CompTIA CySA+ (CS0-003) practice questions

231 free questions with answers and explanations.

Practice test
  1. 101.A security analyst is reviewing logs from a web application firewall (WAF) and notices the following entries: ``` TIME SRC_IP METHOD URI UA 14:05:12 10.0.0.5 GET /search?q=test%27+OR+1%3D1-- Mozilla/5.0 14:05:13 10.0.0.5 POST /login.php Mozilla/5.0 14:05:14 10.0.0.5 GET /products?category=electronics%27+UNION+SELECT+null,version(),database()-- Mozilla/5.0 ``` Which type of attack is indicated by these log entries?Incident Response and Management
  2. 102.A vulnerability management program cross-references CVSS with the Exploit Prediction Scoring System (EPSS). Vulnerability X has a CVSS base score of 7.5 and an EPSS score of 0.02 (2% probability of exploitation in the next 30 days). Vulnerability Y has a CVSS base score of 6.1 and an EPSS score of 0.89 (89% probability). With limited patching resources this week, which vulnerability should be prioritized first?Vulnerability Management
  3. 103.A security analyst is investigating a suspected data exfiltration incident. They find the following log entries from an internal DNS server:Vulnerability Management
  4. 104.A security analyst is investigating a suspected malware infection on a Windows workstation. The analyst needs to quickly determine if any unusual processes are running and if they are communicating over the network. Which of the following commands would be MOST effective for this initial assessment?Incident Response and Management
  5. 105.A security analyst has identified a critical vulnerability in a third-party application used by the finance department. The vulnerability has a CVSS score of 9.8 and allows unauthenticated remote code execution. The analyst needs to communicate this to the finance department head and the vendor. Which of the following is the MOST appropriate initial step for communicating this information to ensure proper handling and prioritization?Reporting and Communication
  6. 106.During an incident review, an analyst finds the following firewall log entries: `10:15:02 OUT 192.168.10.15:49321 -> 45.33.10.7:443 ALLOW` `10:20:04 OUT 192.168.10.15:49325 -> 45.33.10.7:443 ALLOW` `10:25:03 OUT 192.168.10.15:49330 -> 45.33.10.7:443 ALLOW` The internal host contacts the same external IP every 5 minutes with near-identical timing. Which Cyber Kill Chain phase does this activity represent?Vulnerability Management
  7. 107.An organization is developing a new mobile application that will handle sensitive customer data. To ensure the application's security, the development team plans to integrate security testing throughout the Software Development Life Cycle (SDLC). They specifically want to identify security flaws in the source code *before* the application is compiled and deployed. Which type of security testing is BEST suited for this requirement?Vulnerability Management
  8. 108.A security analyst is preparing a compliance report for GDPR. The organization experienced a data breach involving personal identifiable information (PII) of EU citizens. The report needs to detail the breach and the organization's response. Which of the following is a MANDATORY reporting requirement under GDPR that MUST be included in the report?Reporting and Communication
  9. 109.During TLS traffic analysis in Wireshark, an analyst cannot decrypt the session but still needs to identify which domain a client is attempting to reach, even though the destination IP address resolves to a shared CDN used by thousands of unrelated sites. Which field within the unencrypted TLS handshake provides this information?Security Operations
  10. 110.While reviewing a packet capture, an analyst determines the likely operating system of a remote host solely by examining the initial TTL value (128) and TCP window size in response packets that were already captured passively on the network, without sending any probe packets to the host. Which technique is being used?Security Operations
  11. 111.A security analyst is performing a forensic investigation on a workstation suspected of being compromised by malware. The analyst needs to create a forensically sound copy of the hard drive. Which of the following tools is BEST suited for this task?Incident Response and Management
  12. 112.A penetration tester is conducting an assessment of a corporate network. They gain initial access to a low-privilege workstation. Subsequently, they discover that the workstation has direct network connectivity to a segment containing critical database servers and management interfaces, which should have been isolated. This allows the tester to move from the compromised workstation directly to the sensitive database segment. Which security control, if properly implemented, would have best prevented this lateral movement?Vulnerability Management
  13. 113.A security analyst is reviewing a packet capture from a compromised host. The analyst observes ICMP Echo Request packets (Type 8, Code 0) being sent to an external IP address, with unusually large data payloads (e.g., 1000+ bytes). The corresponding ICMP Echo Reply packets (Type 0, Code 0) from the external IP also contain similar large data payloads. This communication pattern occurs frequently and is not associated with any known diagnostic tools or legitimate network activity. Which type of covert channel is most likely being utilized?Security Operations
  14. 114.A security analyst is dispatched to a remote office to investigate a suspected malware infection on a critical workstation. The analyst arrives and finds the workstation powered off. To preserve the most volatile evidence, what should the analyst do FIRST?Incident Response and Management
  15. 115.A vulnerability has fully functional exploit code publicly integrated into a widely used penetration testing framework, allowing virtually any attacker to reliably trigger it in most affected environments. When scoring the CVSS v3.1 Temporal metrics for this vulnerability, which value should be assigned to the Exploit Code Maturity (E) metric?Vulnerability Management
  16. 116.A security analyst is preparing a compliance report for the Payment Card Industry Data Security Standard (PCI DSS). The report must demonstrate that the organization regularly scans for vulnerabilities and remediates them within specified timeframes. Which of the following log snippets would be MOST relevant to include as evidence for this requirement?Reporting and Communication
  17. 117.An email security gateway captured the following log entry: `2024-03-11 08:42:10 SMTP-IN from=finance-alert@extern4l-billing.com to=ap@corp.com subject="Invoice_0398_Overdue.docm" attachment=Invoice_0398_Overdue.docm size=142KB action=DELIVERED` Minutes later, the recipient opened the attachment and enabled macros, triggering a download of a second-stage payload. According to the Lockheed Martin Cyber Kill Chain, which phase does the email log entry itself represent?Vulnerability Management
  18. 118.An organization experiences a widespread ransomware attack that encrypts critical servers and workstations. The security team successfully contains the outbreak by segmenting networks. They've identified the initial vector and eradicated the malware. What is the MOST critical next step in the incident response lifecycle to ensure business continuity and prevent recurrence?Incident Response and Management
  19. 119.A security analyst is investigating a potential data exfiltration incident. Suspicious network traffic is observed originating from an internal server to an unknown external IP address over an unusual port. The analyst needs to immediately prevent further data loss without disrupting other critical services. Which of the following containment strategies would be MOST appropriate?Incident Response and Management
  20. 120.A security analyst is investigating a potential compromise on a system that is part of a critical industrial control system (ICS). Due to the extreme sensitivity and potential for physical harm, the analyst must minimize any disruption to the operational technology (OT) network. Which of the following approaches to evidence collection is MOST appropriate in this scenario?Incident Response and Management
  21. 121.An analyst investigating suspected credential abuse filters Windows Security Event Logs for Kerberos service ticket requests and finds a large number of Event ID 4769 entries for a single user account, all requesting tickets with RC4 encryption (etype 0x17) for multiple different service accounts within a short time span. Which attack technique does this pattern MOST likely indicate?Security Operations
  22. 122.A security analyst is reviewing network traffic on a segment hosting critical industrial control systems (ICS). The analyst observes unusual Modbus/TCP traffic patterns, specifically a high volume of `Function Code 0x03 (Read Holding Registers)` requests originating from a previously unknown internal IP address (10.10.20.15) targeting multiple Programmable Logic Controllers (PLCs). The requests are not part of any scheduled maintenance or known operational procedures. Which of the following actions should the analyst take FIRST?Security Operations
  23. 123.During incident triage, an analyst finds the following command run from an already-compromised workstation: `C:\Windows\System32> psexec.exe \\FIN-SRV02 -u CORP\svc_backup -p ******** cmd.exe /c whoami` The command successfully authenticates to a second, previously unaffected server and runs a command remotely. Which MITRE ATT&CK tactic does this action represent?Vulnerability Management
  24. 124.A security analyst is evaluating a web application for potential vulnerabilities. The application takes user-submitted HTML content for blog posts and displays it directly on other users' screens. The analyst notices that a user can submit the following content: `<script>alert('XSS');</script>`, and it executes in other users' browsers. Which secure coding practice, if properly implemented, would prevent this specific vulnerability?Vulnerability Management
  25. 125.A security analyst is evaluating a web application for potential vulnerabilities. The application takes user input directly from a URL parameter and embeds it into an HTML page without proper sanitization or encoding. Specifically, a parameter `?title=<script>alert('XSS')</script>` causes a pop-up on the user's browser. Which secure coding practice would directly mitigate this type of vulnerability?Vulnerability Management
  26. 126.A SOC analyst reviewing endpoint logs finds the following command executed on a workstation: `powershell.exe -NoP -NonI -W Hidden -Enc SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkA...` Using the MITRE ATT&CK framework, this activity most directly maps to which tactic?Vulnerability Management
  27. 127.During incident triage, an analyst finds the following sequence of commands executed on a compromised Windows host: `wevtutil cl Security` `wevtutil cl System` `powershell.exe -Command "Set-MpPreference -DisableRealtimeMonitoring $true"` Which MITRE ATT&CK tactic do these actions represent?Vulnerability Management
  28. 128.A security analyst is reviewing logs from a web application firewall (WAF) and observes a high volume of requests targeting known vulnerable endpoints and attempting to inject SQL commands into input fields. These requests originate from various IP addresses globally and are repetitive in nature, attempting common attack patterns. Which phase of the Cyber Kill Chain does this activity most accurately represent?Vulnerability Management
  29. 129.A SOC analyst configures a SIEM correlation rule that has been generating dozens of daily alerts for authentication attempts from a company-owned vulnerability scanner. The scanner's IP address and login behavior are well documented and expected. Which action should the analyst take to reduce alert fatigue without weakening detection of real threats?Security Operations
  30. 130.A security analyst is reviewing a vulnerability scan report for a database server. The report flags a high-severity vulnerability (CVSS Base Score 8.5) related to an outdated version of the database software. The analyst confirms the vulnerability is legitimate. However, the database server is part of a legacy system that cannot be upgraded without significant re-engineering and downtime, estimated to take several months. What is the MOST appropriate immediate mitigation strategy for this vulnerability?Vulnerability Management
  31. 131.An organization is developing its incident response plan. A key discussion point is how to ensure that evidence collected during an incident is admissible in legal proceedings. Which of the following components is MOST critical to establish and maintain for all collected evidence?Incident Response and Management
  32. 132.A security operations center (SOC) analyst receives an alert indicating a high volume of outbound connections from an internal server to various external IP addresses on TCP port 6667. The server's baseline shows no legitimate services using this port. Which of the following is the MOST likely type of malware or activity associated with this behavior?Incident Response and Management
  33. 133.A network security analyst observes the following log entries from a firewall: ``` TIME: 2023-10-26 10:05:12 SRC: 192.168.1.10 DST: 172.16.1.5 PROTO: TCP SPORT: 52345 DPORT: 23 ACTION: DENY TIME: 2023-10-26 10:05:13 SRC: 192.168.1.10 DST: 172.16.1.6 PROTO: TCP SPORT: 52346 DPORT: 23 ACTION: DENY TIME: 2023-10-26 10:05:14 SRC: 192.168.1.10 DST: 172.16.1.7 PROTO: TCP SPORT: 52347 DPORT: 23 ACTION: DENY TIME: 2023-10-26 10:05:15 SRC: 192.168.1.10 DST: 172.16.1.8 PROTO: TCP SPORT: 52348 DPORT: 23 ACTION: DENY ``` Which type of attack is most likely indicated by these logs?Security Operations
  34. 134.A security analyst reviews Windows Security Event Logs from a domain controller covering a 5-minute window: Event ID 4625 (failed logon), Account: svc_backup, Source IP: 198.51.100.22 Total failed logon events in window: 600 Baseline average for this account: 4 failed logons per 5 minutes Based on this rate, which conclusion and next step is most appropriate?Security Operations
  35. 135.A security analyst is preparing a vulnerability report for a cloud-based application. The report needs to clearly articulate the business risk associated with a newly discovered SQL injection vulnerability to the application development team. Which of the following details, in addition to the technical description, would be MOST impactful for this audience?Reporting and Communication
  36. 136.A security analyst is investigating a suspected security incident on a Linux server. The primary goal is to determine if unauthorized commands were executed and by which user accounts. The analyst has access to the server's command history files and system logs. Which of the following log files or commands would provide the MOST direct evidence of commands executed by specific users, including their timestamps?Incident Response and Management
  37. 137.A security analyst is reviewing logs from a web server after an alert for unusual activity. They find the following entries: ``` [10/Oct/2023:14:35:01 +0000] "GET /index.php HTTP/1.1" 200 1234 "-" "Mozilla/5.0" [10/Oct/2023:14:35:05 +0000] "GET /admin/login.php HTTP/1.1" 200 5678 "-" "Mozilla/5.0" [10/Oct/2023:14:35:08 +0000] "POST /admin/login.php HTTP/1.1" 302 0 "-" "Mozilla/5.0" [10/Oct/2023:14:35:10 +0000] "GET /admin/dashboard.php HTTP/1.1" 200 9876 "-" "Mozilla/5.0" [10/Oct/2023:14:35:12 +0000] "GET /admin/users.php?id=1' UNION SELECT @@version -- - HTTP/1.1" 400 150 "-" "SQLi_Scanner/1.0" [10/Oct/2023:14:35:13 +0000] "GET /admin/users.php?id=1' ORDER BY 100 -- - HTTP/1.1" 400 150 "-" "SQLi_Scanner/1.0" ``` Which type of attack is clearly indicated by the log entries starting at 14:35:12?Incident Response and Management
  38. 138.A security team is investigating a data breach where sensitive customer information was exfiltrated. During the evidence collection phase, an analyst creates a forensic image of a hard drive. To ensure the integrity of the collected evidence, which of the following is the MOST crucial step after creating the image?Incident Response and Management
  39. 139.During incident investigation, an analyst notes that an attacker on a compromised finance workstation ran the following commands moments before proxy logs showed a large outbound transfer: `rar.exe a -hp secret.rar C:\Finance\Q4_Reports\*` `14:22:05 POST https://transfer.example-cloud.net/upload HTTP/1.1 200 [bytes-out: 512MB]` Which MITRE ATT&CK tactic best describes the proxy log entry showing the 512MB upload?Vulnerability Management
  40. 140.A security analyst is reviewing a system after a reported security incident. During the initial investigation, the analyst discovers a suspicious process running under a privileged account that is not part of the normal baseline. The process is communicating with an external IP address over an unusual port. The analyst needs to prevent further damage and data exfiltration while preserving evidence. Which of the following actions should the analyst prioritize NEXT?Incident Response and Management
  41. 141.A company places its public-facing web server in a separate network segment that is isolated from the internal corporate LAN but still reachable from the internet, with firewall rules restricting traffic between the segment and internal systems. What is this network architecture design called?Security Operations
  42. 142.An analyst reviews NetFlow records for a 15-minute window and finds internal host 10.10.5.22 generated 4,500 flow records to external IP 203.0.113.55, totaling 3.6 GB sent and only 12 MB received. No other internal hosts communicate with this IP. What does this traffic pattern MOST likely indicate?Security Operations
  43. 143.A security analyst is investigating a suspected breach involving a web application. The attacker is believed to have exploited a vulnerability to gain initial access. During the containment phase, the analyst needs to implement a temporary measure to block the attacker's access without disrupting legitimate user traffic entirely. The web application firewall (WAF) logs show repeated attempts from a specific IP address (203.0.113.42) to access '/admin.php' with unusual parameters, immediately followed by successful login attempts from the same IP, even for invalid credentials. Which of the following containment strategies would be most appropriate and effective in this scenario?Incident Response and Management
  44. 144.A threat hunter reviews DNS resolver logs and observes a single infected host querying hundreds of unique, algorithmically generated hostnames such as 'xk93jdla.com', 'plq82basd.net', and 'vt4mqzo.org' within a five-minute window, most returning NXDOMAIN. Which technique is most likely being used by the malware?Security Operations
  45. 145.An analyst captures traffic in Wireshark and observes the following in the packet list for a single TCP stream: 1 0.000 10.1.1.5 -> 198.51.100.9 TCP [SYN] Seq=0 Win=64240 2 0.210 198.51.100.9 -> 10.1.1.5 TCP [SYN, ACK] Seq=0 Ack=1 Win=65535 3 0.211 10.1.1.5 -> 198.51.100.9 TCP [ACK] Seq=1 Ack=1 4 1.500 10.1.1.5 -> 198.51.100.9 TCP [PSH, ACK] Seq=1 Ack=1 Len=1200 5 4.520 10.1.1.5 -> 198.51.100.9 TCP [PSH, ACK] Seq=1 Ack=1 Len=1200 [TCP Retransmission] 6 10.560 10.1.1.5 -> 198.51.100.9 TCP [PSH, ACK] Seq=1 Ack=1 Len=1200 [TCP Retransmission] What does this sequence MOST likely indicate?Security Operations
  46. 146.A company manages a large fleet of remote laptops that connect to the corporate VPN for only a few hours per week and are frequently offline. Which vulnerability scanning approach would provide the most consistent and up-to-date scan coverage for these devices?Vulnerability Management
  47. 147.A security analyst is preparing a quarterly report for the Chief Information Security Officer (CISO). The report needs to highlight the organization's adherence to regulatory requirements and its overall security posture in relation to industry benchmarks. Which of the following metrics would be MOST appropriate to include?Reporting and Communication
  48. 148.A security analyst is preparing an incident report for an unauthorized access event. The report needs to include a 'lessons learned' section to prevent similar incidents in the future. Which of the following elements is MOST crucial to thoroughly document in this section?Reporting and Communication
  49. 149.A security analyst is investigating a report of slow network performance and suspicious activity on a web server (10.10.10.10). The analyst captures the following network traffic summary during the incident: ``` Time Source IP Destination IP Protocol Length Info 0.000000 192.168.1.100 10.10.10.10 TCP 74 50000 -> 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 0.000050 192.168.1.101 10.10.10.10 TCP 74 50001 -> 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 0.000060 192.168.1.102 10.10.10.10 TCP 74 50002 -> 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 ... 0.000100 192.168.1.103 10.10.10.10 TCP 74 50003 -> 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 0.000110 192.168.1.104 10.10.10.10 TCP 74 50004 -> 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 ``` The web server is not responding to legitimate requests, and the analyst notes a large number of similar `[SYN]` packets from various source IPs to the web server's port 80, with very few corresponding `[SYN-ACK]` or `[ACK]` packets from the server. What type of attack is most likely occurring?Security Operations
  50. 150.During an incident response, a security analyst needs to perform deep forensic analysis on a compromised Windows server. The server is still running and critical for business operations, so it cannot be immediately shut down. Which of the following artifact types should the analyst prioritize collecting first due to its high volatility?Incident Response and Management