Step2Study
IT & TechnologyCS0-003100% Free

CompTIA CySA+ (CS0-003)

Practice bank
231 Qs
Real exam
85 Qs
Time limit
165 min
Passing
750 on a 100–900 scale

Exam blueprint

Security Operations
33%
Vulnerability Management
30%
Incident Response and Management
20%
Reporting and Communication
17%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 90 questions each · 175 min · pass 83% · 231 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Part of a learning path

Study with friends

Challenge a friend to beat your score.

CompTIA CySA+ (CS0-003) practice test questions

Sample questions from the 231-question bank, with answers and explanations.

All questions
  1. 1. A web application firewall log shows the following request against a public e-commerce site: `192.168.1.15 - - [10/Mar/2024:14:22:07 +0000] "GET /products.php?id=1' UNION SELECT username,password FROM users-- HTTP/1.1" 200 1523` Which type of attack does this log entry MOST likely indicate?

    Security Operations

    • A. Command injection
    • B. Directory traversal
    • C. SQL injection
    • D. Cross-site scripting (XSS)
    Show answer

    C. SQL injection

    The request injects a `UNION SELECT` statement into the `id` parameter, attempting to append a second query that pulls usernames and passwords from the `users` table — a textbook SQL injection technique. The trailing `--` comments out the rest of the original query to keep the syntax valid.

  2. 2. An incident responder is using the Diamond Model of Intrusion Analysis to document an attack. The team identifies the malicious IP address 203.0.113.55 that hosted the phishing page and later received stolen credentials. Within the Diamond Model, which core feature does this IP address represent?

    Vulnerability Management

    • A. Capability
    • B. Infrastructure
    • C. Victim
    • D. Adversary
    Show answer

    B. Infrastructure

    In the Diamond Model, Infrastructure refers to the physical or logical resources the adversary uses to deliver a capability or maintain communication, such as IP addresses, domains, and servers — exactly what the phishing-hosting IP represents.

  3. 3. A security analyst is reviewing a vulnerability scan report for a fleet of Windows servers. The report flags several servers as missing critical security updates for the operating system and various installed applications. The organization needs a method to automate the deployment of these patches across all affected servers while minimizing manual effort. Which solution is best suited for this task?

    Vulnerability Management

    • A. Patch Management System
    • B. Security Information and Event Management (SIEM)
    • C. Data Loss Prevention (DLP)
    • D. Vulnerability Management System (VMS)
    Show answer

    A. Patch Management System

    A Patch Management System is specifically designed to automate the process of identifying, downloading, testing, and deploying patches and updates across an organization's IT infrastructure, directly addressing the requirement to automate patch deployment for missing security updates.

  4. 4. An incident responder documents an attack using the Diamond Model of Intrusion Analysis. In the report, they record the C2 domain name, the hosting provider's IP address, and the compromised relay server used to route traffic to the attacker. Which core feature (vertex) of the Diamond Model does this information populate?

    Vulnerability Management

    • A. Victim
    • B. Capability
    • C. Adversary
    • D. Infrastructure
    Show answer

    D. Infrastructure

    The Diamond Model's Infrastructure vertex captures the physical or logical communication structures the adversary uses to deliver capabilities and maintain control, such as domains, IP addresses, and relay/proxy servers. Adversary refers to the threat actor, Capability to the tools/malware/techniques used, and Victim to the targeted organization or asset.

  5. 5. During an incident, an analyst identifies that an attacker used a phishing email for initial access, then leveraged a scheduled task for persistence, and finally used PsExec to move laterally to a file server. The analyst wants to document this behavior using a standardized adversary behavior framework for the incident report. Which framework should be used?

    Security Operations

    • A. NIST Cybersecurity Framework (CSF)
    • B. CVSS scoring framework
    • C. MITRE ATT&CK
    • D. Diamond Model of Intrusion Analysis
    Show answer

    C. MITRE ATT&CK

    MITRE ATT&CK is a knowledge base of adversary tactics and techniques (e.g., Initial Access, Persistence, Lateral Movement) used to categorize observed behaviors like phishing, scheduled tasks, and PsExec usage into standardized TTPs.

  6. 6. A development team is building a new mobile application that will handle sensitive customer data. They want to identify security vulnerabilities such as hardcoded credentials, insecure configuration, and potential injection flaws early in the development lifecycle, without actually running the application. Which testing methodology is best suited for this purpose?

    Vulnerability Management

    • A. Dynamic Application Security Testing (DAST)
    • B. Static Application Security Testing (SAST)
    • C. Interactive Application Security Testing (IAST)
    • D. Software Composition Analysis (SCA)
    Show answer

    B. Static Application Security Testing (SAST)

    Static Application Security Testing (SAST) analyzes an application's source code, bytecode, or binary code without executing it. This allows for the identification of vulnerabilities such as hardcoded credentials, insecure configurations, and injection flaws early in the SDLC, aligning perfectly with the requirement to find flaws 'without actually running the application'.

  7. 7. A cyber incident response team has successfully contained a sophisticated persistent threat (APT) from their network. They are now in the post-incident activity phase. Which of the following activities is MOST crucial for improving the organization's future security posture based on this incident?

    Incident Response and Management

    • A. Update the incident response plan to reflect new procedures.
    • B. Archive all incident logs and forensic images for future reference.
    • C. Train all employees on advanced phishing detection techniques.
    • D. Conduct a lessons learned meeting with all involved stakeholders.
    Show answer

    D. Conduct a lessons learned meeting with all involved stakeholders.

    A 'lessons learned' meeting is the most crucial activity as it facilitates a comprehensive review of the entire incident, identifies what worked and what didn't, and gathers insights from all stakeholders to drive actionable improvements across processes, technologies, and training.

  8. 8. A cloud security architect wants to prevent lateral movement between application workloads that reside on the same subnet by enforcing granular, workload-level firewall policies instead of relying solely on VLAN boundaries. Which architectural concept BEST describes this approach?

    Security Operations

    • A. Air-gapped network
    • B. Network address translation (NAT)
    • C. Demilitarized zone (DMZ)
    • D. Microsegmentation
    Show answer

    D. Microsegmentation

    Microsegmentation applies fine-grained, identity- or workload-based security policies down to the individual host or application level, restricting east-west traffic even within the same subnet or VLAN. A DMZ isolates public-facing services from the internal network, an air gap physically isolates a network entirely, and NAT translates addresses rather than enforcing segmentation policy.

  9. 9. A security analyst discovers a critical vulnerability in a production web application that has a CVSSv3 base score of 9.8. The vulnerability allows unauthenticated remote code execution. The development team is currently focused on a major feature release. Which stakeholder group should be immediately informed, emphasizing the potential for data breach and service unavailability, to ensure prompt prioritization and resource allocation for remediation?

    Reporting and Communication

    • A. Human Resources department
    • B. Legal department
    • C. Executive leadership and application owners
    • D. End-users of the web application
    Show answer

    C. Executive leadership and application owners

    Executive leadership and application owners have the authority to re-prioritize development efforts and allocate resources. They need to understand the critical business impact (data breach, service unavailability) to make informed decisions.

  10. 10. A vulnerability management team must choose which finding to remediate first this week. Vulnerability A has a CVSS Base Score of 7.5, appears on the CISA Known Exploited Vulnerabilities (KEV) catalog, and affects an internet-facing VPN appliance. Vulnerability B has a CVSS Base Score of 9.1 but affects an internal file server with no known exploitation activity. Which vulnerability should be prioritized first, and why?

    Vulnerability Management

    • A. Both should be scheduled with equal priority since their CVSS scores are within two points of each other
    • B. Vulnerability B, because a higher CVSS score always takes precedence regardless of other factors
    • C. Vulnerability A, because active in-the-wild exploitation and internet exposure increase real-world risk despite the lower base score
    • D. Vulnerability B, because internal systems must always be patched before external systems
    Show answer

    C. Vulnerability A, because active in-the-wild exploitation and internet exposure increase real-world risk despite the lower base score

    Risk-based prioritization considers exploitability in the wild (KEV listing) and exposure (internet-facing) alongside CVSS severity; a lower-scored but actively exploited, externally reachable vulnerability typically represents greater real-world risk than a higher-scored but unexploited internal one.

  11. 11. Employees on a corporate segment suddenly lose network connectivity. An analyst captures traffic and sees that for a single DHCPDISCOVER broadcast, two DHCPOFFER messages are returned from two different MAC addresses, one of which is not on the approved switch port list, and clients receiving that offer are assigned an incorrect default gateway. Which activity does this indicate?

    Security Operations

    • A. DNS spoofing
    • B. ARP spoofing
    • C. DHCP starvation attack
    • D. Rogue DHCP server
    Show answer

    D. Rogue DHCP server

    An unauthorized device answering DHCP requests with its own configuration (often pointing clients to a malicious gateway) is a rogue DHCP server, typically used to enable man-in-the-middle attacks. DHCP starvation floods the legitimate server with fake requests to exhaust its address pool rather than issuing false offers itself, and ARP/DNS spoofing operate on different protocols.

  12. 12. An analyst reviewing authentication logs from a public-facing web application finds the following pattern from a single source IP over 10 minutes: 5,000 login attempts against 3,200 distinct usernames, with each username attempted only one or two times using a unique password, followed by 12 successful logins to different accounts. Which attack technique does this pattern indicate?

    Security Operations

    • A. Password spraying
    • B. Credential stuffing
    • C. Brute-force attack
    • D. Kerberoasting
    Show answer

    B. Credential stuffing

    Credential stuffing uses large lists of previously breached username:password pairs, so each unique username is tried with only one or two specific (not common) passwords rather than many passwords against one account (brute force) or one common password against many accounts (password spraying); the resulting successes reflect users who reused breached credentials. Kerberoasting targets Kerberos service ticket hashes and would not appear as web login attempts.

  13. 13. A threat intelligence team wants to automatically share and receive structured indicators of compromise (IOCs) with an information sharing and analysis center (ISAC) using a standardized, machine-readable format transported over a defined exchange protocol. Which pair of standards should the team implement?

    Security Operations

    • A. OpenIOC over FTP
    • B. CVSS over HTTP
    • C. YARA rules over SMTP
    • D. STIX over TAXII
    Show answer

    D. STIX over TAXII

    STIX (Structured Threat Information eXpression) defines the standardized, machine-readable format for describing threat intelligence, while TAXII (Trusted Automated eXchange of Indicator Information) defines the protocol for transporting that data between organizations—together the industry standard for automated sharing.

  14. 14. A security analyst is drafting an incident report for a successful ransomware attack that encrypted several critical file servers. The incident response team managed to recover all data from backups and restore services within 24 hours. The report needs to highlight the effectiveness of the incident response plan and the team's performance. Which of the following KPIs would be MOST appropriate to demonstrate this success to management?

    Reporting and Communication

    • A. Number of security awareness training sessions conducted.
    • B. Total number of ransomware variants detected.
    • C. Mean Time To Recover (MTTR) for critical services.
    • D. Percentage of endpoint detection and response (EDR) agents deployed.
    Show answer

    C. Mean Time To Recover (MTTR) for critical services.

    Mean Time To Recover (MTTR) directly measures how quickly an organization can restore services after an incident. A MTTR of 24 hours for a ransomware attack demonstrates highly effective incident response and recovery capabilities.

  15. 15. During a monthly security review, a security analyst notes a consistent increase in the number of successful brute-force attacks against SSH services, despite existing lockout policies. The analyst needs to communicate this trend to the network operations team to prompt a configuration change. Which of the following communication methods is MOST effective for conveying technical details and facilitating immediate action?

    Reporting and Communication

    • A. An email to the network operations team manager summarizing the trend.
    • B. A presentation during the quarterly CISO briefing highlighting the risk.
    • C. A casual mention in a team chat with a link to a dashboard.
    • D. A formal incident report submitted through the ticketing system with detailed logs.
    Show answer

    D. A formal incident report submitted through the ticketing system with detailed logs.

    A formal incident report submitted through a ticketing system provides a structured way to convey technical details, attach relevant logs, assign ownership, and track remediation, which is crucial for facilitating immediate and documented action by the network operations team.

  16. 16. A network administrator runs an Nmap SYN scan across the 10.1.5.0/24 subnet, sending probe packets directly to each address to identify live hosts, open ports, and service versions for an updated asset inventory. Which asset discovery technique does this describe?

    Vulnerability Management

    • A. Active discovery
    • B. Passive discovery
    • C. NetFlow analysis
    • D. Agent-based discovery
    Show answer

    A. Active discovery

    Active discovery involves sending probe packets (pings, SYN packets, port scans) directly to hosts to enumerate devices and services, unlike passive discovery which only observes existing traffic.

  17. 17. A security analyst is reviewing a custom web application's access logs and identifies the following requests originating from a single IP address (10.10.10.5): ``` GET /api/v1/users?search=admin%27%20OR%20%271%27%3D%271 HTTP/1.1 GET /api/v1/products?category=electronics%27%3B%20WAITFOR%20DELAY%20%270%3A0%3A5%27--%20 HTTP/1.1 GET /api/v1/orders?id=123%20AND%20SUBSTRING%28version%28%29%2C1%2C1%29%3D%275%27 HTTP/1.1 ``` Which type of attack is being attempted, and what specific variant is indicated by the second and third entries?

    Security Operations

    • A. Command Injection; OS Command Injection
    • B. Cross-Site Scripting (XSS); Reflected XSS
    • C. XML External Entity (XXE); Out-of-band XXE
    • D. SQL Injection; Time-based Blind SQL Injection
    Show answer

    D. SQL Injection; Time-based Blind SQL Injection

    The requests show classic SQL injection payloads: `admin' OR '1'='1` (boolean-based), `WAITFOR DELAY` (time-based), and `SUBSTRING(version(),1,1)='5'` (error/boolean-based). Specifically, the `WAITFOR DELAY` command indicates a time-based blind SQL injection, where the attacker infers information based on the server's response time. The `SUBSTRING` query combined with a conditional check also suggests a blind SQL injection variant.

  18. 18. A security analyst discovers a critical misconfiguration on a production web server that exposes sensitive customer data. The analyst needs to communicate this finding to the server owner and management. Which of the following elements is MOST crucial to include in the initial communication to ensure the issue is understood and prioritized correctly?

    Reporting and Communication

    • A. The potential business impact (e.g., data breach, regulatory fines) and severity rating.
    • B. The specific steps to reproduce the misconfiguration and proof of concept (PoC) code.
    • C. A detailed history of the server's patching schedule for the last year.
    • D. A list of all previous misconfigurations found on other servers.
    Show answer

    A. The potential business impact (e.g., data breach, regulatory fines) and severity rating.

    For management and server owners, understanding the potential business impact (financial, reputational, legal) and the severity rating (e.g., CVSS score or internal rating) is paramount. This information directly influences their prioritization and resource allocation for remediation, rather than technical reproduction steps or historical data.

  19. 19. A security analyst is investigating a suspected insider threat. The analyst needs to collect volatile data from a running Windows server without altering the system state unnecessarily. Which of the following data types should be collected FIRST due to its ephemeral nature?

    Incident Response and Management

    • A. Hard drive contents (full disk image)
    • B. System memory (RAM dump)
    • C. Network traffic captures (PCAPs)
    • D. Registry hives and configuration files
    Show answer

    B. System memory (RAM dump)

    System memory (RAM) is the most volatile data and contains crucial information about running processes, network connections, and open files that would be lost immediately if the system were shut down or rebooted. Therefore, it should be collected first.

  20. 20. A malware analyst detonates a sample in an automated sandbox but observes no malicious behavior in the report. Manual analysis of the binary reveals a call to GetTickCount followed by a conditional branch that terminates the process if execution time appears too short. Which sandbox evasion technique is being used?

    Security Operations

    • A. API hammering to overwhelm the analysis engine
    • B. Environment fingerprinting via registry key checks
    • C. Timing-based evasion to detect accelerated or short-lived sandbox execution
    • D. Process hollowing to hide the payload inside a legitimate process
    Show answer

    C. Timing-based evasion to detect accelerated or short-lived sandbox execution

    Checking elapsed time (via GetTickCount) and terminating if execution appears too fast is a timing-based evasion technique; malware assumes sandboxes have limited analysis windows or accelerated clocks, so it stalls or exits to avoid revealing behavior.

  21. 21. A threat intelligence analyst rates an external feed source as 'B2' when logging a new indicator, meaning the source is usually reliable and the information is probably true. Which evaluation system is being used to grade the source and the information?

    Security Operations

    • A. MITRE ATT&CK Navigator
    • B. STIX confidence levels
    • C. Traffic Light Protocol (TLP)
    • D. Admiralty Code
    Show answer

    D. Admiralty Code

    The Admiralty Code (also called the NATO System) grades intelligence using a letter (A-F) for source reliability and a number (1-6) for information credibility, so 'B2' means a usually reliable source providing probably true information. STIX confidence levels are numeric scores in threat intel objects, MITRE ATT&CK Navigator visualizes adversary techniques, and TLP governs how information may be shared rather than its reliability.

  22. 22. A security analyst is investigating a suspected data exfiltration incident. Reviewing proxy logs, the analyst observes a large volume of outbound traffic from an internal host (10.10.10.50) to an external IP address (203.0.113.10) on a non-standard port, but the traffic appears to be legitimate HTTP/S. Further inspection of the traffic reveals highly obfuscated data within the HTTP User-Agent and Accept-Language headers. What type of exfiltration technique is most likely being employed?

    Security Operations

    • A. DNS Tunneling
    • B. SMB Relay
    • C. ICMP Tunneling
    • D. HTTP/HTTPS Tunneling
    Show answer

    D. HTTP/HTTPS Tunneling

    HTTP/HTTPS tunneling involves encapsulating other protocols or data within HTTP/HTTPS traffic to bypass firewalls and proxy servers. The use of non-standard ports and obfuscated data within HTTP headers are strong indicators of this technique.

  23. 23. A security analyst is preparing a quarterly report on the organization's security posture for the Board of Directors. The board is primarily interested in high-level trends and the overall effectiveness of security investments. Which of the following Key Performance Indicators (KPIs) would be MOST appropriate to include in this report?

    Reporting and Communication

    • A. Percentage of security patches applied within 48 hours for critical systems.
    • B. Average time to detect (MTTD) and contain (MTTC) critical incidents.
    • C. Count of daily blocked intrusion attempts by the Web Application Firewall (WAF).
    • D. Number of successful phishing emails reported by employees.
    Show answer

    B. Average time to detect (MTTD) and contain (MTTC) critical incidents.

    The Board of Directors needs strategic insights into overall security program effectiveness. MTTD and MTTC for critical incidents provide a holistic view of the organization's ability to respond to significant threats, directly reflecting the return on security investments in a way that is understandable at a high level. Other options are too granular or focused on specific operational aspects.

  24. 24. A security analyst is investigating a suspected data exfiltration incident. The attacker used a compromised user account to log into a critical server and then attempted to transfer a large file to an external IP address. The analyst has identified the compromised account and the external IP. Which of the following actions represents the BEST long-term containment strategy for this specific threat?

    Incident Response and Management

    • A. Force a password reset for all user accounts.
    • B. Implement a Data Loss Prevention (DLP) solution.
    • C. Disable the compromised user account immediately.
    • D. Block the external IP address at the perimeter firewall.
    Show answer

    B. Implement a Data Loss Prevention (DLP) solution.

    While disabling the account and blocking the IP are immediate containment, a DLP solution offers long-term containment by actively monitoring and preventing unauthorized data transfers, regardless of which account is compromised or which external IP is used, addressing the root problem of data exfiltration attempts.

  25. 25. An analyst reviewing endpoint logs finds the following PowerShell command executed by a non-administrative user: powershell.exe -NoP -NonI -W Hidden -Enc SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAn... Which characteristic of this command is the STRONGEST indicator of malicious intent?

    Security Operations

    • A. The Base64-encoded command combined with hidden window and download activity
    • B. The .exe file extension present in the process name
    • C. The command was run by a non-administrative user account
    • D. The use of the -NoP (NoProfile) flag to speed up execution
    Show answer

    A. The Base64-encoded command combined with hidden window and download activity

    Base64-encoded PowerShell (-Enc) combined with a hidden window (-W Hidden) is a common obfuscation and living-off-the-land technique used to conceal a downloader/execution payload, strongly indicating malicious intent versus benign scripting.

CompTIA CySA+ (CS0-003) flashcards

Tap a card to flip it. 190 flashcards in the full deck.

  • SQL Injection Indicator

    Flip card

    An attack technique where malicious SQL syntax is inserted into an input field to manipulate backend database queries.

    • UNION SELECT combines results from an injected query
    • Trailing -- or # comments out remaining original SQL
    • Often targets parameters like id, search, or login fields
    Study this card →
  • Diamond Model of Intrusion Analysis

    Flip card

    An analytic framework describing an intrusion event through four core features: Adversary, Capability, Infrastructure, and Victim.

    • Adversary = the threat actor/group
    • Capability = tools, malware, exploits used
    • Infrastructure = IPs, domains, servers used by attacker
    Study this card →
  • Patch Management System

    Flip card

    A Patch Management System is a software solution that automates the process of managing and deploying software updates and security patches across an organization's network.

    • Streamlines the patching process from discovery to deployment.
    • Helps ensure systems are up-to-date with the latest security fixes.
    • Often includes features for scheduling, testing, and reporting on patch status.
    Study this card →
  • Diamond Model: Infrastructure

    Flip card

    One of the four core Diamond Model features, representing the physical/logical communication resources (domains, IPs, servers) an adversary uses to deliver capabilities.

    • Four core features: Adversary, Capability, Infrastructure, Victim
    • Infrastructure includes C2 domains, IPs, and relay/proxy servers
    • Connects Adversary to Victim in the intrusion event
    Study this card →
  • MITRE ATT&CK Framework

    Flip card

    A globally accessible knowledge base of adversary tactics and techniques based on real-world observations, used to categorize and communicate attacker behavior (TTPs).

    • Organized into tactics (the 'why') and techniques (the 'how')
    • Covers Initial Access, Execution, Persistence, Lateral Movement, etc.
    • Widely used for threat hunting, detection engineering, and reporting
    Study this card →
  • Static Application Security Testing (SAST)

    Flip card

    SAST is a white-box testing methodology that analyzes an application's source code, bytecode, or binary code for vulnerabilities without executing the application.

    • Identifies flaws early in the Software Development Lifecycle (SDLC).
    • Can find issues like injection flaws, hardcoded credentials, and insecure configurations.
    • Does not require a running application, making it suitable for developers.
    Study this card →
  • Post-Incident Activity

    Flip card

    The final phase of incident response focused on improving security posture and response capabilities based on lessons learned from an incident.

    • Includes lessons learned meetings.
    • Updates incident response plans.
    • Aims for continuous improvement.
    Study this card →
  • Microsegmentation

    Flip card

    A security architecture technique that isolates individual workloads or applications with granular policies to limit lateral movement, even within the same network segment.

    • Goes beyond VLAN/subnet-level isolation
    • Commonly implemented via software-defined networking (SDN)
    • Reduces blast radius of a compromised workload
    Study this card →
  • Executive Stakeholder Communication

    Flip card

    The process of informing and engaging senior management and business owners about cybersecurity risks, incidents, and remediation efforts, focusing on business impact and strategic decisions.

    • Prioritizes business context over technical jargon.
    • Aims to secure resources and approval for security initiatives.
    • Essential for managing high-impact risks effectively.
    Study this card →
  • Risk-Based Prioritization (KEV Catalog)

    Flip card

    Remediation prioritization approach that factors in real-world exploitation evidence (e.g., CISA KEV catalog) and asset exposure, not just CVSS severity.

    • CISA KEV lists vulnerabilities confirmed to be exploited in the wild
    • Internet-facing assets carry higher exposure risk than internal-only assets
    • Combines exploitability, exposure, and asset value with CVSS for prioritization
    Study this card →
  • Rogue DHCP Server

    Flip card

    An unauthorized device on the network that responds to DHCP requests with its own lease information, often redirecting victims' default gateway or DNS server to attacker-controlled infrastructure.

    • Detected by seeing multiple DHCPOFFER from unexpected MAC/switch ports
    • Mitigated with DHCP snooping on switches
    • Often paired with man-in-the-middle attacks
    Study this card →
  • Credential Stuffing

    Flip card

    An attack that uses large sets of previously breached username:password pairs against a login portal, relying on password reuse across sites to gain unauthorized access.

    • Each username is typically tried with its known specific password, not many guesses
    • High volume of distinct accounts attempted, low attempts per account
    • Mitigated with MFA, breach password screening, and rate limiting
    Study this card →
  • STIX/TAXII

    Flip card

    STIX is a standardized language for representing cyber threat intelligence; TAXII is the protocol used to exchange STIX data between organizations automatically.

    • STIX = data format (JSON-based)
    • TAXII = transport protocol (REST API-based)
    • Enables automated, machine-to-machine threat intel sharing
    Study this card →
  • Mean Time To Recover (MTTR)

    Flip card

    The average time it takes to fully restore systems, applications, and services to normal operating conditions after a failure or incident.

    • Crucial for business continuity and disaster recovery.
    • Lower MTTR indicates effective recovery processes and resources.
    • Often a key metric in incident response reporting to management.
    Study this card →
  • Technical Communication

    Flip card

    The process of conveying complex security details, findings, or recommendations to technical stakeholders to enable informed decision-making and action.

    • Requires precision and supporting evidence.
    • Should facilitate clear understanding and actionable steps.
    • Often uses ticketing systems or formal reports for tracking.
    Study this card →
  • Active Asset Discovery

    Flip card

    A discovery method that sends probe traffic (ping sweeps, port scans) directly to hosts to identify live systems and services.

    • Uses tools like Nmap, Masscan
    • Generates network traffic that can be detected by IDS
    • More thorough than passive but can disrupt fragile systems like ICS
    Study this card →
  • Blind SQL Injection

    Flip card

    Blind SQL Injection (SQLi) is a type of SQL injection where the attacker cannot see the results of their malicious query directly within the application's response. Instead, they infer information by observing the application's behavior (e.g., response times, error messages, or subtle differences in content) to determine if a condition is true or false.

    • No direct data retrieval in the response.
    • Relies on server behavior (time delays, error messages, boolean logic).
    • Includes Boolean-based, Error-based, and Time-based variants.
    Study this card →
  • Business Impact Communication

    Flip card

    Translating technical security findings into understandable business risks and consequences for non-technical stakeholders, enabling informed decision-making.

    • Focus on financial, reputational, and legal implications.
    • Use clear, concise language.
    • Tie findings to organizational goals and regulatory compliance.
    Study this card →
  • Order of Volatility

    Flip card

    A hierarchy of digital evidence based on how quickly it can be lost or altered, guiding collection priorities.

    • Most volatile data collected first.
    • RAM is typically the most volatile.
    • Disk data is less volatile than RAM.
    Study this card →
  • Timing-Based Sandbox Evasion

    Flip card

    A technique where malware measures elapsed execution time (e.g., via GetTickCount or sleep calls) and withholds malicious behavior if the runtime appears too short, suspecting an automated sandbox.

    • Sandboxes often have limited analysis windows (seconds to minutes)
    • Malware may sleep or check timers to outlast automated analysis
    • Extended/dynamic sandbox timeouts help counter this evasion
    Study this card →
  • Admiralty Code

    Flip card

    A two-part rating system used to evaluate intelligence: a letter (A-F) rates source reliability, and a number (1-6) rates the credibility of the information itself.

    • A=Completely reliable through F=Reliability cannot be judged
    • 1=Confirmed through 6=Cannot be judged
    • Widely used in military and cyber threat intelligence to grade feeds
    Study this card →
  • HTTP/HTTPS Tunneling

    Flip card

    A technique where non-HTTP/S traffic or data is encapsulated within HTTP/HTTPS requests and responses to bypass network security controls.

    • Bypasses firewalls/proxies by blending with legitimate web traffic.
    • Often uses non-standard ports or obfuscated data in headers/payloads.
    • Commonly used for C2 communication or data exfiltration.
    Study this card →
  • Board-Level Security KPIs

    Flip card

    High-level metrics that demonstrate the overall effectiveness of the security program and the value of security investments to the Board of Directors.

    • Focus on risk reduction, strategic impact, and program maturity.
    • Avoid excessive technical detail.
    • Examples include incident response times, compliance status, and overall risk posture.
    Study this card →
  • Long-Term Containment

    Flip card

    Strategies implemented to prevent recurrence or further spread of an incident over an extended period.

    • Goes beyond immediate isolation.
    • Often involves policy changes, new security controls.
    • Aims to address root causes.
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.