1
CompTIA CySA+ (CS0003)
Practice Exam
Comprehensive 150-
Question Practice Test
with Answers and
Rationales a well
detailed one 2025 /
2026 written and graded
A+ upgraded
, 2
Exam Domain Weighting (CS0-003):
• Security Operations — 33% (50 questions)
• Vulnerability Management — 30% (45 questions)
• Incident Response and Management — 20% (30 questions)
• Reporting and Communication — 17% (25 questions)
DOMAIN 1: SECURITY OPERATIONS (33%)
System and Network Architecture & Log Ingestion
1. A security analyst is reviewing SIEM logs and notices that authentication logs from a critical
Linux server are not being received. The server is online and network connectivity is
confirmed. Which of the following is the MOST likely cause?
A. The server's firewall is blocking port 514 UDP
B. The server's syslog service is not configured to forward logs to the SIEM
C. The SIEM's disk storage is full
D. The server's NTP clock is out of synchronization
-” detailed answer 100 % correct :-”B
Rationale: If a server is online and network connectivity is confirmed, the most likely cause is
that the syslog service is not properly configured to forward logs to the SIEM collector. Firewall
issues (A) would typically affect connectivity. Storage issues (C) would affect the SIEM's ability to
store logs but not receipt. NTP issues (D) would affect timestamp accuracy but not log delivery.
2. Which of the following log sources would be MOST useful for detecting unauthorized
changes to file permissions on a Windows server?
A. Application logs
B. Security logs (Event ID 4670, 4719)
, 3
C. System logs
D. DNS logs
-” detailed answer 100 % correct :-”B
Rationale: Windows Security logs record security-related events including permission changes.
Event ID 4670 tracks permissions on an object being changed, and Event ID 4719 tracks system
audit policy changes. Application logs (A) record application-specific events. System logs (C)
record system component events. DNS logs (D) record domain name resolution queries.
3. An organization's SIEM correlates multiple failed login attempts from a single IP address
across three different user accounts, followed by a successful login to one account. This
pattern MOST likely indicates:
A. A password spraying attack
B. A brute force attack
C. A credential stuffing attack
D. A man-in-the-middle attack
-” detailed answer 100 % correct :-”A
Rationale: Password spraying involves attempting a small number of commonly used passwords
against many accounts. The pattern of failed attempts across multiple accounts followed by a
success is characteristic of password spraying. Brute force (B) typically targets a single account
with many password attempts. Credential stuffing (C) uses stolen credentials from one service
to access another. MITM (D) intercepts communications.
4. A security analyst is configuring log retention policies. Which of the following factors should
be the PRIMARY consideration when determining log retention periods?
A. Storage costs
B. Regulatory and compliance requirements
C. Log file size
D. SIEM performance
-” detailed answer 100 % correct :-”B
Rationale: Regulatory and compliance requirements (e.g., GDPR, HIPAA, PCI DSS) mandate
specific log retention periods and are legally binding. While storage costs (A), file size (C), and
, 4
performance (D) are operational considerations, compliance requirements take precedence as
non-compliance can result in significant penalties.
5. A SIEM alert triggers indicating "Potential data exfiltration detected — 2.5 GB of data
transferred to 203.0.113.45 over port 443 in 15 minutes." Which of the following actions
should the analyst take FIRST?
A. Block the destination IP address immediately
B. Validate the alert by reviewing network traffic logs
C. Notify law enforcement
D. Shut down the affected server
-” detailed answer 100 % correct :-”B
Rationale: Before taking any containment action, the analyst should validate the alert to
confirm it is not a false positive. This involves reviewing network traffic logs, comparing against
baselines, and investigating the context of the data transfer. Blocking (A) or shutting down (D)
without validation could disrupt legitimate business operations. Law enforcement (C) is
premature without confirmed malicious activity.
6. Which of the following tools is MOST appropriate for capturing and analyzing live network
traffic to investigate a suspected command-and-control (C2) beacon?
A. Nmap
B. Wireshark
C. Nessus
D. Metasploit
-” detailed answer 100 % correct :-”B
Rationale: Wireshark is a network protocol analyzer that captures and displays live network
traffic, making it ideal for investigating C2 beacon patterns. Nmap (A) is for network discovery
and port scanning. Nessus (C) is a vulnerability scanner. Metasploit (D) is a penetration testing
framework.
7. A security analyst identifies that a system is communicating with an external IP address
every 60 seconds using DNS queries to a suspicious domain. This pattern is MOST indicative
of:
CompTIA CySA+ (CS0003)
Practice Exam
Comprehensive 150-
Question Practice Test
with Answers and
Rationales a well
detailed one 2025 /
2026 written and graded
A+ upgraded
, 2
Exam Domain Weighting (CS0-003):
• Security Operations — 33% (50 questions)
• Vulnerability Management — 30% (45 questions)
• Incident Response and Management — 20% (30 questions)
• Reporting and Communication — 17% (25 questions)
DOMAIN 1: SECURITY OPERATIONS (33%)
System and Network Architecture & Log Ingestion
1. A security analyst is reviewing SIEM logs and notices that authentication logs from a critical
Linux server are not being received. The server is online and network connectivity is
confirmed. Which of the following is the MOST likely cause?
A. The server's firewall is blocking port 514 UDP
B. The server's syslog service is not configured to forward logs to the SIEM
C. The SIEM's disk storage is full
D. The server's NTP clock is out of synchronization
-” detailed answer 100 % correct :-”B
Rationale: If a server is online and network connectivity is confirmed, the most likely cause is
that the syslog service is not properly configured to forward logs to the SIEM collector. Firewall
issues (A) would typically affect connectivity. Storage issues (C) would affect the SIEM's ability to
store logs but not receipt. NTP issues (D) would affect timestamp accuracy but not log delivery.
2. Which of the following log sources would be MOST useful for detecting unauthorized
changes to file permissions on a Windows server?
A. Application logs
B. Security logs (Event ID 4670, 4719)
, 3
C. System logs
D. DNS logs
-” detailed answer 100 % correct :-”B
Rationale: Windows Security logs record security-related events including permission changes.
Event ID 4670 tracks permissions on an object being changed, and Event ID 4719 tracks system
audit policy changes. Application logs (A) record application-specific events. System logs (C)
record system component events. DNS logs (D) record domain name resolution queries.
3. An organization's SIEM correlates multiple failed login attempts from a single IP address
across three different user accounts, followed by a successful login to one account. This
pattern MOST likely indicates:
A. A password spraying attack
B. A brute force attack
C. A credential stuffing attack
D. A man-in-the-middle attack
-” detailed answer 100 % correct :-”A
Rationale: Password spraying involves attempting a small number of commonly used passwords
against many accounts. The pattern of failed attempts across multiple accounts followed by a
success is characteristic of password spraying. Brute force (B) typically targets a single account
with many password attempts. Credential stuffing (C) uses stolen credentials from one service
to access another. MITM (D) intercepts communications.
4. A security analyst is configuring log retention policies. Which of the following factors should
be the PRIMARY consideration when determining log retention periods?
A. Storage costs
B. Regulatory and compliance requirements
C. Log file size
D. SIEM performance
-” detailed answer 100 % correct :-”B
Rationale: Regulatory and compliance requirements (e.g., GDPR, HIPAA, PCI DSS) mandate
specific log retention periods and are legally binding. While storage costs (A), file size (C), and
, 4
performance (D) are operational considerations, compliance requirements take precedence as
non-compliance can result in significant penalties.
5. A SIEM alert triggers indicating "Potential data exfiltration detected — 2.5 GB of data
transferred to 203.0.113.45 over port 443 in 15 minutes." Which of the following actions
should the analyst take FIRST?
A. Block the destination IP address immediately
B. Validate the alert by reviewing network traffic logs
C. Notify law enforcement
D. Shut down the affected server
-” detailed answer 100 % correct :-”B
Rationale: Before taking any containment action, the analyst should validate the alert to
confirm it is not a false positive. This involves reviewing network traffic logs, comparing against
baselines, and investigating the context of the data transfer. Blocking (A) or shutting down (D)
without validation could disrupt legitimate business operations. Law enforcement (C) is
premature without confirmed malicious activity.
6. Which of the following tools is MOST appropriate for capturing and analyzing live network
traffic to investigate a suspected command-and-control (C2) beacon?
A. Nmap
B. Wireshark
C. Nessus
D. Metasploit
-” detailed answer 100 % correct :-”B
Rationale: Wireshark is a network protocol analyzer that captures and displays live network
traffic, making it ideal for investigating C2 beacon patterns. Nmap (A) is for network discovery
and port scanning. Nessus (C) is a vulnerability scanner. Metasploit (D) is a penetration testing
framework.
7. A security analyst identifies that a system is communicating with an external IP address
every 60 seconds using DNS queries to a suspicious domain. This pattern is MOST indicative
of: