CYSA+ 003 Exam Questions and Answers
with Verified Solutions | Latest Updated 2026
2 Factor Authentication ■ Something you are
■ Something you know
■ Something you have
* New and improved statement on 2 factor
or multi
factor -- Location -- Behaviors (but NIST
doesn't
totally accept this yet)
3 threat model scenarios Corporate network
Websites and Cloud
Internal custom apps
4 key pillars to intelligence CART
gathering Completeness - Accuracy - Relevance -
Timeliness
4 phases of the incident response Preparation
cycle Detection and analysis
Containment
Eradication and recovery
5 functions of NIST Framework Identify
Protect
Detect
Respond
Recover
,Authentication is ■ Digital authentication is usually a user
name and
password
■ User name is identifier (SID) that
computers look
at to authenticate
■ W/passwords you are looking at shared
secret.
■These two items together authenticate
Authorization Based off who you are do you have rights
to this
resource
Best practice for where to store SIEM - Security Information and event
logs management
and rules around the location 2 functions
- act as central local in secure way;
- apply AI/ML to correlate
*** Rules - can create own rules or do
queries -
interpret the meaning behind individual
points in a
query to alert (Conditions with logical
expressions,
full queries to extract, sting search) -
allows on
command to take output and return with
specified
info and can sort and do lots with it.
,Best Practices for Securing Code Goal of SW security is maintain CIA and
should check what areas enable
successful business operations, important
to
understand client side controls don't
provide a
security benefit and security isn't a focus
it's usually
about does it do what's intended
- input validation - output validation -
authentication & password - session
management -
access control - Cryptography practice -
error
handling and logging - data protection -
communication security - system
configuration -
Database security - File Management -
memory
management - general coding practice
, break down a cvss v 3 score what ■ AV - Attack vector - access required to
is exploit;
in base higher exploits can be implemented
remotely vs
physical presence (N-Network, Adjacent,
L-Local,
P-Physical)
■ AC - Attack complexity - based on
what's
required outside attackers control to
exploit;
higher scores require additional attacker
work like a
shared secret key or man in the middle
(low, high)
■ PR - Privileges required - based on
attackers
privileges required to exploit; something
requiring
admin control will have higher score
(N-None, Low,
High)
■ UI - User Interaction - varies based on if
the
attacker needs others willingly or not to
execute;
score is higher is you can attack
autonomously,
with no participation. (none, required)
■ S - Scope - Can the vulnerability
component
prorogate to other components
(Unchanged,
changed)
■ I - Impact - focuses on outcome you can
achieve
with Verified Solutions | Latest Updated 2026
2 Factor Authentication ■ Something you are
■ Something you know
■ Something you have
* New and improved statement on 2 factor
or multi
factor -- Location -- Behaviors (but NIST
doesn't
totally accept this yet)
3 threat model scenarios Corporate network
Websites and Cloud
Internal custom apps
4 key pillars to intelligence CART
gathering Completeness - Accuracy - Relevance -
Timeliness
4 phases of the incident response Preparation
cycle Detection and analysis
Containment
Eradication and recovery
5 functions of NIST Framework Identify
Protect
Detect
Respond
Recover
,Authentication is ■ Digital authentication is usually a user
name and
password
■ User name is identifier (SID) that
computers look
at to authenticate
■ W/passwords you are looking at shared
secret.
■These two items together authenticate
Authorization Based off who you are do you have rights
to this
resource
Best practice for where to store SIEM - Security Information and event
logs management
and rules around the location 2 functions
- act as central local in secure way;
- apply AI/ML to correlate
*** Rules - can create own rules or do
queries -
interpret the meaning behind individual
points in a
query to alert (Conditions with logical
expressions,
full queries to extract, sting search) -
allows on
command to take output and return with
specified
info and can sort and do lots with it.
,Best Practices for Securing Code Goal of SW security is maintain CIA and
should check what areas enable
successful business operations, important
to
understand client side controls don't
provide a
security benefit and security isn't a focus
it's usually
about does it do what's intended
- input validation - output validation -
authentication & password - session
management -
access control - Cryptography practice -
error
handling and logging - data protection -
communication security - system
configuration -
Database security - File Management -
memory
management - general coding practice
, break down a cvss v 3 score what ■ AV - Attack vector - access required to
is exploit;
in base higher exploits can be implemented
remotely vs
physical presence (N-Network, Adjacent,
L-Local,
P-Physical)
■ AC - Attack complexity - based on
what's
required outside attackers control to
exploit;
higher scores require additional attacker
work like a
shared secret key or man in the middle
(low, high)
■ PR - Privileges required - based on
attackers
privileges required to exploit; something
requiring
admin control will have higher score
(N-None, Low,
High)
■ UI - User Interaction - varies based on if
the
attacker needs others willingly or not to
execute;
score is higher is you can attack
autonomously,
with no participation. (none, required)
■ S - Scope - Can the vulnerability
component
prorogate to other components
(Unchanged,
changed)
■ I - Impact - focuses on outcome you can
achieve