COMPTIA CYSA+ EXAM – QUESTIONS AND ANSWERS |
VERIFIED AND WELL DETAILED ANSWERS | PLUS
RATIONALES | DOWNLOAD AND PASS | LATEST EXAM
UPDATE 2026/2027
Core Domains
Security Operations (34%)
Vulnerability Management (26%)
Incident Response and Management (24%)
Reporting and Communication (16%)
Introduction
This assessment evaluates the candidate's mastery of essential concepts
required for the CompTIA Cybersecurity Analyst (CySA+) certification
examination. It measures knowledge of security operations, vulnerability
management, incident response, and reporting and communication. The
exam employs multiple-choice and performance-based questions
designed to simulate real-world Security Operations Center (SOC)
challenges. Emphasis is placed on applying threat intelligence,
analyzing indicators of malicious activity, prioritizing vulnerabilities,
and executing incident response procedures. Success requires not only
recall of security concepts but also critical thinking skills necessary for
effective threat detection and response.
Section One: Questions 1–100
1. A SOC analyst is onboarding new log sources into the
organization's SIEM. The platform natively ingests syslog and
Windows Event Forwarding data, but a critical in-house business
application only exposes its audit records through a proprietary
REST API. Which approach should the analyst use to bring this
application's events into the SIEM?
,A. Enable syslog over UDP 514 on the application server and point it at
the SIEM listener
B. Configure a dedicated API connector that queries the application's
REST interface on a schedule and normalizes events into the SIEM's
common schema
C. Export the application logs to CSV once per week and import the
files manually into the SIEM
D. Configure the host firewall to mirror blocked-connection messages to
the SIEM in place of application audit logging
B
RATIONALE: A proprietary REST-based source requires a
purpose-built API connector or agent that retrieves events and maps
their fields to the SIEM's normalized schema, preserving timeliness and
searchability. Option A fails because the application does not natively
emit syslog. Option C destroys the near-real-time detection value the
SOC needs. Option D supplies only a narrow slice of network events,
not the application's own audit trail .
2. During a quarterly access review, an analyst discovers that the
service account used by the backup application is a member of the
local Administrators group and is permitted to log on interactively
to any server in the domain. Which remediation best applies the
principle of least privilege while keeping the backup function
working?
A. Convert the account to a domain admin account so the backup
software never fails due to permissions
B. Leave the membership unchanged but enable MFA on the account for
all logon types
C. Remove interactive logon rights, restrict the account to the specific
servers it services, and grant only the file-system and VSS permissions
the backup job requires
,D. Delete the account and re-run all backup jobs under each
administrator's personal credentials
C
RATIONALE: Least privilege for service accounts means scoping
the account to exactly the systems and permissions its function needs
and eliminating interactive logon capability, which removes a common
lateral-movement and credential-dumping path. Option A increases
privilege. Option B does not reduce standing privilege. Option D ties
automated services to human credentials, causing failures and destroying
accountability .
3. A healthcare organization must protect patient records that are
stored in a database and that replicate nightly to a disaster recovery
site across a WAN link. Which combination of protections addresses
data at rest and data in transit for this scenario?
A. AES-256 encryption of the database storage volumes and TLS 1.3 for
the replication connection
B. TLS 1.3 for the replication connection and SHA-256 hashing of every
patient record
C. Disk compression with password protection on the archive files and
IPSec only between the firewalls
D. AES-256 on the database volumes and disabled replication until an
audit is completed
A
RATIONALE: Confidentiality at rest is provided by strong
symmetric encryption such as AES-256 on the storage volumes, while
confidentiality and integrity in transit are provided by a modern
transport protocol such as TLS 1.3 on the replication link. Option B
confuses integrity hashing with confidentiality. Option C relies on
, reversible archive passwords and compression, which are not security
controls. Option D destroys the availability and resiliency requirement .
4. An analyst returns from a weekend and finds four SIEM alerts in
the queue. Which alert should be triaged first?
A. EDR alert showing PowerShell accessing lsass.exe memory on a
domain controller
B. Antivirus quarantining an EICAR test file on a training workstation
C. One failed VPN logon for a single service account
D. The patch management server reporting that it is offline
A
RATIONALE: Credential dumping from lsass.exe on a domain
controller is a high-confidence indicator of active privilege escalation
and potential domain compromise, so it carries the highest impact and
urgency. The EICAR file is a harmless test artifact, a single failed logon
is routine noise, and the offline patch server is an operational issue rather
than an active attack .
5. A SOC analyst needs a SIEM search that counts failed Windows
logon events per user account over the last 24 hours and returns
only accounts with more than ten failures. Which query is correct?
A. index=main EventCode=4624 | stats count by user | where count > 10
B. index=main sourcetype=win:security earliest=-24h | search
EventCode=4625 | stats count by user | where count > 10
C. index=main EventCode=4625 | stats count by user
D. index=main sourcetype=win:security | search EventCode=4624 | stats
count by user | where count > 10
B
RATIONALE: EventCode 4625 represents failed logon events in
Windows Security logs. The query must filter for this event code, use
VERIFIED AND WELL DETAILED ANSWERS | PLUS
RATIONALES | DOWNLOAD AND PASS | LATEST EXAM
UPDATE 2026/2027
Core Domains
Security Operations (34%)
Vulnerability Management (26%)
Incident Response and Management (24%)
Reporting and Communication (16%)
Introduction
This assessment evaluates the candidate's mastery of essential concepts
required for the CompTIA Cybersecurity Analyst (CySA+) certification
examination. It measures knowledge of security operations, vulnerability
management, incident response, and reporting and communication. The
exam employs multiple-choice and performance-based questions
designed to simulate real-world Security Operations Center (SOC)
challenges. Emphasis is placed on applying threat intelligence,
analyzing indicators of malicious activity, prioritizing vulnerabilities,
and executing incident response procedures. Success requires not only
recall of security concepts but also critical thinking skills necessary for
effective threat detection and response.
Section One: Questions 1–100
1. A SOC analyst is onboarding new log sources into the
organization's SIEM. The platform natively ingests syslog and
Windows Event Forwarding data, but a critical in-house business
application only exposes its audit records through a proprietary
REST API. Which approach should the analyst use to bring this
application's events into the SIEM?
,A. Enable syslog over UDP 514 on the application server and point it at
the SIEM listener
B. Configure a dedicated API connector that queries the application's
REST interface on a schedule and normalizes events into the SIEM's
common schema
C. Export the application logs to CSV once per week and import the
files manually into the SIEM
D. Configure the host firewall to mirror blocked-connection messages to
the SIEM in place of application audit logging
B
RATIONALE: A proprietary REST-based source requires a
purpose-built API connector or agent that retrieves events and maps
their fields to the SIEM's normalized schema, preserving timeliness and
searchability. Option A fails because the application does not natively
emit syslog. Option C destroys the near-real-time detection value the
SOC needs. Option D supplies only a narrow slice of network events,
not the application's own audit trail .
2. During a quarterly access review, an analyst discovers that the
service account used by the backup application is a member of the
local Administrators group and is permitted to log on interactively
to any server in the domain. Which remediation best applies the
principle of least privilege while keeping the backup function
working?
A. Convert the account to a domain admin account so the backup
software never fails due to permissions
B. Leave the membership unchanged but enable MFA on the account for
all logon types
C. Remove interactive logon rights, restrict the account to the specific
servers it services, and grant only the file-system and VSS permissions
the backup job requires
,D. Delete the account and re-run all backup jobs under each
administrator's personal credentials
C
RATIONALE: Least privilege for service accounts means scoping
the account to exactly the systems and permissions its function needs
and eliminating interactive logon capability, which removes a common
lateral-movement and credential-dumping path. Option A increases
privilege. Option B does not reduce standing privilege. Option D ties
automated services to human credentials, causing failures and destroying
accountability .
3. A healthcare organization must protect patient records that are
stored in a database and that replicate nightly to a disaster recovery
site across a WAN link. Which combination of protections addresses
data at rest and data in transit for this scenario?
A. AES-256 encryption of the database storage volumes and TLS 1.3 for
the replication connection
B. TLS 1.3 for the replication connection and SHA-256 hashing of every
patient record
C. Disk compression with password protection on the archive files and
IPSec only between the firewalls
D. AES-256 on the database volumes and disabled replication until an
audit is completed
A
RATIONALE: Confidentiality at rest is provided by strong
symmetric encryption such as AES-256 on the storage volumes, while
confidentiality and integrity in transit are provided by a modern
transport protocol such as TLS 1.3 on the replication link. Option B
confuses integrity hashing with confidentiality. Option C relies on
, reversible archive passwords and compression, which are not security
controls. Option D destroys the availability and resiliency requirement .
4. An analyst returns from a weekend and finds four SIEM alerts in
the queue. Which alert should be triaged first?
A. EDR alert showing PowerShell accessing lsass.exe memory on a
domain controller
B. Antivirus quarantining an EICAR test file on a training workstation
C. One failed VPN logon for a single service account
D. The patch management server reporting that it is offline
A
RATIONALE: Credential dumping from lsass.exe on a domain
controller is a high-confidence indicator of active privilege escalation
and potential domain compromise, so it carries the highest impact and
urgency. The EICAR file is a harmless test artifact, a single failed logon
is routine noise, and the offline patch server is an operational issue rather
than an active attack .
5. A SOC analyst needs a SIEM search that counts failed Windows
logon events per user account over the last 24 hours and returns
only accounts with more than ten failures. Which query is correct?
A. index=main EventCode=4624 | stats count by user | where count > 10
B. index=main sourcetype=win:security earliest=-24h | search
EventCode=4625 | stats count by user | where count > 10
C. index=main EventCode=4625 | stats count by user
D. index=main sourcetype=win:security | search EventCode=4624 | stats
count by user | where count > 10
B
RATIONALE: EventCode 4625 represents failed logon events in
Windows Security logs. The query must filter for this event code, use