Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 60 pages
Exam (elaborations)

CompTIA CySA+ (CS0003) Practice Exam Comprehensive 150 Question Practice Test with Answers and Rationales a well detailed one 2025 / 2026 written and graded A+ upgraded

Document preview thumbnail
Preview 4 out of 60 pages

CompTIA CySA+ (CS0003) Practice Exam Comprehensive 150 Question Practice Test with Answers and Rationales a well detailed one 2025 / 2026 written and graded A+ upgraded

Content preview

1




CompTIA CySA+ (CS0003)
Practice Exam
Comprehensive 150-
Question Practice Test
with Answers and
Rationales a well
detailed one 2025 /
2026 written and graded
A+ upgraded

, 2




Exam Domain Weighting (CS0-003):

• Security Operations — 33% (50 questions)

• Vulnerability Management — 30% (45 questions)

• Incident Response and Management — 20% (30 questions)

• Reporting and Communication — 17% (25 questions)



DOMAIN 1: SECURITY OPERATIONS (33%)

System and Network Architecture & Log Ingestion

1. A security analyst is reviewing SIEM logs and notices that authentication logs from a critical
Linux server are not being received. The server is online and network connectivity is
confirmed. Which of the following is the MOST likely cause?

A. The server's firewall is blocking port 514 UDP
B. The server's syslog service is not configured to forward logs to the SIEM
C. The SIEM's disk storage is full
D. The server's NTP clock is out of synchronization

-” detailed answer 100 % correct :-”B

Rationale: If a server is online and network connectivity is confirmed, the most likely cause is
that the syslog service is not properly configured to forward logs to the SIEM collector. Firewall
issues (A) would typically affect connectivity. Storage issues (C) would affect the SIEM's ability to
store logs but not receipt. NTP issues (D) would affect timestamp accuracy but not log delivery.



2. Which of the following log sources would be MOST useful for detecting unauthorized
changes to file permissions on a Windows server?

A. Application logs
B. Security logs (Event ID 4670, 4719)

, 3



C. System logs
D. DNS logs

-” detailed answer 100 % correct :-”B

Rationale: Windows Security logs record security-related events including permission changes.
Event ID 4670 tracks permissions on an object being changed, and Event ID 4719 tracks system
audit policy changes. Application logs (A) record application-specific events. System logs (C)
record system component events. DNS logs (D) record domain name resolution queries.



3. An organization's SIEM correlates multiple failed login attempts from a single IP address
across three different user accounts, followed by a successful login to one account. This
pattern MOST likely indicates:

A. A password spraying attack
B. A brute force attack
C. A credential stuffing attack
D. A man-in-the-middle attack

-” detailed answer 100 % correct :-”A

Rationale: Password spraying involves attempting a small number of commonly used passwords
against many accounts. The pattern of failed attempts across multiple accounts followed by a
success is characteristic of password spraying. Brute force (B) typically targets a single account
with many password attempts. Credential stuffing (C) uses stolen credentials from one service
to access another. MITM (D) intercepts communications.



4. A security analyst is configuring log retention policies. Which of the following factors should
be the PRIMARY consideration when determining log retention periods?

A. Storage costs
B. Regulatory and compliance requirements
C. Log file size
D. SIEM performance

-” detailed answer 100 % correct :-”B

Rationale: Regulatory and compliance requirements (e.g., GDPR, HIPAA, PCI DSS) mandate
specific log retention periods and are legally binding. While storage costs (A), file size (C), and

, 4



performance (D) are operational considerations, compliance requirements take precedence as
non-compliance can result in significant penalties.



5. A SIEM alert triggers indicating "Potential data exfiltration detected — 2.5 GB of data
transferred to 203.0.113.45 over port 443 in 15 minutes." Which of the following actions
should the analyst take FIRST?

A. Block the destination IP address immediately
B. Validate the alert by reviewing network traffic logs
C. Notify law enforcement
D. Shut down the affected server

-” detailed answer 100 % correct :-”B

Rationale: Before taking any containment action, the analyst should validate the alert to
confirm it is not a false positive. This involves reviewing network traffic logs, comparing against
baselines, and investigating the context of the data transfer. Blocking (A) or shutting down (D)
without validation could disrupt legitimate business operations. Law enforcement (C) is
premature without confirmed malicious activity.



6. Which of the following tools is MOST appropriate for capturing and analyzing live network
traffic to investigate a suspected command-and-control (C2) beacon?

A. Nmap
B. Wireshark
C. Nessus
D. Metasploit

-” detailed answer 100 % correct :-”B

Rationale: Wireshark is a network protocol analyzer that captures and displays live network
traffic, making it ideal for investigating C2 beacon patterns. Nmap (A) is for network discovery
and port scanning. Nessus (C) is a vulnerability scanner. Metasploit (D) is a penetration testing
framework.



7. A security analyst identifies that a system is communicating with an external IP address
every 60 seconds using DNS queries to a suspicious domain. This pattern is MOST indicative
of:

Document information

Uploaded on
July 25, 2026
Number of pages
60
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$25.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
wise254
5.0
(571)
Sold
61
Followers
5
Items
2970
Last sold
3 days ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions