CompTIA CySA+ (CS0-003) practice questions

231 free questions with answers and explanations.

Practice test
  1. 201.A security analyst is preparing a compliance report for the Payment Card Industry Data Security Standard (PCI DSS) Requirement 11.2, which mandates regular vulnerability scanning. The analyst needs to present evidence that all in-scope systems are scanned quarterly by an internal scanner and annually by an Approved Scanning Vendor (ASV). Which of the following metrics would BEST demonstrate compliance with this requirement?Reporting and Communication
  2. 202.A cybersecurity analyst is preparing a quarterly report for the Chief Information Security Officer (CISO). The CISO has requested a metric that demonstrates the efficiency of the security team in addressing newly identified vulnerabilities. Which of the following Key Performance Indicators (KPIs) would BEST address the CISO's request?Reporting and Communication
  3. 203.A security analyst is drafting a compliance report for the General Data Protection Regulation (GDPR). The organization recently experienced a data breach involving personal data of EU citizens. According to GDPR, specific information must be included in the notification to the supervisory authority. Which of the following pieces of information is NOT a mandatory element of a GDPR breach notification?Reporting and Communication
  4. 204.A security analyst is reviewing logs after a suspected insider threat incident. The analyst observes the following log entries: ``` 2023-10-26 10:15:22 host1 user_A logged in from 192.168.1.50 2023-10-26 10:16:01 host1 user_A accessed /financial_reports/Q4_2023_forecast.xlsx 2023-10-26 10:16:35 host1 user_A copied /financial_reports/Q4_2023_forecast.xlsx to /mnt/usb_drive 2023-10-26 10:17:10 host1 user_A logged out ``` Which of the following metrics would BEST describe the time elapsed from the initial access of the sensitive file to its exfiltration?Reporting and Communication
  5. 205.A security analyst is preparing a quarterly report for the Chief Information Security Officer (CISO). The CISO is particularly interested in understanding the organization's ability to quickly restore normal operations after a disruptive security incident. Which of the following metrics would BEST address the CISO's concern?Reporting and Communication
  6. 206.A security analyst is preparing a compliance report for the General Data Protection Regulation (GDPR). The organization experienced a data breach involving personal data of EU citizens. The analyst needs to ensure the report includes all mandatory information for the supervisory authority. Which of the following pieces of information is NOT explicitly required by GDPR Article 33 for breach notification?Reporting and Communication
  7. 207.A security analyst is reviewing a vulnerability report for a public-facing web application. The report identifies a Cross-Site Scripting (XSS) vulnerability with a CVSS score of 7.5 (High). The analyst needs to communicate this finding to the development team for remediation. Which of the following would be the MOST effective way to communicate the technical details and remediation steps?Reporting and Communication
  8. 208.A security analyst is preparing a compliance report for the Payment Card Industry Data Security Standard (PCI DSS) Requirement 10, which mandates logging and monitoring of all access to cardholder data. The organization uses a SIEM system to aggregate logs. Which of the following log snippets, if consistently missing, would indicate a direct non-compliance with this requirement?Reporting and Communication
  9. 209.A security analyst is conducting a post-incident review for a successful phishing attack that led to credential compromise. During the 'lessons learned' meeting, the team identifies that the primary control failure was the lack of multi-factor authentication (MFA) on the affected email accounts. Which section of the 'lessons learned' report should detail this specific control gap and its impact?Reporting and Communication
  10. 210.A cybersecurity team is conducting a quarterly review of their vulnerability management program. They have implemented a new process to prioritize and remediate vulnerabilities based on a combined risk score. To assess the effectiveness of this new process, which of the following metrics would be MOST valuable to track over time and present to management?Reporting and Communication
  11. 211.A security analyst is conducting a post-incident review for a successful phishing attack that compromised several user accounts. As part of the 'lessons learned' report, the analyst needs to identify the root cause to prevent future occurrences. The investigation revealed that users clicked malicious links and entered credentials on fake login pages. Which of the following would MOST likely be identified as the root cause?Reporting and Communication
  12. 212.A security analyst is drafting an incident report for an unauthorized access event that resulted in a brief service disruption. The report needs to clearly communicate the impact to technical stakeholders, including network engineers and system administrators. Which of the following details would be MOST important to include to ensure effective technical communication?Reporting and Communication
  13. 213.During a monthly security review, a security analyst notes a consistent increase in the number of security alerts generated by the Intrusion Detection System (IDS) that are later classified as false positives. The analyst needs to report this trend to the security operations center (SOC) manager to suggest improvements. Which of the following metrics would BEST illustrate the impact of this trend on SOC efficiency?Reporting and Communication
  14. 214.A security analyst is preparing a quarterly report for the Chief Information Security Officer (CISO) and other executive stakeholders. The report needs to convey the current state of the organization's security posture in a clear, concise, and business-focused manner. Which of the following types of metrics would be MOST appropriate for this audience?Reporting and Communication
  15. 215.A security analyst is preparing a quarterly report for the Chief Information Security Officer (CISO) to highlight the overall security posture and resource allocation effectiveness. The CISO is particularly interested in understanding how efficiently security resources are being utilized to address the most significant threats. Which of the following metrics would BEST address this specific concern?Reporting and Communication
  16. 216.A security analyst is preparing a quarterly report for the Board of Directors. The board is primarily concerned with the strategic impact of cybersecurity on the organization's business objectives and overall resilience. Which of the following KPIs would be MOST suitable for communicating this strategic impact to the board?Reporting and Communication
  17. 217.A security analyst is preparing a quarterly report for the Chief Information Security Officer (CISO) and the board of directors. The report needs to highlight the organization's overall cybersecurity resilience and strategic progress. Which of the following KPIs would be MOST suitable for this high-level audience?Reporting and Communication
  18. 218.A security analyst is reviewing a vulnerability scan report for a new internal application. The report indicates several critical vulnerabilities. The development team, however, argues that these findings are not exploitable in the current production environment due to compensating controls and network segmentation. Which of the following metrics would BEST highlight the actual risk posture to executive leadership?Reporting and Communication
  19. 219.A security analyst is preparing a quarterly report for the Chief Information Security Officer (CISO). The CISO has requested a metric that illustrates the organization's effectiveness in reducing its overall attack surface over time. Which of the following would be the MOST appropriate Key Performance Indicator (KPI) to include?Reporting and Communication
  20. 220.A security analyst is preparing for an annual audit against ISO/IEC 27001. The auditor has requested evidence of the organization's incident management process, specifically how improvements are identified and implemented. Which of the following metrics or reporting elements would BEST demonstrate adherence to the 'continual improvement' aspect of ISO 27001's incident management?Reporting and Communication
  21. 221.A security analyst is preparing a vulnerability report for a development team. The report needs to be actionable and provide sufficient detail for developers to understand and fix the identified issues. Which of the following elements would be MOST critical to include for this audience?Reporting and Communication
  22. 222.A security analyst is tasked with generating a compliance report for the General Data Protection Regulation (GDPR). The organization recently experienced an incident involving unauthorized access to customer data. The report needs to include a metric that demonstrates the organization's commitment to data protection post-incident. Which of the following would be the MOST relevant metric to include for GDPR compliance reporting?Reporting and Communication
  23. 223.A cybersecurity analyst is preparing a quarterly report for the Chief Information Security Officer (CISO) and the Board of Directors. The report aims to demonstrate the organization's progress in reducing its overall attack surface. The organization has recently implemented a strict patching policy, decommissioned several legacy systems, and is enforcing a least privilege model. Which of the following KPIs would BEST illustrate these efforts for a strategic audience?Reporting and Communication
  24. 224.A security analyst is investigating a potential data exfiltration event that originated from an internal server. The analyst suspects a sophisticated attacker utilized DNS tunneling to covertly transfer data. Which of the following network indicators, observed in DNS logs, would provide the STRONGEST evidence of DNS tunneling exfiltration?Reporting and Communication
  25. 225.A security analyst is preparing a vulnerability report for a critical web application that handles sensitive customer data. The report is intended for the development team responsible for fixing the identified vulnerabilities. Which of the following details should be prioritized in the report to ensure effective remediation?Reporting and Communication
  26. 226.A security analyst is preparing a quarterly report for the Chief Information Security Officer (CISO). The CISO wants to understand the organization's adherence to security policies and compliance frameworks. Which of the following KPIs would BEST demonstrate compliance with established security policies?Reporting and Communication
  27. 227.A security operations center (SOC) manager is reviewing Key Performance Indicators (KPIs) to evaluate the effectiveness of their threat intelligence program. The goal is to ensure that threat intelligence is actionable and directly contributes to defensive capabilities. Which of the following metrics would BEST indicate the program's success in achieving this goal?Reporting and Communication
  28. 228.During a post-incident review for a significant data breach, the security team is compiling a 'lessons learned' report. The report needs to clearly articulate the financial impact of the breach to inform future budget allocations and risk assessments. Which of the following components should be included to accurately represent the financial cost?Reporting and Communication
  29. 229.A security analyst is reviewing a vulnerability scan report that lists several critical findings on a web server. One finding indicates that the web server software (Apache HTTP Server) is running an outdated version with a known critical vulnerability. The report recommends upgrading Apache to the latest stable version. Which of the following remediation strategies is MOST effective for this type of vulnerability?Vulnerability Management
  30. 230.A security analyst is investigating a suspected data exfiltration incident from an internal Linux server. The analyst suspects that an attacker may have used a common network utility to establish a reverse shell for data transfer. Which of the following log snippets would be the MOST indicative of this activity?Incident Response and Management
  31. 231.A security analyst is investigating a series of failed login attempts against an internal application. The application's logs show numerous attempts from a single IP address (192.168.1.10) using various usernames and common passwords within a short period. The application is critical, but the attempts have not yet been successful. Which of the following attack frameworks would BEST help the analyst document and understand this specific type of activity?Vulnerability Management