CompTIA CySA+ (CS0-003) practice questions
231 free questions with answers and explanations.
- 1.A cybersecurity analyst is preparing a quarterly report for the Chief Information Security Officer (CISO). The report needs to summarize the organization's adherence to the ISO 27001 framework, specifically focusing on the progress made in implementing controls for information security incident management. Which of the following metrics would be MOST relevant to include in this report?Reporting and Communication
- 2.A security operations center (SOC) manager is reviewing monthly performance metrics. They observe a consistent increase in the 'Number of Critical Alerts' generated by the SIEM, while the 'Mean Time To Acknowledge (MTTA)' these alerts has remained stable. To provide clear and actionable insights to the CISO, which additional metric would be MOST important to analyze alongside these two?Reporting and Communication
- 3.A security analyst is reviewing logs from a web server after an alert about unusual activity. The following log snippet is observed: ``` GET /index.php?page=products.php%27%20UNION%20SELECT%20null,database(),null--%20HTTP/1.1 Host: example.com User-Agent: Mozilla/5.0 ``` Which type of attack is indicated by this log entry?Incident Response and Management
- 4.A SOC wants to reduce mean time to respond (MTTR) for phishing reports submitted by employees. They implement a workflow where, upon a user reporting a suspicious email, the system automatically extracts the sender, URLs, and attachment hash, queries threat intelligence feeds, and quarantines the message across all mailboxes if the indicators are found malicious—all without analyst intervention. What is this capability best described as?Security Operations
- 5.An analyst reviewing DNS server logs notices the following unusual pattern from a single internal host: query: a8f3c9d2e1b7.exfildata.com TYPE=TXT query: 7b2f9e4a1c6d.exfildata.com TYPE=TXT query: 3d8e1f6a9b2c.exfildata.com TYPE=TXT (thousands of similar queries per hour, each with unique 12-character hex subdomains) What malicious activity does this pattern most likely indicate?Security Operations
- 6.After a successful incident containment and eradication, a security team is preparing to restore affected services. Part of this process involves ensuring that all systems are patched, configured securely, and monitored for any signs of re-infection. Which phase of the incident response lifecycle does this activity primarily fall under?Incident Response and Management
- 7.A malware analyst detonates a sample in an automated sandbox but observes no malicious behavior in the report. Manual analysis of the binary reveals a call to GetTickCount followed by a conditional branch that terminates the process if execution time appears too short. Which sandbox evasion technique is being used?Security Operations
- 8.A security analyst is investigating a suspected data exfiltration incident. The attacker used a compromised user account to log into a critical server and then attempted to transfer a large file to an external IP address. The analyst has identified the compromised account and the external IP. Which of the following actions represents the BEST long-term containment strategy for this specific threat?Incident Response and Management
- 9.A SOC analyst is investigating an alert from the SIEM indicating a high number of failed login attempts against a public-facing web application originating from a single source IP address (192.168.1.100). The logs show hundreds of attempts within a few minutes, each using a different username and password combination. What type of attack is most likely occurring?Security Operations
- 10.A security operations center (SOC) manager is reviewing Key Performance Indicators (KPIs) for the past quarter. One KPI shows an increasing trend in 'Mean Time To Contain (MTTC)' incidents. The manager needs to communicate this finding to the CISO and propose improvements. Which of the following approaches is MOST effective for this communication?Reporting and Communication
- 11.An analyst calculates a CVSS v3.1 Base Score of 8.9 for a newly discovered vulnerability in a network appliance. According to the official CVSS v3.1 qualitative severity rating scale, which severity label should be assigned to this finding?Vulnerability Management
- 12.A SOC analyst investigating a compromised workstation finds the following command in the Windows event log: `reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Updater /t REG_SZ /d "C:\Users\Public\svc.exe"` This command runs automatically at every user logon. Which MITRE ATT&CK tactic best describes this behavior?Vulnerability Management
- 13.A vulnerability with a CVSS v3.1 Base Score of 6.5 exists on a server hosting the organization's core financial ledger. Because a compromise of that ledger's confidentiality would cause severe business harm, the analyst sets the Confidentiality Requirement (CR) to High when calculating the Environmental Score, raising the final adjusted score to 8.1 — higher than the Base Score alone. What does this scenario best illustrate about CVSS scoring?Vulnerability Management
- 14.A compliance officer is preparing a report for an upcoming audit against the NIST Cybersecurity Framework (CSF). The organization has recently implemented a new privileged access management (PAM) solution. Which core function of the NIST CSF would be MOST directly supported by reporting on the effectiveness and implementation status of this PAM solution?Reporting and Communication
- 15.A security analyst discovers a critical misconfiguration on a production web server that exposes sensitive customer data. The analyst needs to communicate this finding to the server owner and management. Which of the following elements is MOST crucial to include in the initial communication to ensure the issue is understood and prioritized correctly?Reporting and Communication
- 16.A security analyst is investigating a suspected insider threat. The analyst needs to collect volatile data from a running Windows server without altering the system state unnecessarily. Which of the following data types should be collected FIRST due to its ephemeral nature?Incident Response and Management
- 17.A security analyst is preparing a quarterly report on the organization's security posture for the Board of Directors. The board is primarily interested in high-level trends and the overall effectiveness of security investments. Which of the following Key Performance Indicators (KPIs) would be MOST appropriate to include in this report?Reporting and Communication
- 18.A security analyst is investigating a suspected data exfiltration incident. Reviewing proxy logs, the analyst observes a large volume of outbound traffic from an internal host (10.10.10.50) to an external IP address (203.0.113.10) on a non-standard port, but the traffic appears to be legitimate HTTP/S. Further inspection of the traffic reveals highly obfuscated data within the HTTP User-Agent and Accept-Language headers. What type of exfiltration technique is most likely being employed?Security Operations
- 19.An analyst reviewing endpoint logs finds the following PowerShell command executed by a non-administrative user: powershell.exe -NoP -NonI -W Hidden -Enc SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAn... Which characteristic of this command is the STRONGEST indicator of malicious intent?Security Operations
- 20.During the recovery phase of an incident, a security team is tasked with restoring services after a major ransomware attack. The team has successfully eradicated the ransomware and verified the integrity of backups. Which of the following is the MOST critical next step before bringing affected systems back online?Incident Response and Management
- 21.A threat hunter formulates the hypothesis: 'An adversary may be using legitimate remote management tools already present in our environment to move laterally, since our EDR only alerts on known malware signatures.' Based on this hypothesis, the hunter begins searching process execution logs for unusual parent-child relationships involving PsExec, WMI, and PowerShell Remoting. Which threat hunting methodology is being demonstrated?Security Operations
- 22.A security analyst is investigating a suspected data exfiltration incident. The attacker gained access to a critical server and is believed to be using a covert channel for data transfer. The analyst observes the following log entries from a firewall: ``` TIME=2023-10-26T14:35:01 SRC_IP=192.168.1.10 DST_IP=8.8.8.8 PROTO=UDP DST_PORT=53 LEN=72 TIME=2023-10-26T14:35:02 SRC_IP=192.168.1.10 DST_IP=8.8.8.8 PROTO=UDP DST_PORT=53 LEN=85 TIME=2023-10-26T14:35:03 SRC_IP=192.168.1.10 DST_IP=8.8.8.8 PROTO=UDP DST_PORT=53 LEN=69 TIME=2023-10-26T14:35:04 SRC_IP=192.168.1.10 DST_IP=8.8.8.8 PROTO=UDP DST_PORT=53 LEN=78 ``` Which type of covert channel is most likely indicated by these log entries?Incident Response and Management
- 23.After an organization successfully recovers from a significant data breach, the incident response team conducts a thorough review. They identify that the breach originated from an unpatched vulnerability in a legacy system and that communication between teams was inefficient. Which of the following activities is the MOST important outcome of this review process?Incident Response and Management
- 24.A cyber incident response team is conducting a post-incident review after successfully containing and eradicating a sophisticated malware outbreak. The team has gathered data from various sources, including security logs, network traffic captures, and analyst notes. The primary goal of this phase is to refine future response capabilities. Which of the following activities is the MOST crucial for achieving this primary goal during the post-incident review?Incident Response and Management
- 25.A security analyst is performing a penetration test against a web application. During the reconnaissance phase, the analyst uses a tool to send a specially crafted HTTP request to the target server: ``` GET / HTTP/1.1 Host: example.com User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Accept-Language: en-US,en;q=0.9 Accept-Encoding: gzip, deflate Connection: keep-alive X-Forwarded-For: 127.0.0.1 ``` The analyst observes that the server's response includes the `X-Forwarded-For` header with the value `127.0.0.1` in the response, while other requests without this header do not. This indicates the presence of a proxy or load balancer that is reflecting the header. Which vulnerability or misconfiguration is the analyst attempting to identify?Security Operations
- 26.A threat hunter is investigating a potential compromise on the corporate network. While analyzing NetFlow records, the hunter observes a workstation (192.168.1.50) initiating a large number of UDP connections to various external IP addresses on port 53. The data sizes for these UDP packets are consistently small (around 60-100 bytes), and the destination domains are often newly registered or appear to be algorithmically generated. Which of the following malicious activities is MOST consistent with these observations?Security Operations
- 27.A security analyst is reviewing web server access logs and notices the following entries: ``` 192.168.1.1 - - [26/Oct/2023:10:30:01 +0000] "GET /index.php?id=1 UNION SELECT 1,2,3,4,5-- - HTTP/1.1" 200 1234 192.168.1.1 - - [26/Oct/2023:10:30:02 +0000] "GET /index.php?id=1 AND 1=1-- - HTTP/1.1" 200 1234 192.168.1.1 - - [26/Oct/2023:10:30:03 +0000] "GET /index.php?id=1 AND 1=2-- - HTTP/1.1" 404 98 ``` Which type of attack is being attempted against the web server?Security Operations
- 28.A security analyst is investigating a suspected malware infection on a Windows workstation. The EDR solution reports a process named `svchost.exe` running from `C:\Users\Public\Documents\malware.exe`, which is an unusual location for this legitimate system process. Additionally, the process is making outbound connections to a known malicious IP address. What defense evasion technique is the attacker most likely employing?Security Operations
- 29.A network analyst captures the following Wireshark summary during a suspected attack: src=203.0.113.5 dst=10.0.0.10 flags=[SYN] count=48,000 in 30s src=10.0.0.10 dst=203.0.113.5 flags=[SYN,ACK] count=48,000 src=203.0.113.5 dst=10.0.0.10 flags=[ACK] count=12 Which attack does this traffic pattern most likely indicate?Security Operations
- 30.A SOC lead explains that when a phishing email is reported, the SOAR platform automatically extracts indicators, queries threat intelligence feeds, and quarantines the message across all mailboxes without any analyst involvement. Which SOAR concept does this fully unattended, end-to-end workflow represent?Security Operations
- 31.A network administrator runs an Nmap SYN scan across the 10.1.5.0/24 subnet, sending probe packets directly to each address to identify live hosts, open ports, and service versions for an updated asset inventory. Which asset discovery technique does this describe?Vulnerability Management
- 32.A security analyst is reviewing a custom web application's access logs and identifies the following requests originating from a single IP address (10.10.10.5): ``` GET /api/v1/users?search=admin%27%20OR%20%271%27%3D%271 HTTP/1.1 GET /api/v1/products?category=electronics%27%3B%20WAITFOR%20DELAY%20%270%3A0%3A5%27--%20 HTTP/1.1 GET /api/v1/orders?id=123%20AND%20SUBSTRING%28version%28%29%2C1%2C1%29%3D%275%27 HTTP/1.1 ``` Which type of attack is being attempted, and what specific variant is indicated by the second and third entries?Security Operations
- 33.A vulnerability scanner flags a Linux server as affected by a specific Apache HTTP Server CVE based solely on the version string reported in the server's HTTP banner. During manual verification, the analyst confirms the vendor backported the security fix into this version and the vulnerable code path is no longer present. How should this scan result be classified?Vulnerability Management
- 34.A web application firewall log shows the following request against a public e-commerce site: `192.168.1.15 - - [10/Mar/2024:14:22:07 +0000] "GET /products.php?id=1' UNION SELECT username,password FROM users-- HTTP/1.1" 200 1523` Which type of attack does this log entry MOST likely indicate?Security Operations
- 35.A threat intelligence analyst rates an external feed source as 'B2' when logging a new indicator, meaning the source is usually reliable and the information is probably true. Which evaluation system is being used to grade the source and the information?Security Operations
- 36.An incident responder is using the Diamond Model of Intrusion Analysis to document an attack. The team identifies the malicious IP address 203.0.113.55 that hosted the phishing page and later received stolen credentials. Within the Diamond Model, which core feature does this IP address represent?Vulnerability Management
- 37.A security analyst is reviewing a vulnerability scan report for a fleet of Windows servers. The report flags several servers as missing critical security updates for the operating system and various installed applications. The organization needs a method to automate the deployment of these patches across all affected servers while minimizing manual effort. Which solution is best suited for this task?Vulnerability Management
- 38.An incident responder documents an attack using the Diamond Model of Intrusion Analysis. In the report, they record the C2 domain name, the hosting provider's IP address, and the compromised relay server used to route traffic to the attacker. Which core feature (vertex) of the Diamond Model does this information populate?Vulnerability Management
- 39.During an incident, an analyst identifies that an attacker used a phishing email for initial access, then leveraged a scheduled task for persistence, and finally used PsExec to move laterally to a file server. The analyst wants to document this behavior using a standardized adversary behavior framework for the incident report. Which framework should be used?Security Operations
- 40.A development team is building a new mobile application that will handle sensitive customer data. They want to identify security vulnerabilities such as hardcoded credentials, insecure configuration, and potential injection flaws early in the development lifecycle, without actually running the application. Which testing methodology is best suited for this purpose?Vulnerability Management
- 41.A cyber incident response team has successfully contained a sophisticated persistent threat (APT) from their network. They are now in the post-incident activity phase. Which of the following activities is MOST crucial for improving the organization's future security posture based on this incident?Incident Response and Management
- 42.A cloud security architect wants to prevent lateral movement between application workloads that reside on the same subnet by enforcing granular, workload-level firewall policies instead of relying solely on VLAN boundaries. Which architectural concept BEST describes this approach?Security Operations
- 43.A security analyst discovers a critical vulnerability in a production web application that has a CVSSv3 base score of 9.8. The vulnerability allows unauthenticated remote code execution. The development team is currently focused on a major feature release. Which stakeholder group should be immediately informed, emphasizing the potential for data breach and service unavailability, to ensure prompt prioritization and resource allocation for remediation?Reporting and Communication
- 44.A vulnerability management team must choose which finding to remediate first this week. Vulnerability A has a CVSS Base Score of 7.5, appears on the CISA Known Exploited Vulnerabilities (KEV) catalog, and affects an internet-facing VPN appliance. Vulnerability B has a CVSS Base Score of 9.1 but affects an internal file server with no known exploitation activity. Which vulnerability should be prioritized first, and why?Vulnerability Management
- 45.Employees on a corporate segment suddenly lose network connectivity. An analyst captures traffic and sees that for a single DHCPDISCOVER broadcast, two DHCPOFFER messages are returned from two different MAC addresses, one of which is not on the approved switch port list, and clients receiving that offer are assigned an incorrect default gateway. Which activity does this indicate?Security Operations
- 46.An analyst reviewing authentication logs from a public-facing web application finds the following pattern from a single source IP over 10 minutes: 5,000 login attempts against 3,200 distinct usernames, with each username attempted only one or two times using a unique password, followed by 12 successful logins to different accounts. Which attack technique does this pattern indicate?Security Operations
- 47.A threat intelligence team wants to automatically share and receive structured indicators of compromise (IOCs) with an information sharing and analysis center (ISAC) using a standardized, machine-readable format transported over a defined exchange protocol. Which pair of standards should the team implement?Security Operations
- 48.A security analyst is drafting an incident report for a successful ransomware attack that encrypted several critical file servers. The incident response team managed to recover all data from backups and restore services within 24 hours. The report needs to highlight the effectiveness of the incident response plan and the team's performance. Which of the following KPIs would be MOST appropriate to demonstrate this success to management?Reporting and Communication
- 49.During a monthly security review, a security analyst notes a consistent increase in the number of successful brute-force attacks against SSH services, despite existing lockout policies. The analyst needs to communicate this trend to the network operations team to prompt a configuration change. Which of the following communication methods is MOST effective for conveying technical details and facilitating immediate action?Reporting and Communication
- 50.An organization is preparing for an annual security audit. The auditor requests evidence of adherence to the principle of least privilege for critical systems. Which of the following metrics would be MOST effective in demonstrating compliance with this principle?Reporting and Communication