CompTIA Cybersecurity Analyst (CySA+)
Mega Study guide Exam Questions and
Answers with Verified Solutions | Latest
Updated 2026
SSRF Server-side request forgery
- Security vulnerability in which a hacker
tricks a
server into accessing unintended
resources on his
behalf
RCE Counters Remote Code Execution Counters
- Sanitize user input
- Secure app memory management
- Inspect network traffic
XSS Cross-site scripting - type of injection, in
which
malicious scripts are injected into
otherwise benign
and trusted websites
XSS Counters Cross-site scripting counters
- Don't trust your users
- Output encoding
- HTML Sanitization/Java Sanitization
- Input sanitization
- WAF
,Clear, Purge, and Destroy (NIST) Clear - Applies standard r/w commands,
techniques, and tools to overwrite data
found in all
user-accessible storage locations
- Only uses logical techniques
Purge - Physical or logical techniques that
renders
target data recovery infeasible using
state-of-the-
art lab overwrite, block erase, and crypto
erase
methods
- Higher level of sanitization than clear
Destroy - Renders target data recovery
infeasible
using physical destruction techniques,
shredding,
smelting, pulverising, and incinerating
Strings File Analysis Tool
- ASCII & Unicode - Printable sequence of
characters embedded within a file
- Linux
Hashing File Analysis Tool
- Uniquely identifies the data in the file
- "md5sum" or "sha256sum"
, VirusTotal File Analysis Tool
- Analyzes files & URLS for viruses,
worms, trojans,
& other kinds of malicious content
- Checks hashes against known malicious
file
hashes in a database
EDR Endpoint Detection and Response
- Utilizes ML, behavioral analysis, and
threat
hunting to detect malicious/suspicious
activiy
- Detects sophisticated and targeted
attacks
- Also blocks and alerts
- EDR detects and responds to malware
that makes
it past AV
- AV prevents malware from infecting
endpoints
OSS TMM Open Source Security Testing
Methodology
Manual
- Structured approach across different
areas like
apps, networks, and systems
OWASP Open Web Application Security Project
- Framework for web app security testing
Mega Study guide Exam Questions and
Answers with Verified Solutions | Latest
Updated 2026
SSRF Server-side request forgery
- Security vulnerability in which a hacker
tricks a
server into accessing unintended
resources on his
behalf
RCE Counters Remote Code Execution Counters
- Sanitize user input
- Secure app memory management
- Inspect network traffic
XSS Cross-site scripting - type of injection, in
which
malicious scripts are injected into
otherwise benign
and trusted websites
XSS Counters Cross-site scripting counters
- Don't trust your users
- Output encoding
- HTML Sanitization/Java Sanitization
- Input sanitization
- WAF
,Clear, Purge, and Destroy (NIST) Clear - Applies standard r/w commands,
techniques, and tools to overwrite data
found in all
user-accessible storage locations
- Only uses logical techniques
Purge - Physical or logical techniques that
renders
target data recovery infeasible using
state-of-the-
art lab overwrite, block erase, and crypto
erase
methods
- Higher level of sanitization than clear
Destroy - Renders target data recovery
infeasible
using physical destruction techniques,
shredding,
smelting, pulverising, and incinerating
Strings File Analysis Tool
- ASCII & Unicode - Printable sequence of
characters embedded within a file
- Linux
Hashing File Analysis Tool
- Uniquely identifies the data in the file
- "md5sum" or "sha256sum"
, VirusTotal File Analysis Tool
- Analyzes files & URLS for viruses,
worms, trojans,
& other kinds of malicious content
- Checks hashes against known malicious
file
hashes in a database
EDR Endpoint Detection and Response
- Utilizes ML, behavioral analysis, and
threat
hunting to detect malicious/suspicious
activiy
- Detects sophisticated and targeted
attacks
- Also blocks and alerts
- EDR detects and responds to malware
that makes
it past AV
- AV prevents malware from infecting
endpoints
OSS TMM Open Source Security Testing
Methodology
Manual
- Structured approach across different
areas like
apps, networks, and systems
OWASP Open Web Application Security Project
- Framework for web app security testing