Career Employer

Your FREE CySA+ Flashcards 2026 – 250+ Cards

Realistic, CySA+ exam-style flashcards across all 4 CS0-003 domains — flip, match, type, and quiz yourself.

How well do you know them?

To find us again, just search “Career Employer CySA+”

By

Click Study Flashcards above to open the flashcard hub — hundreds of CySA+ cards you can flip, match, type, or quiz yourself on. Every card is drawn from the four official CS0-003 domains, so you study exactly what the exam tests.[2]

Pair them with our free practice test and study guide. Want extra insurance for exam day? Capital Prep’s CySA+ premium study materials come with a CySA+ exam pass guarantee: your money back if you don’t pass, plus up to $439 toward your retake fee — and Career Employer students get a special discount.

CompTIA CySA+ is one of the 14 CompTIA certifications — explore our CompTIA flashcards to compare and prep across the whole family.

CySA+ Flashcard Study Modes

Flip mode walks you card by card for first-pass study, Match turns terms and definitions into a timed pairing game, Type shows a definition and asks you to produce the term from memory, and Quiz builds multiple-choice questions from the same deck. A short acronym like EDR is exactly the kind of front Type drills, since recognizing it is easier than recalling it cold.

Free CompTIA CySA+ flashcards from Career Employer — active recall for the CS0-003 exam

Why Flashcards Work for CySA+

Security Operations is the heaviest domain at 33% of the exam and the largest block in the deck with 98 cards. The fronts run from monitoring and detection tooling to identity and email controls, so you will meet EDR and XDR alongside SDN, and separately work through SPF, DLP and MFA. Attacker behavior language shows up here too, including TTP and IAM, which pay off later when you read alerts and describe what a sensor actually saw.

Vulnerability Management carries 30% of the exam and 79 cards. This block drills the identification and scoring vocabulary you need to triage findings: CVE and CWE for cataloging, CVSS for severity, and Zero-day for the case where no patch exists. Testing methods get their own fronts, so SAST and DAST sit near web weakness terms such as CSRF and SSRF that you have to tell apart under time pressure.

Incident Response & Management accounts for 20% of the exam and 54 cards. The terms track the lifecycle and the people in it, with Containment and Eradication as process steps, Isolation and Reimaging as hands-on responses, and Legal hold for the evidence side. Threat actor labels such as APT and Hacktivist appear here, as does OWASP, which ties attacker technique back to the vulnerability work.

Reporting & Communication closes the deck with 43 cards and 17% of the exam. These fronts cover the metrics and agreements you use to brief stakeholders, including MTTD, MTTR and MTTA, along with MTTC for the closing side of the timeline. Governance vocabulary rounds it out through SLA and MOU, and Risk score and KPI give you the language for summarizing posture to a non-technical audience.

CySA+ is dense with terminology — detection methods, indicators of compromise, the CVSS metric groups, attack frameworks, the incident-response lifecycle, forensics, and reporting metrics.[2] Spaced flashcards are the most efficient way to keep it all fresh. Used alongside our practice test and study guide, they turn review time into measurable progress.

CySA+ Flashcards by Domain

The cards are organized by the four official CS0-003 domains. Drill the highest-weighted ones first — Security Operations and Vulnerability Management make up nearly two-thirds of the exam:[2]

CySA+ flashcards by domain and weight
DomainExam weight
Security Operations33%
Vulnerability Management30%
Incident Response and Management20%
Reporting and Communication17%

How to Get the Most Out of These Flashcards

  • Start with the biggest block. Security Operations is 33% of the exam and 98 cards, so clear it in Flip mode first and let its tooling vocabulary anchor everything you study afterward.
  • Type-drill the confusable pairs. Fronts like CSRF and SSRF, or SAST and DAST, feel obvious in Flip but collapse under recall, which is exactly what Type mode exposes.
  • Use Match for the acronym sets. Metric fronts such as MTTD, MTTR and MTTA pair fastest under timed pressure, and Match forces you to separate them instead of reading them as one cluster.
  • Move to the practice test once recall holds. When Quiz mode stops surprising you across all four domains, switch to the practice test for scenario questions and use the study guide to fill any gaps it reveals.
  • Set a steady cadence across 274 cards. Take one domain per session, re-Flip yesterday’s misses first, and finish each session with a Quiz round mixing the domain you just studied with an earlier one.

CySA+ Flashcards FAQ

Hundreds of free CySA+ flashcards, organized across all four CS0-003 domains — Security Operations, Vulnerability Management, Incident Response and Management, and Reporting and Communication. They're free with no account required.

CySA+ flashcard bank

All 274 cards, by topic

A reference copy of every card in this deck. Each answer stays hidden until you choose to show it. To study with Flip, Match, Type and Quiz modes and track what you have mastered, use Study Flashcards at the top of the page.

Security Operations (98)

SIEM
Show answer

Security Information and Event Management — collects and correlates logs across the enterprise to detect, investigate, and report on threats.

Indicator of compromise (IoC)
Show answer

A forensic artifact (malicious IP/domain, file hash, registry key, beaconing) that signals a system may have been breached.

Signature-based detection
Show answer

Detection that matches known patterns (hashes, rules, byte sequences). Precise on known threats but blind to novel ones.

Anomaly-based detection
Show answer

Detection that flags deviations from a defined baseline of normal activity; catches unknown threats but needs a good baseline.

Behavioral analytics
Show answer

Detecting threats by modeling normal user, host, and network behavior and flagging deviations — finds insider and novel threats.

Heuristic detection
Show answer

Detection that identifies threats by characteristics/rules of suspicious behavior rather than exact signatures.

UEBA
Show answer

User and Entity Behavior Analytics — uses machine learning to baseline normal behavior and detect anomalies like compromised accounts.

Threat intelligence
Show answer

Evidence-based knowledge about adversaries — actors, their TTPs, and indicators — used to inform and improve defense.

Threat-intelligence cycle
Show answer

The repeating process: planning & direction → collection → processing → analysis → dissemination → feedback.

Strategic threat intelligence
Show answer

High-level intelligence on trends and risk, aimed at executives and long-term decision-making.

Operational threat intelligence
Show answer

Intelligence about specific campaigns and adversary operations, aimed at defenders.

Tactical threat intelligence
Show answer

Technical, immediate intelligence — IoCs and TTPs — consumed by security tools and analysts.

TTP
Show answer

Tactics, Techniques, and Procedures — how an adversary operates; the most durable, hardest-to-change indicator.

Confidence level (threat intel)
Show answer

An assessment of how reliable a piece of intelligence is, so consumers know how much to trust it.

MITRE ATT&CK
Show answer

A knowledge base of real-world adversary tactics (goals) and techniques (methods) used to map detections and drive threat hunting.

Threat hunting
Show answer

The proactive, hypothesis-driven search for adversaries that have evaded existing detections, before any alert fires.

Dwell time
Show answer

The length of time an attacker remains undetected in an environment; threat hunting aims to reduce it.

STIX
Show answer

Structured Threat Information Expression — a standardized language for representing and sharing cyber threat intelligence.

TAXII
Show answer

Trusted Automated Exchange of Intelligence Information — the protocol for transporting STIX threat-intelligence data.

ISAC / ISAO
Show answer

Information Sharing and Analysis Center/Organization — communities that share threat intelligence among members.

OSINT
Show answer

Open-Source Intelligence — intelligence gathered from publicly available sources.

Zero trust
Show answer

A model that removes implicit trust and verifies every request based on identity, device, and context — 'never trust, always verify.'

SASE
Show answer

Secure Access Service Edge — converges networking (SD-WAN) and security (SWG, CASB, ZTNA, FWaaS) into one cloud-delivered service.

Network segmentation
Show answer

Dividing a network into zones to limit lateral movement and contain the blast radius of a compromise.

SDN
Show answer

Software-Defined Networking — separates the network control plane from the data plane for centralized, programmable control.

SOAR
Show answer

Security Orchestration, Automation, and Response — automates and coordinates incident response via playbooks and tool integrations.

Playbook
Show answer

A documented, repeatable set of response steps for a given alert or incident type, often automated through SOAR.

Packet capture
Show answer

Recording raw network traffic (e.g., with tcpdump or Wireshark) so analysts can inspect its contents and flow.

Wireshark
Show answer

A graphical packet-capture and protocol-analysis tool used to inspect network traffic in detail.

tcpdump
Show answer

A command-line packet-capture tool for recording and inspecting network traffic.

NetFlow
Show answer

A protocol that records metadata about network flows (who talked to whom, when, how much) — useful for spotting beaconing and exfiltration.

Log analysis
Show answer

Reviewing and correlating system, network, and application logs to detect, scope, and investigate suspicious activity.

EDR
Show answer

Endpoint Detection and Response — continuously monitors endpoints to detect, investigate, and respond to threats.

XDR
Show answer

Extended Detection and Response — correlates detection and response across endpoints, network, email, and cloud.

SPF
Show answer

Sender Policy Framework — a DNS record listing the mail servers authorized to send email for a domain.

DKIM
Show answer

DomainKeys Identified Mail — a cryptographic signature on outbound email so receivers can detect tampering and forged senders.

DMARC
Show answer

Domain-based Message Authentication, Reporting & Conformance — ties SPF and DKIM together and tells receivers how to handle failures.

Email header analysis
Show answer

Examining headers (Received, Authentication-Results) to trace an email's path and verify SPF/DKIM/DMARC results.

Phishing
Show answer

A social-engineering attack using fraudulent messages to steal credentials, deliver malware, or trick users into actions.

Spear phishing
Show answer

A phishing attack targeted at a specific individual or organization, using personalized details.

Whaling
Show answer

A phishing attack that targets high-value executives such as a CEO or CFO.

Vishing
Show answer

Voice phishing — a social-engineering attack carried out over a phone call.

Smishing
Show answer

SMS phishing — a social-engineering attack delivered by text message.

Business email compromise (BEC)
Show answer

An attack impersonating a trusted executive or vendor to authorize fraudulent payments or data transfers.

On-path attack
Show answer

An attacker secretly relaying or altering traffic between two parties (formerly 'man-in-the-middle').

DDoS
Show answer

Distributed Denial of Service — overwhelming a target with traffic from many sources to make it unavailable.

DNS poisoning
Show answer

Corrupting DNS resolution so victims are sent to attacker-controlled addresses.

ARP poisoning
Show answer

Sending forged ARP messages to associate the attacker's MAC with a victim's IP, enabling interception on a LAN.

Beaconing
Show answer

Periodic, regular network callbacks from a compromised host to a command-and-control server.

Command and control (C2)
Show answer

The channel and infrastructure an attacker uses to remotely control compromised systems.

Living off the land
Show answer

Using legitimate, built-in system tools (e.g., PowerShell, WMI) to carry out an attack and evade detection.

Obfuscation
Show answer

Deliberately making code or data hard to understand to evade detection or analysis.

Regular expression (regex)
Show answer

A pattern-matching syntax analysts use to search and filter logs and data.

False positive (alert)
Show answer

An alert that flags benign activity as malicious — a source of analyst alert fatigue.

Alert fatigue
Show answer

Desensitization caused by too many alerts (often from an untuned SIEM), risking missed real threats.

Sandboxing
Show answer

Running suspicious code in an isolated environment to observe its behavior safely.

File integrity monitoring (FIM)
Show answer

Alerting when critical files change unexpectedly, indicating possible tampering.

DLP
Show answer

Data Loss Prevention — tools that detect and block unauthorized movement of sensitive data.

Cyber kill chain
Show answer

Lockheed Martin's linear 7-stage intrusion model used to detect and disrupt attacks early.

Diamond Model
Show answer

An intrusion-analysis model linking four features of every event: adversary, capability, infrastructure, and victim.

CIA triad
Show answer

Confidentiality, Integrity, Availability — the three core goals of information security.

Confidentiality
Show answer

Ensuring only authorized people can read data; enforced by encryption and access control.

Integrity
Show answer

Ensuring data is accurate and unaltered; enforced by hashing and digital signatures.

Availability
Show answer

Ensuring authorized users can access data and systems when needed; enforced by redundancy and backups.

IAM
Show answer

Identity and Access Management — the policies and tools that manage digital identities and control access.

MFA
Show answer

Multi-factor authentication — requiring two or more factors from different categories (know, have, are).

Least privilege
Show answer

Granting only the minimum access needed to perform a task, limiting the blast radius of a compromise.

Encryption
Show answer

Transforming data so only authorized parties with the key can read it; protects confidentiality.

Symmetric encryption
Show answer

Encryption using one shared secret key to both encrypt and decrypt (e.g., AES) — fast.

Asymmetric encryption
Show answer

Encryption using a public/private key pair (e.g., RSA, ECC) for key exchange and digital signatures.

Hashing
Show answer

A one-way function producing a fixed-length digest (e.g., SHA-256); used for integrity, not reversible.

Honeypot
Show answer

A decoy system that lures attackers away from real assets and records their behavior.

Honeytoken
Show answer

Fake data (a credential, record, or key) that signals compromise the moment it is used.

Malware
Show answer

Malicious software — ransomware, trojans, worms, viruses, spyware, rootkits, and keyloggers.

Rootkit
Show answer

Malware that hides deep in the system (often the kernel) to maintain stealthy, privileged access.

Trojan
Show answer

Malware disguised as legitimate software that performs a hidden malicious action when run.

Lateral movement
Show answer

An attacker moving from an initial foothold to other systems within the network.

Privilege escalation
Show answer

Gaining higher access rights than granted — vertical (to admin) or horizontal (to another user).

Persistence
Show answer

Techniques an attacker uses to maintain access across reboots and credential changes.

Endpoint analysis
Show answer

Examining a host for malicious processes, persistence, and artifacts during detection or response.

Email analysis
Show answer

Examining messages, attachments, and headers for phishing, spoofing, and malicious payloads.

File analysis
Show answer

Inspecting a file's properties, hash, and behavior to determine if it is malicious.

Sentiment / anomaly baseline
Show answer

A reference profile of normal activity against which anomaly detection compares current behavior.

Scripting (CySA+)
Show answer

Reading Python, PowerShell, shell, or JavaScript snippets and regex to analyze and automate — not writing production code.

API integration
Show answer

Connecting security tools through APIs and webhooks to share data and automate workflows.

Standardization (process)
Show answer

Defining consistent processes and configurations to reduce error and enable automation.

Orchestration
Show answer

Coordinating multiple security tools and tasks into a unified, often automated, workflow.

Syslog
Show answer

A standard protocol for forwarding log messages, commonly aggregated centrally by a SIEM.

Windows Event Log
Show answer

The Windows logging system (Security, System, Application logs) analysts review for host activity.

Sysmon
Show answer

A Windows system-monitoring tool that logs detailed process, network, and file events for analysis.

Log correlation
Show answer

Linking events across multiple sources to reveal an attack that no single log shows alone.

Use case (SIEM)
Show answer

A defined detection scenario with the logic and data sources needed to catch a specific threat.

Tuning (SIEM)
Show answer

Adjusting detection rules and thresholds to reduce false positives and surface true threats.

Threat feed
Show answer

A stream of indicators (IPs, domains, hashes) consumed to enrich detection and hunting.

Pyramid of Pain
Show answer

A model ranking indicators by how much disrupting them hurts an attacker — TTPs hurt most, hashes least.

CASB
Show answer

Cloud Access Security Broker — enforces security policy between users and cloud services.

ZTNA
Show answer

Zero Trust Network Access — grants per-application access based on identity and context, not network location.

Geofencing / impossible travel
Show answer

Detecting logins from locations too far apart in time to be legitimate.

Vulnerability Management (79)

CVSS
Show answer

Common Vulnerability Scoring System — a 0.0–10.0 score (Base, Temporal, Environmental groups) rating a vulnerability's severity.

CVSS Base metrics
Show answer

The intrinsic, constant severity: attack vector, attack complexity, privileges required, user interaction, scope, and CIA impact.

CVSS Temporal metrics
Show answer

Severity factors that change over time: exploit code maturity, remediation level, and report confidence.

CVSS Environmental metrics
Show answer

Severity tailored to your organization, including asset-value (CIA) requirements and modified base metrics.

CVSS severity bands
Show answer

None 0.0, Low 0.1–3.9, Medium 4.0–6.9, High 7.0–8.9, Critical 9.0–10.0.

Attack vector (AV)
Show answer

A CVSS base metric describing how a vulnerability is exploited: Network, Adjacent, Local, or Physical.

Attack complexity (AC)
Show answer

A CVSS base metric for how hard the attack is to carry out beyond the attacker's control.

Privileges required (PR)
Show answer

A CVSS base metric for the level of access an attacker needs before exploiting the flaw.

Scope (CVSS)
Show answer

A CVSS base metric indicating whether exploiting the vulnerability impacts resources beyond its security scope.

CVE
Show answer

Common Vulnerabilities and Exposures — a unique public identifier for one specific known vulnerability.

CWE
Show answer

Common Weakness Enumeration — a catalog of software and hardware weakness types.

Vulnerability management
Show answer

The continuous cycle of identifying, scanning, analyzing, prioritizing, remediating, validating, and reporting on vulnerabilities.

Asset discovery
Show answer

Inventorying and mapping the systems and services in an environment — the first step in vulnerability management.

Attack surface
Show answer

The total set of points where an attacker could attempt to enter or extract data; reducing it is a core goal.

Attack surface management
Show answer

Continuously discovering, inventorying, and reducing an organization's exposed footprint.

Active scanning
Show answer

Scanning that sends probes directly to targets — thorough but can disrupt fragile systems.

Passive scanning
Show answer

Identifying assets and issues by observing existing traffic without sending probes — non-disruptive but less complete.

Credentialed scan
Show answer

A vulnerability scan that logs into the target — deeper, more accurate, fewer false positives.

Non-credentialed scan
Show answer

A scan that probes only from the outside, like an unauthenticated attacker — a shallower, attacker's-eye view.

Agent-based scan
Show answer

A scan run by software installed on the host; works offline and for roaming assets.

Agentless scan
Show answer

A scan run from the network with no software installed on the target.

Internal scan
Show answer

A vulnerability scan run from inside the network perimeter.

External scan
Show answer

A vulnerability scan run from outside the perimeter to show internet-facing exposure.

SAST
Show answer

Static Application Security Testing — analyzing source code or binaries for flaws without running the application.

DAST
Show answer

Dynamic Application Security Testing — testing a running application from the outside for exploitable flaws.

Software composition analysis (SCA)
Show answer

Scanning an application's third-party and open-source components for known vulnerabilities and license risk.

IaC scanning
Show answer

Scanning infrastructure-as-code templates for misconfigurations before deployment.

Nessus / OpenVAS
Show answer

Widely used vulnerability scanners that identify and report known vulnerabilities across assets.

False positive (scan)
Show answer

A reported vulnerability that is not actually present or exploitable; must be validated before acting.

False negative (scan)
Show answer

A real vulnerability the scanner failed to report — the more dangerous error.

True positive
Show answer

A correctly reported, confirmed vulnerability that proceeds to prioritization and remediation.

Validation (vuln)
Show answer

Confirming a finding is real and exploitable — via manual checks, correlating tools, and verifying the configuration.

Context-aware prioritization
Show answer

Ranking vulnerabilities by combining CVSS with asset value, exposure, criticality, and active exploitation.

Zero-day
Show answer

A vulnerability unknown to the vendor with no patch available, leaving 'zero days' to fix it before exploitation.

Exploitability
Show answer

How feasible it is to exploit a vulnerability, including whether a working exploit exists in the wild.

Weaponization
Show answer

Turning a vulnerability into a usable exploit or payload.

Compensating control
Show answer

An alternative safeguard used when the primary control (e.g., a patch) cannot be applied, to reduce residual risk.

Patch management
Show answer

The process of acquiring, testing, and applying updates to remediate vulnerabilities.

SQL injection
Show answer

Inserting malicious SQL into input so the database runs unintended commands. Fix: parameterized queries + input validation.

Cross-site scripting (XSS)
Show answer

Injecting script into a trusted site that runs in another user's browser. Fix: output encoding + Content Security Policy.

Broken access control
Show answer

Missing or flawed authorization checks. Fix: enforce least privilege and deny by default.

Cryptographic failures
Show answer

Weak or missing encryption of sensitive data. Fix: strong algorithms, proper key management, and TLS.

Buffer overflow
Show answer

Writing more data than a buffer holds, overwriting adjacent memory. Fix: bounds checking, ASLR/DEP, secure coding.

Data poisoning
Show answer

Corrupting the training data of a machine-learning model so it behaves incorrectly.

Insecure deserialization
Show answer

Processing untrusted serialized data unsafely, potentially allowing code execution.

SLO (vuln response)
Show answer

Service-Level Objective — a target timeframe for remediating vulnerabilities by severity.

Threat modeling
Show answer

Systematically identifying potential threats and weaknesses in a design so they can be mitigated early.

Secure SDLC
Show answer

Building security into every phase of the software development lifecycle.

OWASP Top 10
Show answer

OWASP's regularly updated list of the most critical web-application security risks.

CVSS vector string
Show answer

A compact text encoding of a vulnerability's CVSS metrics (e.g., AV:N/AC:L/PR:N) used to compute the score.

User interaction (UI)
Show answer

A CVSS base metric for whether exploitation requires a user to take some action.

Confidentiality impact (CVSS)
Show answer

A CVSS base metric rating the loss of confidentiality if the vulnerability is exploited.

Patch (n-day)
Show answer

Once a patch is released, an unpatched flaw is an 'n-day' — still dangerous on unpatched systems.

Vulnerability vs. exploit
Show answer

A vulnerability is a weakness; an exploit is the code or technique that takes advantage of it.

Vulnerability vs. threat
Show answer

A vulnerability is a weakness; a threat is a potential danger that could exploit it.

Risk (vuln context)
Show answer

The potential for loss when a threat exploits a vulnerability; a function of likelihood and impact.

Misconfiguration
Show answer

An insecure default or setting (e.g., open cloud storage) — a leading cause of breaches; fix with secure baselines.

Default credentials
Show answer

Unchanged factory usernames/passwords that attackers easily abuse; a common scan finding.

Hardening
Show answer

Reducing a system's attack surface by removing unneeded services, applying secure baselines, and patching.

Secure baseline
Show answer

A defined, minimum-security configuration applied consistently across systems.

Patch testing
Show answer

Validating a patch in a controlled environment before deploying it broadly to avoid breakage.

Risk-based prioritization
Show answer

Ranking remediation by real-world risk (exposure, exploitability, asset value), not raw CVSS alone.

Remediation
Show answer

Eliminating a vulnerability by patching, reconfiguring, or replacing the affected component.

Mitigation
Show answer

Reducing the likelihood or impact of a vulnerability when full remediation isn't possible.

Web application scanner
Show answer

A tool that tests web apps for flaws like injection, XSS, and misconfiguration.

Network vulnerability scanner
Show answer

A tool that probes networked hosts and services for known vulnerabilities.

Directory traversal
Show answer

An attack that accesses files outside the intended directory via crafted path input ('../').

CSRF
Show answer

Cross-Site Request Forgery — tricking a logged-in user's browser into submitting an unwanted request.

Race condition
Show answer

A flaw where timing between a check and use (TOCTOU) can be exploited.

SSRF
Show answer

Server-Side Request Forgery — coercing a server into making requests to unintended internal resources.

Privilege creep
Show answer

The gradual accumulation of access rights a user no longer needs; reduced by access reviews.

Patch prioritization
Show answer

Sequencing patches by severity, exposure, and exploitability rather than applying all at once.

Asset criticality
Show answer

How important an asset is to the business; a key factor in prioritizing its vulnerabilities.

Exposure
Show answer

Whether a vulnerable asset is reachable (e.g., internet-facing); raises real-world risk.

Scanning cadence
Show answer

How often scans run; continuous or frequent scanning catches new vulnerabilities sooner.

Rescan / validation scan
Show answer

Scanning again after remediation to confirm the vulnerability is actually closed.

Vulnerability feed (NVD)
Show answer

The National Vulnerability Database — the U.S. government repository of CVEs and CVSS data.

Penetration test
Show answer

An authorized simulated attack that exploits weaknesses to demonstrate real-world impact.

Bug bounty
Show answer

A program that pays external researchers to responsibly disclose vulnerabilities.

Incident Response & Management (54)

Incident response lifecycle
Show answer

NIST's four phases: preparation; detection & analysis; containment, eradication & recovery; post-incident activity.

Preparation (IR)
Show answer

Building the team, tools, playbooks, training, logging, and communication plan before an incident occurs.

Detection & analysis (IR)
Show answer

Identifying and validating an incident from IoCs, SIEM alerts, and logs, then determining its scope and impact.

Containment
Show answer

Limiting the spread and impact of an incident (e.g., isolating a host) — usually the first action in a live incident.

Eradication
Show answer

Removing the threat — malware, attacker footholds, compromised accounts — from the environment.

Recovery (IR)
Show answer

Restoring affected systems to normal operation from known-good, tested backups and monitoring for reinfection.

Post-incident activity
Show answer

Lessons learned, root cause analysis, IoC generation, and reporting that feed back into preparation.

Root cause analysis
Show answer

Determining the underlying reason an incident occurred so the same issue can be prevented from recurring.

Lessons learned
Show answer

The post-incident review that captures what went well and what to improve for next time.

Scope determination
Show answer

Establishing how far an incident reaches — which systems, accounts, and data are affected.

Evidence acquisition
Show answer

Collecting data relevant to an incident in a forensically sound manner.

Evidence preservation
Show answer

Protecting collected evidence from alteration so it remains reliable and admissible.

Chain of custody
Show answer

The documented, unbroken record of who handled evidence and when — to keep it admissible.

Order of volatility
Show answer

Collecting evidence most-volatile-first (CPU/RAM, network state) before less-volatile data (disk, archives).

Forensic image
Show answer

A bit-for-bit copy of storage made for analysis so the original evidence is never altered; verified with a hash.

Write blocker
Show answer

A device or software that prevents any writes to evidence media during forensic acquisition.

Hashing (forensics)
Show answer

Computing a hash of evidence to prove it has not changed; the same hash means an exact, unaltered copy.

Legal hold
Show answer

A directive to preserve relevant data when litigation or an investigation is anticipated.

Memory forensics
Show answer

Analyzing a captured copy of RAM to find running malware, network connections, and artifacts not on disk.

Disk forensics
Show answer

Analyzing storage media (from a forensic image) for files, deleted data, and artifacts.

Cyber kill chain stages
Show answer

Reconnaissance, weaponization, delivery, exploitation, installation, command & control, and actions on objectives.

Reconnaissance (kill chain)
Show answer

The first kill-chain stage: gathering information about the target before attacking.

Weaponization (kill chain)
Show answer

Coupling an exploit with a deliverable payload (e.g., a malicious document).

Actions on objectives
Show answer

The final kill-chain stage where the attacker achieves their goal (e.g., data theft or destruction).

Diamond Model vertices
Show answer

Adversary, capability, infrastructure, and victim — the four core features linked in each intrusion event.

Pivoting (analysis)
Show answer

Using one known fact about an intrusion (e.g., an IP) to discover related facts, often via the Diamond Model.

MITRE ATT&CK tactic
Show answer

A column in the ATT&CK matrix representing an attacker's goal (e.g., persistence, exfiltration).

MITRE ATT&CK technique
Show answer

A specific method an attacker uses to achieve a tactic (e.g., a particular persistence mechanism).

OWASP
Show answer

Open Worldwide Application Security Project — a community producing resources like the OWASP Top 10.

Incident declaration
Show answer

The formal decision that an event is a security incident, triggering the response process.

Escalation (IR)
Show answer

Routing an incident to higher-tier responders or management based on severity and predefined criteria.

Communication plan (IR)
Show answer

The plan defining who is informed, how, and when during an incident — internal and external.

Tabletop exercise
Show answer

A discussion-based drill that walks a team through an incident scenario to test the plan and readiness.

Indicator of attack (IoA)
Show answer

Evidence of an attack in progress based on intent/behavior, as opposed to a backward-looking IoC.

Ransomware (IR)
Show answer

Malware that encrypts data and demands payment; recover from tested backups rather than paying.

Containment strategy
Show answer

Choosing between isolation, segmentation, or removal based on impact, evidence needs, and business continuity.

Isolation
Show answer

Disconnecting an affected system from the network to stop an incident from spreading.

Segmentation (containment)
Show answer

Restricting affected systems to a network segment to limit an incident while preserving some operation.

IR playbook
Show answer

A documented set of response steps for a specific incident type, ensuring a consistent response.

CSIRT / CIRT
Show answer

Computer Security Incident Response Team — the group responsible for handling incidents.

Eradication validation
Show answer

Confirming the threat and its persistence are fully removed before returning systems to service.

Threat actor
Show answer

An individual or group that carries out an attack — nation-state, organized crime, hacktivist, insider, or unskilled.

Nation-state actor
Show answer

A highly sophisticated, well-resourced adversary (APT) usually motivated by espionage or strategic disruption.

APT
Show answer

Advanced Persistent Threat — a skilled, well-resourced adversary that maintains long-term, stealthy access.

Insider threat
Show answer

A current or former employee, contractor, or partner who misuses authorized access to cause harm.

Hacktivist
Show answer

A threat actor motivated by an ideological cause rather than profit.

Indicators (IR)
Show answer

Observable signs of an incident — from IoCs and IoAs to anomalies in logs and behavior.

Timeline (incident)
Show answer

A chronological reconstruction of an incident's events, essential for root cause and reporting.

Scope creep (IR)
Show answer

Failing to bound an investigation, leading to wasted effort; scope determination prevents it.

Order of operations (IR)
Show answer

The correct sequence of response actions; getting it wrong can destroy evidence.

Reimaging
Show answer

Rebuilding a compromised host from a known-good image to ensure no attacker artifacts remain.

Known-good backup
Show answer

A verified, uncompromised backup used to restore systems during recovery.

Data exfiltration
Show answer

Unauthorized transfer of data out of an organization — a common attacker objective.

Command-and-control detection
Show answer

Identifying C2 channels (beaconing, unusual destinations) during analysis.

Reporting & Communication (43)

MTTD
Show answer

Mean Time to Detect — the average time from when an incident begins to when it is detected.

MTTR
Show answer

Mean Time to Respond/Remediate — the average time to contain and resolve an incident or remediate a vulnerability.

MTTA
Show answer

Mean Time to Acknowledge — the average time from an alert to a responder acknowledging it.

MTTC
Show answer

Mean Time to Contain — the average time to stop an incident from spreading once it is detected.

KPI
Show answer

Key Performance Indicator — a measurable value (e.g., MTTD, MTTR, recurrence) showing how a program performs.

Recurrence rate
Show answer

A metric tracking how often the same vulnerability or incident type reappears.

Top vulnerabilities (metric)
Show answer

A report of the most frequent or highest-risk vulnerabilities, used to focus remediation.

Risk score
Show answer

A combined measure of a finding's likelihood and impact used to prioritize and communicate risk.

Stakeholder
Show answer

Anyone who needs incident or vulnerability information — technical teams, executives, legal, HR, PR, customers, or regulators.

Stakeholder identification
Show answer

Determining who must receive which information so the right message reaches the right audience.

Compliance report
Show answer

A report demonstrating that vulnerability or security posture meets a regulatory or contractual requirement.

Action plan
Show answer

A report pairing each finding with an owner, remediation steps, and a realistic timeline.

Inhibitor to remediation
Show answer

A real-world constraint (MOU/SLA, business interruption, legacy system, downtime cost) that delays or prevents a fix.

MOU
Show answer

Memorandum of Understanding — a non-binding agreement outlining mutual intentions between parties.

SLA
Show answer

Service Level Agreement — a contract defining expected service levels and metrics with a provider.

Business process interruption
Show answer

An inhibitor where patching requires downtime the business cannot yet absorb.

Degrading functionality
Show answer

An inhibitor where a fix breaks a needed feature or integration.

Legacy system (inhibitor)
Show answer

An older or proprietary system with no available patch — mitigate with compensating controls.

Accepted residual risk
Show answer

The remaining risk an organization knowingly and formally accepts after applying controls.

Indicator of compromise generation
Show answer

Producing new IoCs from an incident so detection can be improved going forward.

Incident report
Show answer

A document summarizing what happened, impact, timeline, root cause, response, and lessons learned.

Executive summary
Show answer

A concise, business-focused overview of an incident or assessment for leadership.

Technical report
Show answer

A detailed report for responders covering timeline, affected systems, root cause, and remediation.

Breach notification
Show answer

A required disclosure to regulators and affected individuals after a data breach, within set timeframes.

Metrics dashboard
Show answer

A visual summary of security KPIs (MTTD, MTTR, open vulnerabilities) for ongoing monitoring.

Trend analysis
Show answer

Tracking metrics over time to show whether the security program is improving or declining.

Audience tailoring
Show answer

Adjusting a report's depth and framing for its audience — risk for executives, detail for technical teams.

Governance (reporting)
Show answer

The policies and oversight structures that direct how vulnerabilities and incidents are reported and handled.

Vulnerability report
Show answer

A report communicating findings, severity, affected assets, and remediation guidance to stakeholders.

Remediation timeline
Show answer

A realistic schedule for fixing findings that accounts for inhibitors and SLOs.

Owner (action plan)
Show answer

The person or team accountable for remediating a specific finding.

Escalation criteria
Show answer

Predefined thresholds that determine when to notify higher tiers or management.

Communication matrix
Show answer

A table mapping stakeholders to what information they receive and through which channel.

Regulatory reporting
Show answer

Disclosing incidents or compliance status to regulators as required by law or contract.

PR / public communication
Show answer

Coordinated external messaging about an incident to customers and the public.

Legal stakeholder
Show answer

Counsel involved to manage liability, evidence, and breach-notification obligations.

HR stakeholder
Show answer

Human Resources, engaged when an incident involves an employee (e.g., insider threat).

Customer notification
Show answer

Informing affected customers of a breach within legally required timeframes.

Metrics maturity
Show answer

Improving MTTD/MTTR and recurrence over time as a sign of a maturing security program.

Closed-loop reporting
Show answer

Feeding lessons learned and generated IoCs back into detection and preparation.

Risk register (reporting)
Show answer

A documented list of risks with owner, likelihood, impact, and treatment, referenced in reports.

Compliance vs. security
Show answer

Compliance proves a standard is met; security reduces actual risk — they overlap but aren't identical.

Evidence in reports
Show answer

Including verified facts and, where needed, forensic findings (with chain of custody) to support conclusions.

References

  1. 1.CompTIA. “CompTIA CySA+ (CS0-003) Certification.” comptia.org. ↑
  2. 2.CompTIA. “CySA+ (CS0-003) Exam Objectives.” comptia.org. ↑
  3. 3.Forum of Incident Response and Security Teams. “Common Vulnerability Scoring System (CVSS).” first.org. ↑
Career Employer

Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.

Follow Us:

All Posts

Career Employer’s Editorial Process

Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.