Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 46 pages
Exam (elaborations)

CompTIA CySA+ Exam Prep 2026 Updated Practice Questions Comprehensive Cybersecurity Analysis Review | Detailed Explanations | Verified Answers | Complete Success Workbook

Document preview thumbnail
Preview 4 out of 46 pages

CompTIA CySA+ Exam Prep 2026 Updated Practice Questions Comprehensive Cybersecurity Analysis Review | Detailed Explanations | Verified Answers | Complete Success Workbook

Content preview

CompTIA CySA+ Exam Prep 2026 Updated Practice
Questions Comprehensive Cybersecurity Analysis
Review | Detailed Explanations | Verified Answers |
Complete Success Workbook

Exam Reference: CompTIA CySA+ CS0-003
Question Format: Multiple-choice questions covering all four exam domains with
detailed rationales for each answer.
Exam Domains & Weighting:
• Domain 1.0: Security Operations — 33%
• Domain 2.0: Vulnerability Management — 30%
• Domain 3.0: Incident Response and Management — 20%
• Domain 4.0: Reporting and Communication — 17%
Exam Details: Maximum 85 questions | 165 minutes | Passing Score: 750/900


DOMAIN 1.0: SECURITY OPERATIONS (33%)


Question 1
A SOC analyst is reviewing SIEM alerts and sees multiple failed login attempts
from a single external IP address targeting a domain controller, followed by a
single successful login from the same IP. Which of the following is the MOST
appropriate next step?
A) Immediately block the IP address at the firewall
B) Escalate the incident to the incident response team for investigation
C) Ignore the alert as it is likely a false positive
D) Reset the domain controller password
Answer: B

,Rationale: Multiple failed login attempts followed by a successful login strongly
indicates a successful brute force or password spraying attack. This requires
immediate escalation to the incident response team for investigation. While
blocking the IP (A) may be part of containment, investigation should precede
action to understand the scope. Ignoring the alert (C) is negligent. Resetting the
password (D) alone does not address the potential compromise.


Question 2
A security analyst is configuring a SIEM solution and needs to correlate events
from multiple sources. Which of the following is the BEST approach to reduce
false positives?
A) Increase the log retention period to 90 days
B) Implement baseline tuning and rule refinement based on normal network
behavior
C) Disable all alerts except critical severity
D) Increase the alert threshold to 100 events per minute
Answer: B
Rationale: Baseline tuning and rule refinement are essential for reducing false
positives in SIEM environments. By establishing normal network behavior and
adjusting rules accordingly, analysts can distinguish genuine threats from benign
activity. Increasing retention (A) doesn't reduce false positives. Disabling alerts (C)
defeats the purpose of the SIEM. Increasing thresholds (D) may miss real attacks.


Question 3
Which of the following threat intelligence sharing standards is used to represent
structured information about cyber threats in a machine-readable format?
A) STIX
B) TAXII
C) OpenIOC
D) YARA
Answer: A

,Rationale: STIX (Structured Threat Information eXpression) is a language and
serialization format used to exchange cyber threat intelligence in a structured,
machine-readable format. TAXII (B) is the transport protocol for sharing STIX
data. OpenIOC (C) is an older format for indicators of compromise. YARA (D) is
used for malware identification and classification.


Question 4
A security analyst is using Wireshark to investigate unusual network activity. The
analyst observes a large number of SYN packets being sent to a single host from
multiple spoofed IP addresses, but no SYN-ACK responses are observed. What
type of attack is this?
A) SYN flood attack
B) DNS amplification attack
C) ARP poisoning
D) Man-in-the-middle attack
Answer: A
Rationale: A SYN flood attack sends a large number of SYN packets from
spoofed IP addresses to overwhelm a target's connection table, preventing
legitimate connections. DNS amplification (B) uses DNS queries to generate large
responses. ARP poisoning (C) manipulates ARP tables. MITM (D) intercepts
communications.


Question 5
Which of the following is an example of an indicator of compromise (IoC) at the
host level?
A) Unusual outbound traffic to an unknown IP address
B) Unauthorized scheduled task creation
C) Bandwidth spikes during off-hours
D) DNS query anomalies
Answer: B
Rationale: Unauthorized scheduled task creation is a host-level indicator of
compromise, often used by malware to maintain persistence. Unusual outbound

, traffic (A) and bandwidth spikes (C) are network-level indicators. DNS anomalies
(D) are also network-level indicators.


Question 6
A SOC analyst is reviewing threat intelligence feeds and encounters the term
"TTP." What does TTP stand for in the context of threat intelligence?
A) Tactics, Techniques, and Procedures
B) Tools, Threats, and Payloads
C) Testing, Training, and Procedures
D) Threat, Triage, and Prioritization
Answer: A
Rationale: TTP stands for Tactics, Techniques, and Procedures, which describes
how threat actors operate. Understanding TTPs allows analysts to predict and
defend against adversary behavior rather than just reacting to specific indicators.


Question 7
A security analyst needs to analyze a suspicious executable file without executing
it on a production system. Which of the following tools should the analyst use?
A) Static analysis using a disassembler or debugger
B) Dynamic analysis in a sandbox environment
C) Packet capture analysis
D) Log analysis
Answer: A
Rationale: Static analysis examines the executable file without running it, using
disassemblers, debuggers, or hex editors to understand its structure and potential
functionality. Dynamic analysis (B) would execute the file, which should be done
in a sandbox but is not the same as static analysis. Packet capture (C) and log
analysis (D) are for network and system activity, not file analysis.

Document information

Uploaded on
August 9, 2026
Number of pages
46
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$26.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
7
Followers
0
Items
1990
Last sold
1 day ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions