CompTIA CySA+ (CS0-003) practice questions

231 free questions with answers and explanations.

Practice test
  1. 151.A security analyst is performing a forensic investigation on a Linux server following a suspected rootkit infection. The analyst needs to identify any hidden or modified system binaries. Which of the following commands would be most effective for comparing the cryptographic hashes of installed packages against a known good baseline?Incident Response and Management
  2. 152.A security analyst is building a threat hunting hypothesis focused on detecting advanced persistent threats (APTs). The analyst suspects that an APT might be using legitimate system utilities for living-off-the-land techniques to evade detection. The analyst wants to specifically look for instances where `rundll32.exe` is used to load arbitrary DLLs from non-standard locations or with unusual command-line arguments. Which of the following log sources would be MOST effective for detecting this specific activity?Security Operations
  3. 153.A development team wants to identify vulnerabilities such as hardcoded credentials, insecure cryptographic calls, and unsafe deserialization directly within the application's source code before it is compiled or deployed. Which testing technique best fits this requirement?Vulnerability Management
  4. 154.Windows Security Event Log Event ID 4688 shows the following process creation entry on a user workstation: `New Process Name: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe` `Creator Process Name: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE` `Process Command Line: powershell.exe -nop -w hidden -enc SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQA...` Which of the following BEST explains this event?Security Operations
  5. 155.A security analyst is reviewing a server after a suspected compromise. The server is a Linux web server running Apache. The analyst discovers a suspicious file named 'shell.php' in the web root directory (/var/www/html) containing base64 encoded strings and commands for executing system processes. The file was created by the 'apache' user. Which of the following is the MOST appropriate eradication step for this finding?Incident Response and Management
  6. 156.A security analyst is preparing a compliance report for the Payment Card Industry Data Security Standard (PCI DSS). The report needs to demonstrate that the organization has implemented and maintained appropriate access controls for systems processing cardholder data. Which of the following metrics would be MOST effective in demonstrating this compliance requirement?Reporting and Communication
  7. 157.During malware analysis, an incident responder determines that the attacker took a known Adobe Reader exploit and bundled it with a custom remote access trojan into a single malicious PDF file before ever sending it to the target. Which phase of the Cyber Kill Chain does this activity represent?Vulnerability Management
  8. 158.A security manager reviews an incident timeline: initial compromise occurred at 09:50, the SIEM generated an alert at 10:02, an analyst began triage at 10:10, and containment was completed at 10:45. Based on this timeline, what is the Mean Time to Detect (MTTD) for this incident?Security Operations
  9. 159.A web server access log shows the following sequence of requests from a single external IP address over two minutes, with no exploitation attempts or payloads submitted: `10:02:11 GET /robots.txt 200 10:02:12 GET /sitemap.xml 200 10:02:15 GET /.git/config 404 10:02:20 GET /admin/login.php 200` According to the Cyber Kill Chain, which phase does this activity represent?Vulnerability Management
  10. 160.A security analyst is preparing a quarterly report for the board of directors. The report needs to provide a high-level overview of the organization's cybersecurity posture and key risks. Which type of metric should the analyst primarily focus on to ensure the information is relevant and actionable for this audience?Reporting and Communication
  11. 161.A security analyst is investigating a suspected advanced persistent threat (APT) that has compromised several systems within the organization. The attacker is believed to be leveraging living-off-the-land binaries (LOLBins) and fileless malware techniques to maintain persistence and evade detection. The analyst has collected memory dumps from several affected workstations. Which of the following techniques would be MOST effective for detecting fileless malware and LOLBin usage within the collected memory dumps?Incident Response and Management
  12. 162.A security analyst is reviewing alerts from an EDR solution. An alert indicates that `cmd.exe` spawned `powershell.exe`, which then executed a base64-encoded command. The EDR also reports that `powershell.exe` then made an outbound connection to a suspicious IP address (185.x.x.x) on port 80. The encoded command, when decoded, reveals a script attempting to download and execute a file from the same suspicious IP. Which MITRE ATT&CK technique does this scenario primarily represent?Security Operations
  13. 163.An analyst is scoring a newly discovered web application flaw using CVSS v3.1. The vulnerability can be exploited remotely over the network (AV:N), requires low attack complexity (AC:L), needs no privileges (PR:N), requires no user interaction (UI:N), does not change scope (S:U), and results in complete loss of confidentiality, integrity, and availability (C:H/I:H/A:H). What is the resulting CVSS v3.1 Base Score?Vulnerability Management
  14. 164.A security team is implementing a vulnerability management program for a new cloud environment. They want to ensure that all virtual machines (VMs) and containers are continuously monitored for misconfigurations and known vulnerabilities, including those introduced by new software deployments. Which type of vulnerability scanning is BEST suited for this requirement?Vulnerability Management
  15. 165.An analyst reviews a CVSS v3.1 vector string for a newly disclosed vulnerability: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H. What does the AC:H (Attack Complexity: High) metric indicate about exploiting this vulnerability?Vulnerability Management
  16. 166.A malware analyst wants to write reusable detection signatures based on specific byte sequences, strings, and file structure patterns so that antivirus and EDR tools can scan disk and memory for known malware families across many samples. Which tool/format is purpose-built for this task?Security Operations
  17. 167.A security analyst is investigating a potential insider threat where an employee is suspected of exfiltrating sensitive company data. The investigation requires collecting digital evidence from the employee's workstation. To ensure the evidence is admissible in court and its integrity is maintained, a strict protocol must be followed. Which of the following actions is MOST critical to establish and maintain the integrity and authenticity of the collected digital evidence?Incident Response and Management
  18. 168.A security analyst is reviewing a vulnerability scan report for a critical database server. The report indicates several 'High' severity vulnerabilities with a CVSS base score range of 7.0-8.9. The analyst knows that the database contains highly sensitive customer data and is directly accessible from the internet. When preparing the vulnerability report for the database owner, which additional detail should the analyst emphasize to BEST convey the true organizational risk beyond the technical CVSS score?Reporting and Communication
  19. 169.A security analyst is reviewing network flow logs and observes a significant increase in outbound traffic to a single external IP address (172.217.160.142) from multiple internal workstations. The traffic is consistently using TCP port 6667, which is typically associated with Internet Relay Chat (IRC). Further investigation reveals that the internal workstations are communicating with this external IP using malformed HTTP requests. Which of the following types of C2 (Command and Control) channel is this activity most indicative of?Incident Response and Management
  20. 170.A security analyst is reviewing a packet capture from a compromised host. The analyst observes a high volume of ICMP Echo Request and Echo Reply packets, but the data payload within these packets is unusually large and appears to contain encoded information, rather than typical small ping payloads. The destination IP addresses are external and belong to a known suspicious range. What type of covert communication is this indicative of?Security Operations
  21. 171.A SOC analyst is investigating a suspected data exfiltration incident. Reviewing proxy logs, the analyst finds a significant volume of outbound traffic from an internal workstation to an external IP address (52.x.x.x) over port 443. The traffic size for each connection is small, but the connections are frequent and occur at irregular intervals. Further inspection of the traffic reveals a high degree of entropy in the data payloads. Which type of data exfiltration technique is most likely being employed?Security Operations
  22. 172.A penetration test finds that an attacker who compromised a single workstation in the finance VLAN was able to directly reach domain controllers, file servers, and HR systems over SMB because all hosts shared the same flat broadcast domain with no internal traffic restrictions. Which mitigation would most effectively reduce the blast radius of a similar compromise in the future?Vulnerability Management
  23. 173.A security team needs to build an inventory of devices on a fragile industrial control network segment. Management is concerned that active port scanning could crash sensitive PLCs. Which asset discovery method should the analyst use?Vulnerability Management
  24. 174.A threat intelligence analyst tells the SOC team that blocking a malware file hash only causes an attacker a minor inconvenience, since a new hash can be generated instantly, whereas identifying and countering the adversary's tactics, techniques, and procedures (TTPs) forces them to fundamentally retool their entire operation. Which concept describes this hierarchy of indicator durability and value?Security Operations
  25. 175.A legacy medical device running an unsupported operating system has a critical unpatched vulnerability. The vendor states that applying any OS patch will void the device's regulatory certification. Which action best mitigates the risk while keeping the device certified?Vulnerability Management
  26. 176.An organization is updating its incident response plan. A key discussion point is how to handle evidence collected during an incident to ensure its admissibility in potential legal proceedings. Which of the following elements is MOST critical to establish for every piece of evidence collected?Incident Response and Management
  27. 177.A security analyst is investigating a potential compromise on the corporate network. While analyzing DNS server logs, the analyst observes numerous unusual-looking DNS queries originating from an internal host (10.10.10.20) to an external domain (malicious.com). The queries often contain long, seemingly random strings as subdomains, and the responses typically return non-existent domain (NXDOMAIN) errors or very small data packets. What type of activity is this pattern most indicative of?Security Operations
  28. 178.A security analyst is investigating a potential compromise on a Windows server. The analyst suspects that an attacker may have established persistence by creating scheduled tasks that execute malicious scripts. The analyst needs to identify these scheduled tasks to remove them. Which of the following command-line utilities or locations would be MOST effective for listing and examining scheduled tasks on a Windows system?Incident Response and Management
  29. 179.A vulnerability management team runs a scan against a fleet of Windows servers using SCAP content mapped to the CIS Benchmark for Windows Server 2019. The scan checks registry values, password policy settings, and audit configurations rather than searching for unpatched CVEs. Which type of scan is being performed?Vulnerability Management
  30. 180.A security analyst is drafting an incident report for a successful ransomware attack. The report needs to clearly articulate the immediate financial impact of the attack to executive leadership. Which of the following would be MOST appropriate to include in the 'Impact Assessment' section?Reporting and Communication
  31. 181.A security analyst is preparing a report on the organization's adherence to the NIST Cybersecurity Framework (CSF) 'Recover' function. Which of the following metrics would be MOST relevant to include in this report?Reporting and Communication
  32. 182.A security analyst is reviewing a vulnerability report that lists a critical vulnerability (CVSS Base Score 9.8) in a web application. The vulnerability is a remote code execution flaw. However, the report indicates the CVSS Temporal Score is significantly lower. Upon investigation, the analyst discovers the following in the temporal vector string: `E:U/RL:O/RC:C`. What is the most likely reason for the lower temporal score?Vulnerability Management
  33. 183.A development team wants to test a running web application for vulnerabilities without access to its source code, simulating how an external attacker would interact with it over HTTP. Which testing approach should they use?Vulnerability Management
  34. 184.A security analyst is investigating a suspected phishing attempt. A user reported an email with a suspicious link, which was clicked. The analyst needs to determine if any malicious files were downloaded or executed on the user's workstation. Which of the following log types would provide the MOST direct evidence of such activity?Incident Response and Management
  35. 185.A SOC is redesigning its logging strategy and must decide whether analysts should review logs directly on each individual firewall and server or forward all logs to a centralized SIEM platform. Which of the following is the PRIMARY benefit of forwarding logs to a centralized SIEM?Security Operations
  36. 186.An analyst reviews the CVSS v3.1 vector for a vulnerability in an internal HR application: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H. Based on the Privileges Required (PR) metric, what must be true for successful exploitation?Vulnerability Management
  37. 187.A SOC integrates its SOAR platform with the organization's ITSM tool. When an employee-reported phishing email triggers the playbook, the SOAR platform automatically opens a ticket, assigns it to the on-call analyst, attaches extracted indicators, and updates the ticket status as each remediation step completes. Which SOAR capability does this scenario primarily illustrate?Security Operations
  38. 188.A security analyst is compiling a 'lessons learned' report after a successful phishing campaign resulted in a minor data breach. The report needs to identify areas for improvement in both technical controls and organizational processes. Which section of the report should detail the specific actions that will be taken to prevent recurrence and strengthen defenses?Reporting and Communication
  39. 189.A legacy C application component repeatedly suffers from buffer overflow vulnerabilities due to manual pointer arithmetic and unchecked array bounds. The development team wants to eliminate this entire class of vulnerability going forward rather than continuing to patch individual instances. Which secure coding practice would most directly achieve this goal?Vulnerability Management
  40. 190.A developer modifies a web form's server-side code so that any submitted username field is checked against an approved allow-list of alphanumeric characters and rejected if it contains anything else before the value is processed further. Which secure coding practice is being applied?Vulnerability Management
  41. 191.A wireless intrusion detection system alerts on the following activity in a corporate office: - AP1: SSID "CorpWiFi", BSSID 00:1A:2B:3C:4D:5E, channel 6, signal strength -40 dBm - AP2: SSID "CorpWiFi", BSSID 00:1A:2B:3C:4D:99, channel 11, signal strength -35 dBm (new, unregistered) - A burst of deauthentication frames targeting clients connected to AP1 occurs immediately before several clients associate with AP2 Which of the following attacks does this activity MOST likely represent?Security Operations
  42. 192.During a forensic investigation, a security analyst needs to acquire volatile data from a compromised Windows server before powering it down for a full disk image. The server is still running, and the analyst has administrative access. Which of the following data types should the analyst prioritize collecting first due to its highly volatile nature?Incident Response and Management
  43. 193.A security analyst is investigating a brute-force attack attempt against an internal SSH server. The firewall logs show numerous failed login attempts originating from a single internal IP address (192.168.1.100) over a short period. This IP address belongs to a developer's workstation. Which phase of the Diamond Model of Intrusion Analysis would focus on identifying the specific tools or techniques used by the attacker from this workstation to perform the brute-force attempts?Vulnerability Management
  44. 194.A vulnerability scan report lists only open ports and service banners for a server, with no information about missing OS patches or installed software versions. Which change to the scan configuration would provide this missing detail?Vulnerability Management
  45. 195.A security team wants to automatically identify known CVEs affecting third-party open-source libraries — including transitive dependencies — that are bundled inside their application's build artifacts. Which practice best addresses this requirement?Vulnerability Management
  46. 196.A security analyst is reviewing a vulnerability report for a public-facing web application. The report identifies a Cross-Site Scripting (XSS) vulnerability with a CVSS score of 7.5 (High). The analyst needs to communicate this finding to the development team for remediation. Which of the following would be the MOST effective way to communicate the technical details and remediation steps?Reporting and Communication
  47. 197.A security analyst is conducting a post-incident review for a successful phishing attack that led to credential compromise. During the 'lessons learned' meeting, the team identifies that the primary control failure was the lack of multi-factor authentication (MFA) on the affected email accounts. Which section of the 'lessons learned' report should detail this specific control gap and its impact?Reporting and Communication
  48. 198.A cybersecurity team is conducting a quarterly review of their vulnerability management program. They have implemented a new process to prioritize and remediate vulnerabilities based on a combined risk score. To assess the effectiveness of this new process, which of the following metrics would be MOST valuable to track over time and present to management?Reporting and Communication
  49. 199.A security analyst is conducting a post-incident review for a successful phishing attack that compromised several user accounts. As part of the 'lessons learned' report, the analyst needs to identify the root cause to prevent future occurrences. The investigation revealed that users clicked malicious links and entered credentials on fake login pages. Which of the following would MOST likely be identified as the root cause?Reporting and Communication
  50. 200.A security analyst is drafting an incident report for an unauthorized access event that resulted in a brief service disruption. The report needs to clearly communicate the impact to technical stakeholders, including network engineers and system administrators. Which of the following details would be MOST important to include to ensure effective technical communication?Reporting and Communication