• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 3 out of 24 pages
Exam (elaborations)

CompTIA CySA+ Practice Exam Questions And Correct Answers (Verified Answers) Plus Rationales 2025/2026 Q&A | Instant Download Pdf

Document preview thumbnail
Preview 3 out of 24 pages

1. Which of the following best describes the purpose of a SIEM system? A. To perform penetration testing B. To collect and analyze security event logs C. To encrypt stored data D. To manage user accounts SIEM (Security Information and Event Management) aggregates logs and events from multiple sources for correlation and threat detection. 2. What is the main goal of threat hunting? A. Automate malware detection B. Proactively search for threats that evade existing defenses C. Replace antivirus software D. Improve network performance Threat hunting identifies threats not caught by automated tools.

Content preview

CompTIA CySA+ Practice Exam Questions
And Correct Answers (Verified Answers)
Plus Rationales 2025/2026 Q&A | Instant
Download Pdf

1. Which of the following best describes the purpose of a SIEM system?
A. To perform penetration testing
B. To collect and analyze security event logs
C. To encrypt stored data
D. To manage user accounts
SIEM (Security Information and Event Management) aggregates logs and
events from multiple sources for correlation and threat detection.


2. What is the main goal of threat hunting?
A. Automate malware detection
B. Proactively search for threats that evade existing defenses
C. Replace antivirus software
D. Improve network performance
Threat hunting identifies threats not caught by automated tools.


3. A cybersecurity analyst notices unusual outbound traffic to an unknown IP
address. What should be done first?
A. Block the IP address
B. Validate and analyze the traffic
C. Disconnect the system from the network
D. Notify law enforcement
Analysts should first confirm the legitimacy of the traffic before taking action.

,4. What does CVSS stand for in vulnerability management?
A. Centralized Vulnerability Scoring System
B. Common Vulnerability Scoring System
C. Cybersecurity Vulnerability Scanning System
D. Computer Virus Scoring System
CVSS standardizes the severity rating of vulnerabilities.


5. Which attack uses a large number of compromised devices to flood a
network?
A. Phishing
B. Distributed Denial of Service (DDoS)
C. SQL Injection
D. Cross-site Scripting
DDoS attacks use multiple compromised systems to overwhelm a target.


6. What is the primary benefit of network segmentation?
A. Reduces encryption needs
B. Increases latency
C. Limits lateral movement of attackers
D. Simplifies authentication
Segmentation confines attacks to smaller network zones.


7. Which of the following best defines a false positive in IDS alerts?
A. A real attack missed by the system
B. Benign activity flagged as malicious
C. A real attack correctly identified
D. A missed alert
False positives occur when legitimate activity is incorrectly flagged.


8. What is the main function of a vulnerability scanner?

, A. Apply patches automatically
B. Identify potential weaknesses in systems
C. Perform brute-force attacks
D. Encrypt network data
Vulnerability scanners find potential flaws before exploitation.


9. Which type of malware encrypts files and demands payment?
A. Worm
B. Trojan
C. Ransomware
D. Rootkit
Ransomware locks or encrypts files until a ransom is paid.


10. What does the term “data exfiltration” mean?
A. Inbound data flooding
B. Unauthorized transfer of data outside the network
C. Data encryption at rest
D. Data loss from backup failure
Data exfiltration involves the theft of sensitive information.


11. Which of these best describes “threat intelligence”?
A. A firewall configuration
B. Information about potential and active threats
C. A password policy
D. A SIEM report
Threat intelligence provides context about adversaries and their tactics.


12. Which framework focuses on identifying, protecting, detecting,
responding, and recovering?
A. ISO 27001
B. COBIT
C. NIST Cybersecurity Framework

Document information

Uploaded on
November 24, 2025
Number of pages
24
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$23.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
lewizranking
3.3
(8)
Sold
45
Followers
3
Items
5741
Last sold
4 hours ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions