Free knowledge base

CompTIA CySA+ (CS0-003) — key terms, tricks & tips

Everything from the course in one searchable place: 236 entries. Use it to review before a practice test or look up a word you forgot.

236 results

Key term

Performance-Based Questions (PBQs)

Interactive questions requiring practical application of skills in a simulated environment.

Getting Started: How the CySA+ Exam Works

Key term

Multiple-Choice Questions (MCQs)

Standard questions with a list of options, where one or more may be correct.

Getting Started: How the CySA+ Exam Works

Key term

Scaled Score

A raw score converted to a standardized scale (e.g., 100-900) to ensure fairness across exam versions.

Getting Started: How the CySA+ Exam Works

Key term

Domain

A major content area or topic covered by the certification exam.

Getting Started: How the CySA+ Exam Works

Key term

Blue Team Analyst

A cybersecurity professional focused on defending an organization's assets against threats.

Getting Started: How the CySA+ Exam Works

Key term

Vulnerability Management

The process of identifying, assessing, and remediating security weaknesses.

Getting Started: How the CySA+ Exam Works

Key term

Incident Response

The organized approach to addressing and managing a security breach or cyberattack.

Getting Started: How the CySA+ Exam Works

Memory trick

Exam Overview: Format, Domains, and Scoring

To remember the top three domains by weight: 'S.V.I.' - Security Operations, Vulnerability Management, Incident Response. Think of a 'Security V.I.P.'

Getting Started: How the CySA+ Exam Works

Exam tip

Exam Overview: Format, Domains, and Scoring

The CySA+ CS0-003 exam has a maximum of 85 questions and a time limit of 165 minutes. The passing score is 750 on a scale of 100-900. Memorize these specific numbers.

Getting Started: How the CySA+ Exam Works

Common mistake

Exam Overview: Format, Domains, and Scoring

Underestimating the importance of Performance-Based Questions (PBQs) and not practicing hands-on scenarios.

Getting Started: How the CySA+ Exam Works

Common mistake

Exam Overview: Format, Domains, and Scoring

Focusing too much on low-weighted domains while neglecting the higher-weighted core areas.

Getting Started: How the CySA+ Exam Works

Common mistake

Exam Overview: Format, Domains, and Scoring

Not managing time effectively during the exam, especially on PBQs which can take longer.

Getting Started: How the CySA+ Exam Works

Key term

Virtual Lab

A simulated environment for practicing cybersecurity tasks.

Getting Started: How the CySA+ Exam Works

Key term

SIEM

Security Information and Event Management; centralizes logs.

Getting Started: How the CySA+ Exam Works

Key term

Threat Intelligence

Information about current and potential threats and adversaries.

Getting Started: How the CySA+ Exam Works

Key term

False Positive

An alert indicating a threat where none exists.

Getting Started: How the CySA+ Exam Works

Key term

Blue Team

Defensive security professionals protecting an organization's assets.

Getting Started: How the CySA+ Exam Works

Key term

Wireshark

A popular network protocol analyzer for traffic inspection.

Getting Started: How the CySA+ Exam Works

Key term

Continuous Learning

Ongoing acquisition of knowledge and skills throughout a career.

Getting Started: How the CySA+ Exam Works

Memory trick

Study Strategy: Tools, Labs, and Practice Tips

To remember the study strategy: 'L.A.P.S.' - Labs, Analysis (of practice tests), Practice (more tests), Stay current (continuous learning).

Getting Started: How the CySA+ Exam Works

Exam tip

Study Strategy: Tools, Labs, and Practice Tips

The CySA+ exam objectives frequently use action verbs like 'analyze,' 'implement,' and 'troubleshoot.' These indicate that you'll need to do more than just recall facts; you'll need to apply your knowledge, often in a simulated environment. Pay close attention to labs and practice questions that test these application skills.

Getting Started: How the CySA+ Exam Works

Common mistake

Study Strategy: Tools, Labs, and Practice Tips

Only memorizing facts without understanding the underlying concepts or how to apply them.

Getting Started: How the CySA+ Exam Works

Common mistake

Study Strategy: Tools, Labs, and Practice Tips

Skipping hands-on labs, which are crucial for performance-based questions.

Getting Started: How the CySA+ Exam Works

Common mistake

Study Strategy: Tools, Labs, and Practice Tips

Taking practice tests without reviewing incorrect answers and understanding the 'why' behind them.

Getting Started: How the CySA+ Exam Works

Key term

Network Topology

Arrangement of network devices.

Security Operations: Monitoring, Logs, and Threat Hunting

Key term

Router

Connects different networks, forwards IP packets.

Security Operations: Monitoring, Logs, and Threat Hunting

Key term

Switch

Connects devices within a LAN, forwards MAC frames.

Security Operations: Monitoring, Logs, and Threat Hunting

Key term

Firewall

Enforces network security policies.

Security Operations: Monitoring, Logs, and Threat Hunting

Key term

On-premises

IT infrastructure located within the organization.

Security Operations: Monitoring, Logs, and Threat Hunting

Key term

Cloud Deployment

IT resources hosted by a third-party provider.

Security Operations: Monitoring, Logs, and Threat Hunting

Key term

Shared Responsibility Model

Divides security tasks between cloud provider and customer.

Security Operations: Monitoring, Logs, and Threat Hunting

Key term

Hybrid Deployment

Combines on-premises and cloud resources.

Security Operations: Monitoring, Logs, and Threat Hunting

Memory trick

System and Network Architecture Fundamentals

To remember network devices: 'R-S-F-I' - Routers Separate, Switches Connect, Firewalls Filter, IDS/IPS Inspect.

Security Operations: Monitoring, Logs, and Threat Hunting

Exam tip

System and Network Architecture Fundamentals

The exam often tests your ability to identify the function of a specific network device or architectural component. Pay close attention to what each device (router, switch, firewall, IDS/IPS) *does* and where it typically sits in a network diagram. Also, know the core differences in responsibility for on-premises vs. cloud security.

Security Operations: Monitoring, Logs, and Threat Hunting

Common mistake

System and Network Architecture Fundamentals

Confusing the function of a router (inter-network) with a switch (intra-network).

Security Operations: Monitoring, Logs, and Threat Hunting

Common mistake

System and Network Architecture Fundamentals

Underestimating the organization's security responsibility in cloud deployments (shared responsibility model).

Security Operations: Monitoring, Logs, and Threat Hunting

Common mistake

System and Network Architecture Fundamentals

Not understanding that logs from different devices provide unique security insights.

Security Operations: Monitoring, Logs, and Threat Hunting

Key term

Log

A record of events occurring within a system or network.

Security Operations: Monitoring, Logs, and Threat Hunting

Key term

Aggregation

Collecting logs from various sources into one central location.

Security Operations: Monitoring, Logs, and Threat Hunting

Key term

Normalization

Converting diverse log formats into a standardized, common format.

Security Operations: Monitoring, Logs, and Threat Hunting

Key term

Correlation

Linking related events across different logs to identify patterns.

Security Operations: Monitoring, Logs, and Threat Hunting

Key term

Event ID

A unique identifier for a specific type of event in a log.

Security Operations: Monitoring, Logs, and Threat Hunting

Key term

Syslog

A standard protocol for sending system log messages.

Security Operations: Monitoring, Logs, and Threat Hunting

Memory trick

Log Sources, SIEM Concepts, and Sample Log Analysis

To remember SIEM functions: 'CAN-DO' - Collect, Aggregate, Normalize, Detect, Orchestrate (or Output).

Security Operations: Monitoring, Logs, and Threat Hunting

Exam tip

Log Sources, SIEM Concepts, and Sample Log Analysis

The exam often tests your understanding of what a SIEM does (collection, aggregation, normalization, correlation, alerting) and common log sources (Windows Event Logs, firewall logs, web server logs). Be prepared to identify the purpose of specific log entries or event IDs (e.g., 4625 for failed logon).

Security Operations: Monitoring, Logs, and Threat Hunting

Common mistake

Log Sources, SIEM Concepts, and Sample Log Analysis

Ignoring logs or failing to collect them centrally, making incident response slow and difficult.

Security Operations: Monitoring, Logs, and Threat Hunting

Common mistake

Log Sources, SIEM Concepts, and Sample Log Analysis

Not normalizing logs, which hinders correlation and makes analysis inefficient.

Security Operations: Monitoring, Logs, and Threat Hunting

Common mistake

Log Sources, SIEM Concepts, and Sample Log Analysis

Over-relying on default SIEM rules without tuning them for the specific environment, leading to alert fatigue or missed threats.

Security Operations: Monitoring, Logs, and Threat Hunting

Key term

Indicator of Compromise (IOC)

Forensic data that suggests a system or network has been breached.

Security Operations: Monitoring, Logs, and Threat Hunting

Key term

Baselining

Establishing a normal pattern of behavior to detect deviations.

Security Operations: Monitoring, Logs, and Threat Hunting

Key term

Anomaly Detection

Identifying deviations from established baselines or normal behavior.

Security Operations: Monitoring, Logs, and Threat Hunting

Key term

Command and Control (C2)

Server used by attackers to remotely control compromised systems.

Security Operations: Monitoring, Logs, and Threat Hunting

Key term

Data Exfiltration

Unauthorized transfer of data from a computer or network.

Security Operations: Monitoring, Logs, and Threat Hunting

Key term

Privilege Escalation

Gaining unauthorized higher-level access or permissions.

Security Operations: Monitoring, Logs, and Threat Hunting

Key term

Log Analysis

Reviewing records of events for security incidents or anomalies.

Security Operations: Monitoring, Logs, and Threat Hunting

Memory trick

Identifying Indicators of Malicious Activity

To remember IOCs, think 'I Observe Compromise': I for IP addresses, O for Outbound connections, C for C2 traffic, O for Odd processes, M for Malicious files, P for Privilege changes, R for Rogue accounts, O for Odd logins, M for Malicious domains, I for Infiltration attempts, S for Suspicious emails, E for Exfiltration.

Security Operations: Monitoring, Logs, and Threat Hunting

Exam tip

Identifying Indicators of Malicious Activity

For the CySA+ exam, memorize common event IDs for critical security events in Windows (e.g., 4624 for successful logon, 4625 for failed logon, 4688 for process creation, 4728 for group membership changes) and their Linux equivalents. Understand that baselining is crucial for distinguishing normal from anomalous behavior.

Security Operations: Monitoring, Logs, and Threat Hunting

Common mistake

Identifying Indicators of Malicious Activity

Ignoring minor anomalies: Small, seemingly insignificant deviations can be early indicators of a larger attack.

Security Operations: Monitoring, Logs, and Threat Hunting

Common mistake

Identifying Indicators of Malicious Activity

Lack of baselining: Without knowing what's normal, everything looks suspicious, leading to alert fatigue.

Security Operations: Monitoring, Logs, and Threat Hunting

Common mistake

Identifying Indicators of Malicious Activity

Focusing only on known IOCs: Attackers constantly evolve, so look for behavioral anomalies, not just signatures.

Security Operations: Monitoring, Logs, and Threat Hunting

Key term

Threat Intelligence (TI)

Evidence-based knowledge about existing or emerging cyber threats.

Security Operations: Monitoring, Logs, and Threat Hunting

Key term

Tactics, Techniques, and Procedures (TTPs)

Patterns of behavior and methods used by threat actors.

Security Operations: Monitoring, Logs, and Threat Hunting

Key term

Threat Hunting

Proactive and iterative search for threats not detected by security tools.

Security Operations: Monitoring, Logs, and Threat Hunting

Key term

OSINT

Open-Source Intelligence; publicly available information used for TI.

Security Operations: Monitoring, Logs, and Threat Hunting

Key term

ISAC/ISAO

Information Sharing and Analysis Center/Organization for threat data exchange.

Security Operations: Monitoring, Logs, and Threat Hunting

Key term

Hypothesis-Driven Hunting

Hunting method based on forming and testing assumptions about threats.

Security Operations: Monitoring, Logs, and Threat Hunting

Key term

MITRE ATT&CK

Globally accessible knowledge base of adversary tactics and techniques.

Security Operations: Monitoring, Logs, and Threat Hunting

Memory trick

Threat Intelligence Sources & Hunting Techniques

To remember the key characteristics of good TI, think of CAR: Contextual, Actionable, Relevant.

Security Operations: Monitoring, Logs, and Threat Hunting

Exam tip

Threat Intelligence Sources & Hunting Techniques

The CySA+ exam expects you to differentiate between strategic, operational, and tactical threat intelligence. Strategic TI informs high-level decisions, operational TI focuses on adversary TTPs, and tactical TI provides specific IOCs for immediate action.

Security Operations: Monitoring, Logs, and Threat Hunting

Common mistake

Threat Intelligence Sources & Hunting Techniques

Treating all threat intelligence as equally relevant; always prioritize based on your organization's specific risk profile.

Security Operations: Monitoring, Logs, and Threat Hunting

Common mistake

Threat Intelligence Sources & Hunting Techniques

Hunting without a clear hypothesis or goal, leading to aimless searching and wasted resources.

Security Operations: Monitoring, Logs, and Threat Hunting

Common mistake

Threat Intelligence Sources & Hunting Techniques

Failing to feed hunting discoveries back into security controls and threat intelligence platforms, missing opportunities for improvement.

Security Operations: Monitoring, Logs, and Threat Hunting

Key term

Packet Analysis

Inspecting network traffic data to understand communication.

Security Operations: Monitoring, Logs, and Threat Hunting

Key term

Display Filter

Rules in Wireshark to show only specific packets.

Security Operations: Monitoring, Logs, and Threat Hunting

Key term

Sandbox

An isolated environment for safely executing suspicious code.

Security Operations: Monitoring, Logs, and Threat Hunting

Key term

SOAR

Security Orchestration, Automation, and Response platform.

Security Operations: Monitoring, Logs, and Threat Hunting

Key term

Playbook

A predefined, automated sequence of actions for incident response.

Security Operations: Monitoring, Logs, and Threat Hunting

Key term

IOC (Indicator of Compromise)

Evidence on a network or system indicating intrusion.

Security Operations: Monitoring, Logs, and Threat Hunting

Memory trick

Packet Analysis, Wireshark, Sandboxing, and SOAR

Imagine a 'SOARing' eagle, orchestrating all the little 'PACKETS' of information below, then putting them in a 'SANDBOX' to play safely.

Security Operations: Monitoring, Logs, and Threat Hunting

Exam tip

Packet Analysis, Wireshark, Sandboxing, and SOAR

The exam often tests your ability to identify common Wireshark filters and their purpose. Memorize basic filter syntax for IP addresses, ports, and protocols. Also, understand the core function of sandboxing (safe execution) and SOAR (automation/orchestration).

Security Operations: Monitoring, Logs, and Threat Hunting

Common mistake

Packet Analysis, Wireshark, Sandboxing, and SOAR

Not using specific enough Wireshark filters, leading to overwhelming amounts of data.

Security Operations: Monitoring, Logs, and Threat Hunting

Common mistake

Packet Analysis, Wireshark, Sandboxing, and SOAR

Executing suspicious files directly on your analysis machine instead of in a sandbox.

Security Operations: Monitoring, Logs, and Threat Hunting

Common mistake

Packet Analysis, Wireshark, Sandboxing, and SOAR

Believing SOAR replaces human analysts entirely; it's a force multiplier, not a replacement.

Security Operations: Monitoring, Logs, and Threat Hunting

Key term

Asset Discovery

Process of identifying all hardware, software, and data within a network.

Vulnerability Management: Discovery to Remediation

Key term

Asset Inventory

A comprehensive, documented list of all IT assets in an organization.

Vulnerability Management: Discovery to Remediation

Key term

CMDB

Configuration Management Database; stores information about IT assets and their relationships.

Vulnerability Management: Discovery to Remediation

Key term

Shadow IT

Hardware or software used within an organization without official approval or knowledge.

Vulnerability Management: Discovery to Remediation

Key term

Active Discovery

Identifying assets by sending probes or requests to devices on the network.

Vulnerability Management: Discovery to Remediation

Key term

Passive Discovery

Identifying assets by monitoring network traffic and existing logs without direct interaction.

Vulnerability Management: Discovery to Remediation

Key term

Nmap

Network Mapper; a free and open-source utility for network discovery and security auditing.

Vulnerability Management: Discovery to Remediation

Memory trick

Asset Discovery and Inventory Techniques

To remember Active vs. Passive: 'Active' means you 'Act' on the network (send probes). 'Passive' means you 'Passively' listen (monitor traffic).

Vulnerability Management: Discovery to Remediation

Exam tip

Asset Discovery and Inventory Techniques

The CySA+ exam expects you to differentiate between active and passive discovery methods. Look for keywords like 'scanning,' 'probes,' or 'agents' for active, and 'monitoring traffic,' 'logs,' or 'sniffing' for passive.

Vulnerability Management: Discovery to Remediation

Common mistake

Asset Discovery and Inventory Techniques

Failing to include cloud assets or IoT devices in the asset inventory.

Vulnerability Management: Discovery to Remediation

Common mistake

Asset Discovery and Inventory Techniques

Relying solely on manual processes for asset discovery, leading to outdated inventories.

Vulnerability Management: Discovery to Remediation

Common mistake

Asset Discovery and Inventory Techniques

Not performing regular audits of the asset inventory against actual network devices.

Vulnerability Management: Discovery to Remediation

Key term

Vulnerability Scan

Automated process to identify security weaknesses in systems.

Vulnerability Management: Discovery to Remediation

Key term

Credentialed Scan

Scan performed with authenticated access to the target system.

Vulnerability Management: Discovery to Remediation

Key term

Non-Credentialed Scan

Scan performed without authenticated access, mimicking an external attacker.

Vulnerability Management: Discovery to Remediation

Key term

Network-based Scan

Assesses vulnerabilities visible from the network, targeting devices and services.

Vulnerability Management: Discovery to Remediation

Key term

Host-based Scan

Runs directly on a target system to inspect local configurations and software.

Vulnerability Management: Discovery to Remediation

Key term

Web Application Scan

Specifically targets web applications for common vulnerabilities like XSS or SQLi.

Vulnerability Management: Discovery to Remediation

Key term

Scan Policy

A set of rules and checks that a vulnerability scanner will perform.

Vulnerability Management: Discovery to Remediation

Memory trick

Vulnerability Scanning Types and Configuration

Think 'C' for Credentialed, 'C' for Comprehensive. If you have credentials, you get a much more comprehensive view inside the system.

Vulnerability Management: Discovery to Remediation

Exam tip

Vulnerability Scanning Types and Configuration

CompTIA CySA+ (CS0-003) candidates must distinguish between credentialed and non-credentialed scans, understanding their use cases and the depth of information each provides. Be prepared to identify the appropriate scan type for various scenarios, such as internal network assessments versus external perimeter testing.

Vulnerability Management: Discovery to Remediation

Common mistake

Vulnerability Scanning Types and Configuration

Relying solely on non-credentialed scans for internal systems, missing critical internal vulnerabilities.

Vulnerability Management: Discovery to Remediation

Common mistake

Vulnerability Scanning Types and Configuration

Not configuring scan policies correctly, leading to incomplete or irrelevant results.

Vulnerability Management: Discovery to Remediation

Common mistake

Vulnerability Scanning Types and Configuration

Ignoring false positives, causing unnecessary remediation efforts.

Vulnerability Management: Discovery to Remediation

Key term

CVSS

Common Vulnerability Scoring System; open standard for vulnerability severity.

Vulnerability Management: Discovery to Remediation

Key term

Base Score

Intrinsic characteristics of a vulnerability; constant over time.

Vulnerability Management: Discovery to Remediation

Key term

Temporal Score

Adjusts Base Score based on time-dependent factors (e.g., exploit).

Vulnerability Management: Discovery to Remediation

Key term

Environmental Score

Customizes score based on organizational context and asset criticality.

Vulnerability Management: Discovery to Remediation

Key term

Attack Vector

How a vulnerability can be exploited (e.g., Network, Local).

Vulnerability Management: Discovery to Remediation

Key term

Confidentiality Impact

Impact on data secrecy if vulnerability is exploited.

Vulnerability Management: Discovery to Remediation

Key term

Integrity Impact

Impact on data trustworthiness if vulnerability is exploited.

Vulnerability Management: Discovery to Remediation

Key term

Availability Impact

Impact on system access/uptime if vulnerability is exploited.

Vulnerability Management: Discovery to Remediation

Memory trick

Scoring and Prioritizing with CVSS

BTE: Base, Temporal, Environmental. Remember 'Be The Expert' to recall the three CVSS metric groups.

Vulnerability Management: Discovery to Remediation

Exam tip

Scoring and Prioritizing with CVSS

The CySA+ exam expects you to understand the three CVSS metric groups (Base, Temporal, Environmental) and their purpose. Be able to interpret what a high or low score implies for each metric, and how they collectively contribute to prioritization.

Vulnerability Management: Discovery to Remediation

Common mistake

Scoring and Prioritizing with CVSS

Only relying on the Base Score for prioritization without considering Temporal and Environmental factors.

Vulnerability Management: Discovery to Remediation

Common mistake

Scoring and Prioritizing with CVSS

Treating all vulnerabilities with the same CVSS score as equally critical, regardless of the affected asset.

Vulnerability Management: Discovery to Remediation

Common mistake

Scoring and Prioritizing with CVSS

Not understanding that CVSS is a tool for assessment, not a complete risk management solution on its own.

Vulnerability Management: Discovery to Remediation

Key term

Cyber Kill Chain

Seven-stage model outlining the typical phases of a cyberattack.

Vulnerability Management: Discovery to Remediation

Key term

Diamond Model

Framework for intrusion analysis focusing on Adversary, Capability, Infrastructure, Victim.

Vulnerability Management: Discovery to Remediation

Key term

Tactic

The 'why' of an adversary's action in MITRE ATT&CK (e.g., Execution, Persistence).

Vulnerability Management: Discovery to Remediation

Key term

Technique

The 'how' of an adversary's action in MITRE ATT&CK (e.g., PowerShell, Scheduled Task).

Vulnerability Management: Discovery to Remediation

Memory trick

Attack Frameworks: MITRE ATT&CK, Diamond Model, Kill Chain

To remember the Diamond Model's core features: 'A C I V' - 'A'll 'C'yber 'I'ntrusions 'V'ary.

Vulnerability Management: Discovery to Remediation

Exam tip

Attack Frameworks: MITRE ATT&CK, Diamond Model, Kill Chain

The exam often tests your ability to differentiate between the frameworks and apply them to specific scenarios. Pay close attention to the number of stages in the Cyber Kill Chain (seven) and the four core features of the Diamond Model.

Vulnerability Management: Discovery to Remediation

Common mistake

Attack Frameworks: MITRE ATT&CK, Diamond Model, Kill Chain

Confusing the stages of the Cyber Kill Chain or the components of the Diamond Model.

Vulnerability Management: Discovery to Remediation

Common mistake

Attack Frameworks: MITRE ATT&CK, Diamond Model, Kill Chain

Applying a framework that doesn't best fit the specific analysis need (e.g., using Kill Chain for granular technique detail).

Vulnerability Management: Discovery to Remediation

Common mistake

Attack Frameworks: MITRE ATT&CK, Diamond Model, Kill Chain

Not understanding that these frameworks are complementary and can be used together.

Vulnerability Management: Discovery to Remediation

Key term

Mitigation

Reducing the impact or likelihood of a vulnerability.

Vulnerability Management: Discovery to Remediation

Key term

Patching

Applying vendor-supplied updates to fix software flaws.

Vulnerability Management: Discovery to Remediation

Key term

Compensating Control

An alternative security measure to reduce risk.

Vulnerability Management: Discovery to Remediation

Key term

Hardening

Securing a system by reducing its attack surface.

Vulnerability Management: Discovery to Remediation

Key term

SSDLC

Integrating security into every phase of software development.

Vulnerability Management: Discovery to Remediation

Key term

Input Validation

Ensuring user-supplied data is safe and expected.

Vulnerability Management: Discovery to Remediation

Key term

Whitelisting

Only allowing explicitly approved input.

Vulnerability Management: Discovery to Remediation

Key term

Prepared Statement

A secure way to execute SQL queries with user input.

Vulnerability Management: Discovery to Remediation

Memory trick

Mitigation Strategies and Secure Coding Practices

To remember SSDLC phases: **R**eally **D**esigned **D**evelopers **T**est **D**eploy **M**aintain.

Vulnerability Management: Discovery to Remediation

Exam tip

Mitigation Strategies and Secure Coding Practices

The exam often tests your knowledge of the SSDLC phases and the importance of secure coding practices, especially input validation. Be prepared to identify which phase a security activity belongs to (e.g., threat modeling in design) and common vulnerabilities prevented by input validation (e.g., SQLi, XSS).

Vulnerability Management: Discovery to Remediation

Common mistake

Mitigation Strategies and Secure Coding Practices

Relying solely on client-side input validation; it's easily bypassed.

Vulnerability Management: Discovery to Remediation

Common mistake

Mitigation Strategies and Secure Coding Practices

Delaying patching critical vulnerabilities, increasing exposure time.

Vulnerability Management: Discovery to Remediation

Common mistake

Mitigation Strategies and Secure Coding Practices

Treating security as an afterthought, rather than integrating it into development.

Vulnerability Management: Discovery to Remediation

Key term

Incident Response Lifecycle

A structured approach to managing security incidents.

Incident Response and Management Essentials

Key term

Preparation Phase

The initial phase of IR, establishing plans and resources.

Incident Response and Management Essentials

Key term

Incident Response Plan (IRP)

A documented guide for handling security incidents.

Incident Response and Management Essentials

Key term

Incident Response Team (IRT)

A dedicated group responsible for executing the IRP.

Incident Response and Management Essentials

Key term

CSIRT

Computer Security Incident Response Team, another name for IRT.

Incident Response and Management Essentials

Key term

Tabletop Exercise

A discussion-based drill simulating an incident.

Incident Response and Management Essentials

Memory trick

Incident Response Lifecycle and Preparation

P-I-C-E-R-L: **P**eople **I**n **C**ybersecurity **E**verywhere **R**eally **L**ike security! (Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned)

Incident Response and Management Essentials

Exam tip

Incident Response Lifecycle and Preparation

The CySA+ exam heavily emphasizes the NIST Incident Response Lifecycle (SP 800-61). Memorize the six phases and understand the key activities within each, especially 'preparation' as it sets the stage for everything else.

Incident Response and Management Essentials

Common mistake

Incident Response Lifecycle and Preparation

Skipping the preparation phase, leading to chaotic and ineffective responses.

Incident Response and Management Essentials

Common mistake

Incident Response Lifecycle and Preparation

Failing to regularly update and test the Incident Response Plan (IRP).

Incident Response and Management Essentials

Common mistake

Incident Response Lifecycle and Preparation

Not providing adequate training or resources for the Incident Response Team (IRT).

Incident Response and Management Essentials

Key term

Containment

Isolating compromised systems to prevent further incident spread.

Incident Response and Management Essentials

Key term

Eradication

Removing the root cause and all traces of an incident.

Incident Response and Management Essentials

Key term

Recovery

Restoring systems and data to normal, secure operation.

Incident Response and Management Essentials

Key term

Network Segmentation

Dividing a network into smaller, isolated segments.

Incident Response and Management Essentials

Key term

Host Isolation

Disconnecting or quarantining a single compromised system.

Incident Response and Management Essentials

Key term

Post-Incident Hardening

Implementing security improvements after an incident.

Incident Response and Management Essentials

Memory trick

Containment, Eradication, and Recovery Techniques

Remember the C-E-R order: 'Cats Eat Rodents' (Contain, Eradicate, Recover).

Incident Response and Management Essentials

Exam tip

Containment, Eradication, and Recovery Techniques

The CySA+ exam expects you to know the specific steps of containment, eradication, and recovery and understand the rationale behind each. Look for keywords like 'isolate,' 'remove,' 'restore,' and 'verify' to identify the correct phase.

Incident Response and Management Essentials

Common mistake

Containment, Eradication, and Recovery Techniques

Skipping containment in an effort to immediately eradicate, leading to wider infection.

Incident Response and Management Essentials

Common mistake

Containment, Eradication, and Recovery Techniques

Failing to identify and remove the root cause during eradication, resulting in re-infection.

Incident Response and Management Essentials

Common mistake

Containment, Eradication, and Recovery Techniques

Restoring systems from compromised backups, reintroducing the threat.

Incident Response and Management Essentials

Key term

Chain of Custody

Documented history of evidence handling from collection to disposition.

Incident Response and Management Essentials

Key term

Volatile Data

Information lost when a system is powered off (e.g., RAM contents).

Incident Response and Management Essentials

Key term

Persistent Data

Information that remains after power-off (e.g., hard drive contents).

Incident Response and Management Essentials

Key term

Forensically Sound

Methods that preserve the integrity and authenticity of evidence.

Incident Response and Management Essentials

Key term

Write-Blocker

Hardware or software that prevents data modification on storage devices.

Incident Response and Management Essentials

Key term

Cryptographic Hash

A unique digital fingerprint used to verify data integrity.

Incident Response and Management Essentials

Key term

Tamper-Evident Bag

Security bag designed to show if it has been opened or altered.

Incident Response and Management Essentials

Memory trick

Evidence Handling and Chain of Custody

Remember 'CVPD' for the order of collection: Cache, Volatile memory, Persistent storage, Disk images. Or 'Can Very Patient Detectives'!

Incident Response and Management Essentials

Exam tip

Evidence Handling and Chain of Custody

The CySA+ exam frequently tests the order of volatility for data collection. Memorize that RAM, cache, and network connections are highly volatile and should be collected before disk images or logs. Also, know that cryptographic hashes (MD5, SHA1) are used to verify evidence integrity.

Incident Response and Management Essentials

Common mistake

Evidence Handling and Chain of Custody

Failing to document every transfer of evidence, leading to a broken chain of custody.

Incident Response and Management Essentials

Common mistake

Evidence Handling and Chain of Custody

Collecting persistent data before volatile data, resulting in the loss of critical information.

Incident Response and Management Essentials

Common mistake

Evidence Handling and Chain of Custody

Not using write-blockers or creating hashes, which can lead to evidence being deemed unreliable.

Incident Response and Management Essentials

Key term

Post-Incident Review (PIR)

Meeting to analyze an incident, identify root causes, and learn from it.

Incident Response and Management Essentials

Key term

Lessons Learned

Actionable insights and recommendations derived from a PIR.

Incident Response and Management Essentials

Key term

Root Cause Analysis

Process of identifying the fundamental reason for an incident.

Incident Response and Management Essentials

Key term

MTTD

Mean Time To Detect: average time to identify an incident.

Incident Response and Management Essentials

Key term

MTTR

Mean Time To Recover: average time to restore normal operations.

Incident Response and Management Essentials

Key term

MTTC

Mean Time To Contain: average time to stop an incident's spread.

Incident Response and Management Essentials

Key term

Continuous Improvement

Ongoing effort to enhance processes, products, or services.

Incident Response and Management Essentials

Memory trick

Post-Incident Activities and Lessons Learned

PIRATES: Post-Incident Review Analyzes The Entire Situation, Resulting in Actionable Takeaways, Enhancing Security.

Incident Response and Management Essentials

Exam tip

Post-Incident Activities and Lessons Learned

The exam expects you to know the purpose of a Post-Incident Review and how lessons learned contribute to organizational security posture. Keywords to look for include 'root cause analysis,' 'continuous improvement,' and 'metrics' like MTTD/MTTR.

Incident Response and Management Essentials

Common mistake

Post-Incident Activities and Lessons Learned

Skipping the post-incident review due to 'busyness' or a desire to move on.

Incident Response and Management Essentials

Common mistake

Post-Incident Activities and Lessons Learned

Focusing on blaming individuals rather than identifying process or system failures.

Incident Response and Management Essentials

Common mistake

Post-Incident Activities and Lessons Learned

Failing to document lessons learned or implement recommended changes.

Incident Response and Management Essentials

Key term

Vulnerability Report

Formal document detailing security weaknesses, their impact, and remediation.

Reporting and Communication for Blue Teams

Key term

Executive Summary

High-level, non-technical overview for management, focusing on business impact.

Reporting and Communication for Blue Teams

Key term

Technical Summary

Concise overview for technical leads, summarizing scope and key findings.

Reporting and Communication for Blue Teams

Key term

Remediation

The process of fixing or mitigating identified security vulnerabilities.

Reporting and Communication for Blue Teams

Key term

Actionable Recommendations

Specific, clear steps provided to fix or mitigate a vulnerability.

Reporting and Communication for Blue Teams

Key term

Evidence

Supporting data like log snippets or screenshots to validate vulnerability findings.

Reporting and Communication for Blue Teams

Memory trick

Writing Effective Vulnerability Reports

Remember 'REPORT': R-isk, E-vidence, P-urpose, O-utline, R-ecommendations, T-arget Audience.

Reporting and Communication for Blue Teams

Exam tip

Writing Effective Vulnerability Reports

The CySA+ exam (CS0-003) expects you to know the typical structure and content of a vulnerability report, including the distinction between executive and technical summaries, and the importance of actionable recommendations. Look for keywords like 'report structure,' 'stakeholder communication,' and 'remediation steps.'

Reporting and Communication for Blue Teams

Common mistake

Writing Effective Vulnerability Reports

Providing only technical details without an executive summary for management.

Reporting and Communication for Blue Teams

Common mistake

Writing Effective Vulnerability Reports

Offering vague recommendations instead of specific, actionable steps.

Reporting and Communication for Blue Teams

Common mistake

Writing Effective Vulnerability Reports

Failing to include sufficient evidence (e.g., log snippets, screenshots) to validate findings.

Reporting and Communication for Blue Teams

Key term

KPI (Key Performance Indicator)

Quantifiable measure of success towards an objective.

Reporting and Communication for Blue Teams

Key term

Security Metric

Specific data point used to measure security performance.

Reporting and Communication for Blue Teams

Key term

MTTD (Mean Time to Detect)

Average time from incident start to detection.

Reporting and Communication for Blue Teams

Key term

MTTR (Mean Time to Respond)

Average time from detection to initial response actions.

Reporting and Communication for Blue Teams

Key term

MTTC (Mean Time to Contain)

Average time from detection to incident containment.

Reporting and Communication for Blue Teams

Key term

MTTRc (Mean Time to Recover)

Average time from containment to full system restoration.

Reporting and Communication for Blue Teams

Key term

Operational Metrics

Real-time data for daily security activities.

Reporting and Communication for Blue Teams

Key term

Strategic Metrics

High-level data for long-term security decisions.

Reporting and Communication for Blue Teams

Memory trick

Key KPIs and Security Metrics That Matter

To remember the 'Mean Time To' metrics in order: Detect, Respond, Contain, Recover. Think 'DR. CR' – Doctor, See, Are, You.

Reporting and Communication for Blue Teams

Exam tip

Key KPIs and Security Metrics That Matter

The CySA+ exam expects you to identify and understand common security metrics and KPIs used in incident response and vulnerability management. Keywords to spot include 'MTTD', 'MTTR', 'containment time', 'patching cadence', and 'false positive rate'. Memorize what each of the 'Mean Time To...' metrics represents.

Reporting and Communication for Blue Teams

Common mistake

Key KPIs and Security Metrics That Matter

Confusing KPIs with raw metrics; KPIs are derived from metrics.

Reporting and Communication for Blue Teams

Common mistake

Key KPIs and Security Metrics That Matter

Collecting too many metrics without a clear purpose, leading to 'data overload'.

Reporting and Communication for Blue Teams

Common mistake

Key KPIs and Security Metrics That Matter

Failing to contextualize metrics for different audiences (e.g., technical vs. executive).

Reporting and Communication for Blue Teams

Key term

Stakeholder

Any individual or group with an interest in an incident.

Reporting and Communication for Blue Teams

Key term

Incident Report

Formal document detailing a security incident, its impact, and response.

Reporting and Communication for Blue Teams

Key term

Indicators of Compromise (IOCs)

Forensic data identifying malicious activity on a system or network.

Reporting and Communication for Blue Teams

Key term

Public Relations (PR)

Department managing an organization's public image and communication.

Reporting and Communication for Blue Teams

Key term

Regulatory Body

Government agency enforcing specific laws and regulations.

Reporting and Communication for Blue Teams

Key term

Communication Plan

Predefined strategy for informing stakeholders during an incident.

Reporting and Communication for Blue Teams

Key term

Timeliness

The promptness of reporting during a security incident.

Reporting and Communication for Blue Teams

Memory trick

Stakeholder Communication and Incident Reporting

To remember key report sections: 'E.I.I.R.R.R.' - Executive Summary, Incident Details, Impact, Response, Recovery, Recommendations.

Reporting and Communication for Blue Teams

Exam tip

Stakeholder Communication and Incident Reporting

The CySA+ exam expects you to differentiate between communication needs for various audiences. Keywords like 'executive leadership,' 'technical staff,' 'legal counsel,' and 'public relations' signal questions about tailored communication. Remember that regulatory compliance often dictates reporting timelines.

Reporting and Communication for Blue Teams

Common mistake

Stakeholder Communication and Incident Reporting

Using overly technical jargon when communicating with non-technical stakeholders.

Reporting and Communication for Blue Teams

Common mistake

Stakeholder Communication and Incident Reporting

Delaying incident notification to avoid perceived negative consequences.

Reporting and Communication for Blue Teams

Common mistake

Stakeholder Communication and Incident Reporting

Failing to update stakeholders as an incident evolves, leading to outdated information.

Reporting and Communication for Blue Teams

Key term

Compliance Framework

Set of guidelines for security practices.

Reporting and Communication for Blue Teams

Key term

HIPAA

US law protecting health information privacy.

Reporting and Communication for Blue Teams

Key term

GDPR

EU law for data protection and privacy.

Reporting and Communication for Blue Teams

Key term

PCI DSS

Standard for credit card data security.

Reporting and Communication for Blue Teams

Key term

NIST CSF

Framework for improving critical infrastructure cybersecurity.

Reporting and Communication for Blue Teams

Key term

Audit Finding

Identified deficiency during a compliance audit.

Reporting and Communication for Blue Teams

Key term

PDCA Cycle

Iterative management method for continuous improvement.

Reporting and Communication for Blue Teams

Memory trick

Compliance Reporting and Continuous Improvement

HIPAA protects Health, GDPR guards Global Data, PCI DSS secures Payments, NIST guides National Infrastructure. Remember the first letter of each to link it to its domain!

Reporting and Communication for Blue Teams

Exam tip

Compliance Reporting and Continuous Improvement

The exam often tests your knowledge of specific compliance frameworks (HIPAA, GDPR, PCI DSS, NIST CSF) and their primary purpose. Be ready to identify which framework applies to a given scenario (e.g., healthcare data, credit card processing).

Reporting and Communication for Blue Teams

Common mistake

Compliance Reporting and Continuous Improvement

Confusing the scope of different compliance frameworks (e.g., applying HIPAA rules to credit card data).

Reporting and Communication for Blue Teams

Common mistake

Compliance Reporting and Continuous Improvement

Failing to document security controls and actions, making it impossible to prove compliance during an audit.

Reporting and Communication for Blue Teams

Common mistake

Compliance Reporting and Continuous Improvement

Viewing compliance as a one-time event instead of an ongoing, continuous process.

Reporting and Communication for Blue Teams