MTTD/MTTR.
Incident Response and Management Essentials
Skipping the post-incident review due to 'busyness' or a desire to move on.
Incident Response and Management Essentials
Focusing on blaming individuals rather than identifying process or system failures.
Incident Response and Management Essentials
Failing to document lessons learned or implement recommended changes.
Incident Response and Management Essentials
Formal document detailing security weaknesses, their impact, and remediation.
Reporting and Communication for Blue Teams
High-level, non-technical overview for management, focusing on business impact.
Reporting and Communication for Blue Teams
Concise overview for technical leads, summarizing scope and key findings.
Reporting and Communication for Blue Teams
The process of fixing or mitigating identified security vulnerabilities.
Reporting and Communication for Blue Teams
Specific, clear steps provided to fix or mitigate a vulnerability.
Reporting and Communication for Blue Teams
Supporting data like log snippets or screenshots to validate vulnerability findings.
Reporting and Communication for Blue Teams
Remember 'REPORT': R-isk, E-vidence, P-urpose, O-utline, R-ecommendations, T-arget Audience.
Reporting and Communication for Blue Teams
The CySA+ exam (CS0-003) expects you to know the typical structure and content of a vulnerability report, including the distinction between executive and technical summaries, and the importance of actionable recommendations. Look for keywords like 'report structure,' 'stakeholder communication,' and 'remediation steps.'
Reporting and Communication for Blue Teams
Providing only technical details without an executive summary for management.
Reporting and Communication for Blue Teams
Offering vague recommendations instead of specific, actionable steps.
Reporting and Communication for Blue Teams
Failing to include sufficient evidence (e.g., log snippets, screenshots) to validate findings.
Reporting and Communication for Blue Teams
Quantifiable measure of success towards an objective.
Reporting and Communication for Blue Teams
Specific data point used to measure security performance.
Reporting and Communication for Blue Teams
Average time from incident start to detection.
Reporting and Communication for Blue Teams
Average time from detection to initial response actions.
Reporting and Communication for Blue Teams
Average time from detection to incident containment.
Reporting and Communication for Blue Teams
Average time from containment to full system restoration.
Reporting and Communication for Blue Teams
Real-time data for daily security activities.
Reporting and Communication for Blue Teams
High-level data for long-term security decisions.
Reporting and Communication for Blue Teams
To remember the 'Mean Time To' metrics in order: Detect, Respond, Contain, Recover. Think 'DR. CR' – Doctor, See, Are, You.
Reporting and Communication for Blue Teams
The CySA+ exam expects you to identify and understand common security metrics and KPIs used in incident response and vulnerability management. Keywords to spot include 'MTTD', 'MTTR', 'containment time', 'patching cadence', and 'false positive rate'. Memorize what each of the 'Mean Time To...' metrics represents.
Reporting and Communication for Blue Teams
Confusing KPIs with raw metrics; KPIs are derived from metrics.
Reporting and Communication for Blue Teams
Collecting too many metrics without a clear purpose, leading to 'data overload'.
Reporting and Communication for Blue Teams
Failing to contextualize metrics for different audiences (e.g., technical vs. executive).
Reporting and Communication for Blue Teams
Any individual or group with an interest in an incident.
Reporting and Communication for Blue Teams
Formal document detailing a security incident, its impact, and response.
Reporting and Communication for Blue Teams
Forensic data identifying malicious activity on a system or network.
Reporting and Communication for Blue Teams
Department managing an organization's public image and communication.
Reporting and Communication for Blue Teams
Government agency enforcing specific laws and regulations.
Reporting and Communication for Blue Teams
Predefined strategy for informing stakeholders during an incident.
Reporting and Communication for Blue Teams
The promptness of reporting during a security incident.
Reporting and Communication for Blue Teams
To remember key report sections: 'E.I.I.R.R.R.' - Executive Summary, Incident Details, Impact, Response, Recovery, Recommendations.
Reporting and Communication for Blue Teams
The CySA+ exam expects you to differentiate between communication needs for various audiences. Keywords like 'executive leadership,' 'technical staff,' 'legal counsel,' and 'public relations' signal questions about tailored communication. Remember that regulatory compliance often dictates reporting timelines.
Reporting and Communication for Blue Teams
Using overly technical jargon when communicating with non-technical stakeholders.
Reporting and Communication for Blue Teams
Delaying incident notification to avoid perceived negative consequences.
Reporting and Communication for Blue Teams
Failing to update stakeholders as an incident evolves, leading to outdated information.
Reporting and Communication for Blue Teams
Set of guidelines for security practices.
Reporting and Communication for Blue Teams
US law protecting health information privacy.
Reporting and Communication for Blue Teams
EU law for data protection and privacy.
Reporting and Communication for Blue Teams
Standard for credit card data security.
Reporting and Communication for Blue Teams
Framework for improving critical infrastructure cybersecurity.
Reporting and Communication for Blue Teams
Identified deficiency during a compliance audit.
Reporting and Communication for Blue Teams
Iterative management method for continuous improvement.
Reporting and Communication for Blue Teams
HIPAA protects Health, GDPR guards Global Data, PCI DSS secures Payments, NIST guides National Infrastructure. Remember the first letter of each to link it to its domain!
Reporting and Communication for Blue Teams
The exam often tests your knowledge of specific compliance frameworks (HIPAA, GDPR, PCI DSS, NIST CSF) and their primary purpose. Be ready to identify which framework applies to a given scenario (e.g., healthcare data, credit card processing).
Reporting and Communication for Blue Teams
Confusing the scope of different compliance frameworks (e.g., applying HIPAA rules to credit card data).
Reporting and Communication for Blue Teams
Failing to document security controls and actions, making it impossible to prove compliance during an audit.
Reporting and Communication for Blue Teams
Viewing compliance as a one-time event instead of an ongoing, continuous process.
Reporting and Communication for Blue Teams