Click Study Flashcards above to open the flashcard hub — hundreds of CySA+ cards you can flip, match, type, or quiz yourself on. Every card is drawn from the four official CS0-003 domains, so you study exactly what the exam tests.[2]
Pair them with our free practice test and study guide. Want extra insurance for exam day? Capital Prep’s CySA+ premium study materials come with a CySA+ exam pass guarantee: your money back if you don’t pass, plus up to $439 toward your retake fee — and Career Employer students get a special discount.
CompTIA CySA+ is one of the 14 CompTIA certifications — explore our CompTIA flashcards to compare and prep across the whole family.
CySA+ Flashcard Study Modes
Flip mode walks you card by card for first-pass study, Match turns terms and definitions into a timed pairing game, Type shows a definition and asks you to produce the term from memory, and Quiz builds multiple-choice questions from the same deck. A short acronym like EDR is exactly the kind of front Type drills, since recognizing it is easier than recalling it cold.

Why Flashcards Work for CySA+
Security Operations is the heaviest domain at 33% of the exam and the largest block in the deck with 98 cards. The fronts run from monitoring and detection tooling to identity and email controls, so you will meet EDR and XDR alongside SDN, and separately work through SPF, DLP and MFA. Attacker behavior language shows up here too, including TTP and IAM, which pay off later when you read alerts and describe what a sensor actually saw.
Vulnerability Management carries 30% of the exam and 79 cards. This block drills the identification and scoring vocabulary you need to triage findings: CVE and CWE for cataloging, CVSS for severity, and Zero-day for the case where no patch exists. Testing methods get their own fronts, so SAST and DAST sit near web weakness terms such as CSRF and SSRF that you have to tell apart under time pressure.
Incident Response & Management accounts for 20% of the exam and 54 cards. The terms track the lifecycle and the people in it, with Containment and Eradication as process steps, Isolation and Reimaging as hands-on responses, and Legal hold for the evidence side. Threat actor labels such as APT and Hacktivist appear here, as does OWASP, which ties attacker technique back to the vulnerability work.
Reporting & Communication closes the deck with 43 cards and 17% of the exam. These fronts cover the metrics and agreements you use to brief stakeholders, including MTTD, MTTR and MTTA, along with MTTC for the closing side of the timeline. Governance vocabulary rounds it out through SLA and MOU, and Risk score and KPI give you the language for summarizing posture to a non-technical audience.
CySA+ is dense with terminology — detection methods, indicators of compromise, the CVSS metric groups, attack frameworks, the incident-response lifecycle, forensics, and reporting metrics.[2] Spaced flashcards are the most efficient way to keep it all fresh. Used alongside our practice test and study guide, they turn review time into measurable progress.
CySA+ Flashcards by Domain
The cards are organized by the four official CS0-003 domains. Drill the highest-weighted ones first — Security Operations and Vulnerability Management make up nearly two-thirds of the exam:[2]
| Domain | Exam weight |
|---|---|
| Security Operations | 33% |
| Vulnerability Management | 30% |
| Incident Response and Management | 20% |
| Reporting and Communication | 17% |
How to Get the Most Out of These Flashcards
- Start with the biggest block. Security Operations is 33% of the exam and 98 cards, so clear it in Flip mode first and let its tooling vocabulary anchor everything you study afterward.
- Type-drill the confusable pairs. Fronts like CSRF and SSRF, or SAST and DAST, feel obvious in Flip but collapse under recall, which is exactly what Type mode exposes.
- Use Match for the acronym sets. Metric fronts such as MTTD, MTTR and MTTA pair fastest under timed pressure, and Match forces you to separate them instead of reading them as one cluster.
- Move to the practice test once recall holds. When Quiz mode stops surprising you across all four domains, switch to the practice test for scenario questions and use the study guide to fill any gaps it reveals.
- Set a steady cadence across 274 cards. Take one domain per session, re-Flip yesterday’s misses first, and finish each session with a Quiz round mixing the domain you just studied with an earlier one.
CySA+ Flashcards FAQ
Hundreds of free CySA+ flashcards, organized across all four CS0-003 domains — Security Operations, Vulnerability Management, Incident Response and Management, and Reporting and Communication. They're free with no account required.
Yes. Flashcards use active recall — retrieving an answer from memory — which research shows is one of the most effective study methods, especially in short, spaced sessions. CySA+ is dense with terminology (detection methods, CVSS metrics, attack frameworks, forensics, metrics), which is exactly what flashcards drill best.
All four CS0-003 domains: Security Operations (SIEM/log analysis, IoCs, threat intelligence and hunting, MITRE ATT&CK), Vulnerability Management (scanning, CVSS, prioritization, mitigations), Incident Response and Management (the NIST lifecycle, forensics, chain of custody), and Reporting and Communication (metrics like MTTD/MTTR, stakeholders, inhibitors).
Lead with the highest-weighted domains — Security Operations (33%) and Vulnerability Management (30%) — then drill Incident Response and Reporting. Mix the modes: flip to learn, type to test recall, match for speed, and quiz to check yourself before a full practice test.
Yes — 100% free, all four study modes, no paywall.
The cards are organized to CompTIA's CS0-003 (V3) exam objectives, covering all four scored domains in their official proportions. CompTIA launched the newer V4 exam (CS0-004) on June 23, 2026 with reweighted domains (34/26/24/16), and CS0-003 retires in English on December 22, 2026. The deck emphasizes behavioral analytics, threat intelligence, and CVSS-based prioritization.
CySA+ flashcard bank
All 274 cards, by topic
A reference copy of every card in this deck. Each answer stays hidden until you choose to show it. To study with Flip, Match, Type and Quiz modes and track what you have mastered, use Study Flashcards at the top of the page.
Security Operations (98)
- SIEM
Show answerHide answer
Security Information and Event Management — collects and correlates logs across the enterprise to detect, investigate, and report on threats.
- Indicator of compromise (IoC)
Show answerHide answer
A forensic artifact (malicious IP/domain, file hash, registry key, beaconing) that signals a system may have been breached.
- Signature-based detection
Show answerHide answer
Detection that matches known patterns (hashes, rules, byte sequences). Precise on known threats but blind to novel ones.
- Anomaly-based detection
Show answerHide answer
Detection that flags deviations from a defined baseline of normal activity; catches unknown threats but needs a good baseline.
- Behavioral analytics
Show answerHide answer
Detecting threats by modeling normal user, host, and network behavior and flagging deviations — finds insider and novel threats.
- Heuristic detection
Show answerHide answer
Detection that identifies threats by characteristics/rules of suspicious behavior rather than exact signatures.
- UEBA
Show answerHide answer
User and Entity Behavior Analytics — uses machine learning to baseline normal behavior and detect anomalies like compromised accounts.
- Threat intelligence
Show answerHide answer
Evidence-based knowledge about adversaries — actors, their TTPs, and indicators — used to inform and improve defense.
- Threat-intelligence cycle
Show answerHide answer
The repeating process: planning & direction → collection → processing → analysis → dissemination → feedback.
- Strategic threat intelligence
Show answerHide answer
High-level intelligence on trends and risk, aimed at executives and long-term decision-making.
- Operational threat intelligence
Show answerHide answer
Intelligence about specific campaigns and adversary operations, aimed at defenders.
- Tactical threat intelligence
Show answerHide answer
Technical, immediate intelligence — IoCs and TTPs — consumed by security tools and analysts.
- TTP
Show answerHide answer
Tactics, Techniques, and Procedures — how an adversary operates; the most durable, hardest-to-change indicator.
- Confidence level (threat intel)
Show answerHide answer
An assessment of how reliable a piece of intelligence is, so consumers know how much to trust it.
- MITRE ATT&CK
Show answerHide answer
A knowledge base of real-world adversary tactics (goals) and techniques (methods) used to map detections and drive threat hunting.
- Threat hunting
Show answerHide answer
The proactive, hypothesis-driven search for adversaries that have evaded existing detections, before any alert fires.
- Dwell time
Show answerHide answer
The length of time an attacker remains undetected in an environment; threat hunting aims to reduce it.
- STIX
Show answerHide answer
Structured Threat Information Expression — a standardized language for representing and sharing cyber threat intelligence.
- TAXII
Show answerHide answer
Trusted Automated Exchange of Intelligence Information — the protocol for transporting STIX threat-intelligence data.
- ISAC / ISAO
Show answerHide answer
Information Sharing and Analysis Center/Organization — communities that share threat intelligence among members.
- OSINT
Show answerHide answer
Open-Source Intelligence — intelligence gathered from publicly available sources.
- Zero trust
Show answerHide answer
A model that removes implicit trust and verifies every request based on identity, device, and context — 'never trust, always verify.'
- SASE
Show answerHide answer
Secure Access Service Edge — converges networking (SD-WAN) and security (SWG, CASB, ZTNA, FWaaS) into one cloud-delivered service.
- Network segmentation
Show answerHide answer
Dividing a network into zones to limit lateral movement and contain the blast radius of a compromise.
- SDN
Show answerHide answer
Software-Defined Networking — separates the network control plane from the data plane for centralized, programmable control.
- SOAR
Show answerHide answer
Security Orchestration, Automation, and Response — automates and coordinates incident response via playbooks and tool integrations.
- Playbook
Show answerHide answer
A documented, repeatable set of response steps for a given alert or incident type, often automated through SOAR.
- Packet capture
Show answerHide answer
Recording raw network traffic (e.g., with tcpdump or Wireshark) so analysts can inspect its contents and flow.
- Wireshark
Show answerHide answer
A graphical packet-capture and protocol-analysis tool used to inspect network traffic in detail.
- tcpdump
Show answerHide answer
A command-line packet-capture tool for recording and inspecting network traffic.
- NetFlow
Show answerHide answer
A protocol that records metadata about network flows (who talked to whom, when, how much) — useful for spotting beaconing and exfiltration.
- Log analysis
Show answerHide answer
Reviewing and correlating system, network, and application logs to detect, scope, and investigate suspicious activity.
- EDR
Show answerHide answer
Endpoint Detection and Response — continuously monitors endpoints to detect, investigate, and respond to threats.
- XDR
Show answerHide answer
Extended Detection and Response — correlates detection and response across endpoints, network, email, and cloud.
- SPF
Show answerHide answer
Sender Policy Framework — a DNS record listing the mail servers authorized to send email for a domain.
- DKIM
Show answerHide answer
DomainKeys Identified Mail — a cryptographic signature on outbound email so receivers can detect tampering and forged senders.
- DMARC
Show answerHide answer
Domain-based Message Authentication, Reporting & Conformance — ties SPF and DKIM together and tells receivers how to handle failures.
- Email header analysis
Show answerHide answer
Examining headers (Received, Authentication-Results) to trace an email's path and verify SPF/DKIM/DMARC results.
- Phishing
Show answerHide answer
A social-engineering attack using fraudulent messages to steal credentials, deliver malware, or trick users into actions.
- Spear phishing
Show answerHide answer
A phishing attack targeted at a specific individual or organization, using personalized details.
- Whaling
Show answerHide answer
A phishing attack that targets high-value executives such as a CEO or CFO.
- Vishing
Show answerHide answer
Voice phishing — a social-engineering attack carried out over a phone call.
- Smishing
Show answerHide answer
SMS phishing — a social-engineering attack delivered by text message.
- Business email compromise (BEC)
Show answerHide answer
An attack impersonating a trusted executive or vendor to authorize fraudulent payments or data transfers.
- On-path attack
Show answerHide answer
An attacker secretly relaying or altering traffic between two parties (formerly 'man-in-the-middle').
- DDoS
Show answerHide answer
Distributed Denial of Service — overwhelming a target with traffic from many sources to make it unavailable.
- DNS poisoning
Show answerHide answer
Corrupting DNS resolution so victims are sent to attacker-controlled addresses.
- ARP poisoning
Show answerHide answer
Sending forged ARP messages to associate the attacker's MAC with a victim's IP, enabling interception on a LAN.
- Beaconing
Show answerHide answer
Periodic, regular network callbacks from a compromised host to a command-and-control server.
- Command and control (C2)
Show answerHide answer
The channel and infrastructure an attacker uses to remotely control compromised systems.
- Living off the land
Show answerHide answer
Using legitimate, built-in system tools (e.g., PowerShell, WMI) to carry out an attack and evade detection.
- Obfuscation
Show answerHide answer
Deliberately making code or data hard to understand to evade detection or analysis.
- Regular expression (regex)
Show answerHide answer
A pattern-matching syntax analysts use to search and filter logs and data.
- False positive (alert)
Show answerHide answer
An alert that flags benign activity as malicious — a source of analyst alert fatigue.
- Alert fatigue
Show answerHide answer
Desensitization caused by too many alerts (often from an untuned SIEM), risking missed real threats.
- Sandboxing
Show answerHide answer
Running suspicious code in an isolated environment to observe its behavior safely.
- File integrity monitoring (FIM)
Show answerHide answer
Alerting when critical files change unexpectedly, indicating possible tampering.
- DLP
Show answerHide answer
Data Loss Prevention — tools that detect and block unauthorized movement of sensitive data.
- Cyber kill chain
Show answerHide answer
Lockheed Martin's linear 7-stage intrusion model used to detect and disrupt attacks early.
- Diamond Model
Show answerHide answer
An intrusion-analysis model linking four features of every event: adversary, capability, infrastructure, and victim.
- CIA triad
Show answerHide answer
Confidentiality, Integrity, Availability — the three core goals of information security.
- Confidentiality
Show answerHide answer
Ensuring only authorized people can read data; enforced by encryption and access control.
- Integrity
Show answerHide answer
Ensuring data is accurate and unaltered; enforced by hashing and digital signatures.
- Availability
Show answerHide answer
Ensuring authorized users can access data and systems when needed; enforced by redundancy and backups.
- IAM
Show answerHide answer
Identity and Access Management — the policies and tools that manage digital identities and control access.
- MFA
Show answerHide answer
Multi-factor authentication — requiring two or more factors from different categories (know, have, are).
- Least privilege
Show answerHide answer
Granting only the minimum access needed to perform a task, limiting the blast radius of a compromise.
- Encryption
Show answerHide answer
Transforming data so only authorized parties with the key can read it; protects confidentiality.
- Symmetric encryption
Show answerHide answer
Encryption using one shared secret key to both encrypt and decrypt (e.g., AES) — fast.
- Asymmetric encryption
Show answerHide answer
Encryption using a public/private key pair (e.g., RSA, ECC) for key exchange and digital signatures.
- Hashing
Show answerHide answer
A one-way function producing a fixed-length digest (e.g., SHA-256); used for integrity, not reversible.
- Honeypot
Show answerHide answer
A decoy system that lures attackers away from real assets and records their behavior.
- Honeytoken
Show answerHide answer
Fake data (a credential, record, or key) that signals compromise the moment it is used.
- Malware
Show answerHide answer
Malicious software — ransomware, trojans, worms, viruses, spyware, rootkits, and keyloggers.
- Rootkit
Show answerHide answer
Malware that hides deep in the system (often the kernel) to maintain stealthy, privileged access.
- Trojan
Show answerHide answer
Malware disguised as legitimate software that performs a hidden malicious action when run.
- Lateral movement
Show answerHide answer
An attacker moving from an initial foothold to other systems within the network.
- Privilege escalation
Show answerHide answer
Gaining higher access rights than granted — vertical (to admin) or horizontal (to another user).
- Persistence
Show answerHide answer
Techniques an attacker uses to maintain access across reboots and credential changes.
- Endpoint analysis
Show answerHide answer
Examining a host for malicious processes, persistence, and artifacts during detection or response.
- Email analysis
Show answerHide answer
Examining messages, attachments, and headers for phishing, spoofing, and malicious payloads.
- File analysis
Show answerHide answer
Inspecting a file's properties, hash, and behavior to determine if it is malicious.
- Sentiment / anomaly baseline
Show answerHide answer
A reference profile of normal activity against which anomaly detection compares current behavior.
- Scripting (CySA+)
Show answerHide answer
Reading Python, PowerShell, shell, or JavaScript snippets and regex to analyze and automate — not writing production code.
- API integration
Show answerHide answer
Connecting security tools through APIs and webhooks to share data and automate workflows.
- Standardization (process)
Show answerHide answer
Defining consistent processes and configurations to reduce error and enable automation.
- Orchestration
Show answerHide answer
Coordinating multiple security tools and tasks into a unified, often automated, workflow.
- Syslog
Show answerHide answer
A standard protocol for forwarding log messages, commonly aggregated centrally by a SIEM.
- Windows Event Log
Show answerHide answer
The Windows logging system (Security, System, Application logs) analysts review for host activity.
- Sysmon
Show answerHide answer
A Windows system-monitoring tool that logs detailed process, network, and file events for analysis.
- Log correlation
Show answerHide answer
Linking events across multiple sources to reveal an attack that no single log shows alone.
- Use case (SIEM)
Show answerHide answer
A defined detection scenario with the logic and data sources needed to catch a specific threat.
- Tuning (SIEM)
Show answerHide answer
Adjusting detection rules and thresholds to reduce false positives and surface true threats.
- Threat feed
Show answerHide answer
A stream of indicators (IPs, domains, hashes) consumed to enrich detection and hunting.
- Pyramid of Pain
Show answerHide answer
A model ranking indicators by how much disrupting them hurts an attacker — TTPs hurt most, hashes least.
- CASB
Show answerHide answer
Cloud Access Security Broker — enforces security policy between users and cloud services.
- ZTNA
Show answerHide answer
Zero Trust Network Access — grants per-application access based on identity and context, not network location.
- Geofencing / impossible travel
Show answerHide answer
Detecting logins from locations too far apart in time to be legitimate.
Vulnerability Management (79)
- CVSS
Show answerHide answer
Common Vulnerability Scoring System — a 0.0–10.0 score (Base, Temporal, Environmental groups) rating a vulnerability's severity.
- CVSS Base metrics
Show answerHide answer
The intrinsic, constant severity: attack vector, attack complexity, privileges required, user interaction, scope, and CIA impact.
- CVSS Temporal metrics
Show answerHide answer
Severity factors that change over time: exploit code maturity, remediation level, and report confidence.
- CVSS Environmental metrics
Show answerHide answer
Severity tailored to your organization, including asset-value (CIA) requirements and modified base metrics.
- CVSS severity bands
Show answerHide answer
None 0.0, Low 0.1–3.9, Medium 4.0–6.9, High 7.0–8.9, Critical 9.0–10.0.
- Attack vector (AV)
Show answerHide answer
A CVSS base metric describing how a vulnerability is exploited: Network, Adjacent, Local, or Physical.
- Attack complexity (AC)
Show answerHide answer
A CVSS base metric for how hard the attack is to carry out beyond the attacker's control.
- Privileges required (PR)
Show answerHide answer
A CVSS base metric for the level of access an attacker needs before exploiting the flaw.
- Scope (CVSS)
Show answerHide answer
A CVSS base metric indicating whether exploiting the vulnerability impacts resources beyond its security scope.
- CVE
Show answerHide answer
Common Vulnerabilities and Exposures — a unique public identifier for one specific known vulnerability.
- CWE
Show answerHide answer
Common Weakness Enumeration — a catalog of software and hardware weakness types.
- Vulnerability management
Show answerHide answer
The continuous cycle of identifying, scanning, analyzing, prioritizing, remediating, validating, and reporting on vulnerabilities.
- Asset discovery
Show answerHide answer
Inventorying and mapping the systems and services in an environment — the first step in vulnerability management.
- Attack surface
Show answerHide answer
The total set of points where an attacker could attempt to enter or extract data; reducing it is a core goal.
- Attack surface management
Show answerHide answer
Continuously discovering, inventorying, and reducing an organization's exposed footprint.
- Active scanning
Show answerHide answer
Scanning that sends probes directly to targets — thorough but can disrupt fragile systems.
- Passive scanning
Show answerHide answer
Identifying assets and issues by observing existing traffic without sending probes — non-disruptive but less complete.
- Credentialed scan
Show answerHide answer
A vulnerability scan that logs into the target — deeper, more accurate, fewer false positives.
- Non-credentialed scan
Show answerHide answer
A scan that probes only from the outside, like an unauthenticated attacker — a shallower, attacker's-eye view.
- Agent-based scan
Show answerHide answer
A scan run by software installed on the host; works offline and for roaming assets.
- Agentless scan
Show answerHide answer
A scan run from the network with no software installed on the target.
- Internal scan
Show answerHide answer
A vulnerability scan run from inside the network perimeter.
- External scan
Show answerHide answer
A vulnerability scan run from outside the perimeter to show internet-facing exposure.
- SAST
Show answerHide answer
Static Application Security Testing — analyzing source code or binaries for flaws without running the application.
- DAST
Show answerHide answer
Dynamic Application Security Testing — testing a running application from the outside for exploitable flaws.
- Software composition analysis (SCA)
Show answerHide answer
Scanning an application's third-party and open-source components for known vulnerabilities and license risk.
- IaC scanning
Show answerHide answer
Scanning infrastructure-as-code templates for misconfigurations before deployment.
- Nessus / OpenVAS
Show answerHide answer
Widely used vulnerability scanners that identify and report known vulnerabilities across assets.
- False positive (scan)
Show answerHide answer
A reported vulnerability that is not actually present or exploitable; must be validated before acting.
- False negative (scan)
Show answerHide answer
A real vulnerability the scanner failed to report — the more dangerous error.
- True positive
Show answerHide answer
A correctly reported, confirmed vulnerability that proceeds to prioritization and remediation.
- Validation (vuln)
Show answerHide answer
Confirming a finding is real and exploitable — via manual checks, correlating tools, and verifying the configuration.
- Context-aware prioritization
Show answerHide answer
Ranking vulnerabilities by combining CVSS with asset value, exposure, criticality, and active exploitation.
- Zero-day
Show answerHide answer
A vulnerability unknown to the vendor with no patch available, leaving 'zero days' to fix it before exploitation.
- Exploitability
Show answerHide answer
How feasible it is to exploit a vulnerability, including whether a working exploit exists in the wild.
- Weaponization
Show answerHide answer
Turning a vulnerability into a usable exploit or payload.
- Compensating control
Show answerHide answer
An alternative safeguard used when the primary control (e.g., a patch) cannot be applied, to reduce residual risk.
- Patch management
Show answerHide answer
The process of acquiring, testing, and applying updates to remediate vulnerabilities.
- SQL injection
Show answerHide answer
Inserting malicious SQL into input so the database runs unintended commands. Fix: parameterized queries + input validation.
- Cross-site scripting (XSS)
Show answerHide answer
Injecting script into a trusted site that runs in another user's browser. Fix: output encoding + Content Security Policy.
- Broken access control
Show answerHide answer
Missing or flawed authorization checks. Fix: enforce least privilege and deny by default.
- Cryptographic failures
Show answerHide answer
Weak or missing encryption of sensitive data. Fix: strong algorithms, proper key management, and TLS.
- Buffer overflow
Show answerHide answer
Writing more data than a buffer holds, overwriting adjacent memory. Fix: bounds checking, ASLR/DEP, secure coding.
- Data poisoning
Show answerHide answer
Corrupting the training data of a machine-learning model so it behaves incorrectly.
- Insecure deserialization
Show answerHide answer
Processing untrusted serialized data unsafely, potentially allowing code execution.
- SLO (vuln response)
Show answerHide answer
Service-Level Objective — a target timeframe for remediating vulnerabilities by severity.
- Threat modeling
Show answerHide answer
Systematically identifying potential threats and weaknesses in a design so they can be mitigated early.
- Secure SDLC
Show answerHide answer
Building security into every phase of the software development lifecycle.
- OWASP Top 10
Show answerHide answer
OWASP's regularly updated list of the most critical web-application security risks.
- CVSS vector string
Show answerHide answer
A compact text encoding of a vulnerability's CVSS metrics (e.g., AV:N/AC:L/PR:N) used to compute the score.
- User interaction (UI)
Show answerHide answer
A CVSS base metric for whether exploitation requires a user to take some action.
- Confidentiality impact (CVSS)
Show answerHide answer
A CVSS base metric rating the loss of confidentiality if the vulnerability is exploited.
- Patch (n-day)
Show answerHide answer
Once a patch is released, an unpatched flaw is an 'n-day' — still dangerous on unpatched systems.
- Vulnerability vs. exploit
Show answerHide answer
A vulnerability is a weakness; an exploit is the code or technique that takes advantage of it.
- Vulnerability vs. threat
Show answerHide answer
A vulnerability is a weakness; a threat is a potential danger that could exploit it.
- Risk (vuln context)
Show answerHide answer
The potential for loss when a threat exploits a vulnerability; a function of likelihood and impact.
- Misconfiguration
Show answerHide answer
An insecure default or setting (e.g., open cloud storage) — a leading cause of breaches; fix with secure baselines.
- Default credentials
Show answerHide answer
Unchanged factory usernames/passwords that attackers easily abuse; a common scan finding.
- Hardening
Show answerHide answer
Reducing a system's attack surface by removing unneeded services, applying secure baselines, and patching.
- Secure baseline
Show answerHide answer
A defined, minimum-security configuration applied consistently across systems.
- Patch testing
Show answerHide answer
Validating a patch in a controlled environment before deploying it broadly to avoid breakage.
- Risk-based prioritization
Show answerHide answer
Ranking remediation by real-world risk (exposure, exploitability, asset value), not raw CVSS alone.
- Remediation
Show answerHide answer
Eliminating a vulnerability by patching, reconfiguring, or replacing the affected component.
- Mitigation
Show answerHide answer
Reducing the likelihood or impact of a vulnerability when full remediation isn't possible.
- Web application scanner
Show answerHide answer
A tool that tests web apps for flaws like injection, XSS, and misconfiguration.
- Network vulnerability scanner
Show answerHide answer
A tool that probes networked hosts and services for known vulnerabilities.
- Directory traversal
Show answerHide answer
An attack that accesses files outside the intended directory via crafted path input ('../').
- CSRF
Show answerHide answer
Cross-Site Request Forgery — tricking a logged-in user's browser into submitting an unwanted request.
- Race condition
Show answerHide answer
A flaw where timing between a check and use (TOCTOU) can be exploited.
- SSRF
Show answerHide answer
Server-Side Request Forgery — coercing a server into making requests to unintended internal resources.
- Privilege creep
Show answerHide answer
The gradual accumulation of access rights a user no longer needs; reduced by access reviews.
- Patch prioritization
Show answerHide answer
Sequencing patches by severity, exposure, and exploitability rather than applying all at once.
- Asset criticality
Show answerHide answer
How important an asset is to the business; a key factor in prioritizing its vulnerabilities.
- Exposure
Show answerHide answer
Whether a vulnerable asset is reachable (e.g., internet-facing); raises real-world risk.
- Scanning cadence
Show answerHide answer
How often scans run; continuous or frequent scanning catches new vulnerabilities sooner.
- Rescan / validation scan
Show answerHide answer
Scanning again after remediation to confirm the vulnerability is actually closed.
- Vulnerability feed (NVD)
Show answerHide answer
The National Vulnerability Database — the U.S. government repository of CVEs and CVSS data.
- Penetration test
Show answerHide answer
An authorized simulated attack that exploits weaknesses to demonstrate real-world impact.
- Bug bounty
Show answerHide answer
A program that pays external researchers to responsibly disclose vulnerabilities.
Incident Response & Management (54)
- Incident response lifecycle
Show answerHide answer
NIST's four phases: preparation; detection & analysis; containment, eradication & recovery; post-incident activity.
- Preparation (IR)
Show answerHide answer
Building the team, tools, playbooks, training, logging, and communication plan before an incident occurs.
- Detection & analysis (IR)
Show answerHide answer
Identifying and validating an incident from IoCs, SIEM alerts, and logs, then determining its scope and impact.
- Containment
Show answerHide answer
Limiting the spread and impact of an incident (e.g., isolating a host) — usually the first action in a live incident.
- Eradication
Show answerHide answer
Removing the threat — malware, attacker footholds, compromised accounts — from the environment.
- Recovery (IR)
Show answerHide answer
Restoring affected systems to normal operation from known-good, tested backups and monitoring for reinfection.
- Post-incident activity
Show answerHide answer
Lessons learned, root cause analysis, IoC generation, and reporting that feed back into preparation.
- Root cause analysis
Show answerHide answer
Determining the underlying reason an incident occurred so the same issue can be prevented from recurring.
- Lessons learned
Show answerHide answer
The post-incident review that captures what went well and what to improve for next time.
- Scope determination
Show answerHide answer
Establishing how far an incident reaches — which systems, accounts, and data are affected.
- Evidence acquisition
Show answerHide answer
Collecting data relevant to an incident in a forensically sound manner.
- Evidence preservation
Show answerHide answer
Protecting collected evidence from alteration so it remains reliable and admissible.
- Chain of custody
Show answerHide answer
The documented, unbroken record of who handled evidence and when — to keep it admissible.
- Order of volatility
Show answerHide answer
Collecting evidence most-volatile-first (CPU/RAM, network state) before less-volatile data (disk, archives).
- Forensic image
Show answerHide answer
A bit-for-bit copy of storage made for analysis so the original evidence is never altered; verified with a hash.
- Write blocker
Show answerHide answer
A device or software that prevents any writes to evidence media during forensic acquisition.
- Hashing (forensics)
Show answerHide answer
Computing a hash of evidence to prove it has not changed; the same hash means an exact, unaltered copy.
- Legal hold
Show answerHide answer
A directive to preserve relevant data when litigation or an investigation is anticipated.
- Memory forensics
Show answerHide answer
Analyzing a captured copy of RAM to find running malware, network connections, and artifacts not on disk.
- Disk forensics
Show answerHide answer
Analyzing storage media (from a forensic image) for files, deleted data, and artifacts.
- Cyber kill chain stages
Show answerHide answer
Reconnaissance, weaponization, delivery, exploitation, installation, command & control, and actions on objectives.
- Reconnaissance (kill chain)
Show answerHide answer
The first kill-chain stage: gathering information about the target before attacking.
- Weaponization (kill chain)
Show answerHide answer
Coupling an exploit with a deliverable payload (e.g., a malicious document).
- Actions on objectives
Show answerHide answer
The final kill-chain stage where the attacker achieves their goal (e.g., data theft or destruction).
- Diamond Model vertices
Show answerHide answer
Adversary, capability, infrastructure, and victim — the four core features linked in each intrusion event.
- Pivoting (analysis)
Show answerHide answer
Using one known fact about an intrusion (e.g., an IP) to discover related facts, often via the Diamond Model.
- MITRE ATT&CK tactic
Show answerHide answer
A column in the ATT&CK matrix representing an attacker's goal (e.g., persistence, exfiltration).
- MITRE ATT&CK technique
Show answerHide answer
A specific method an attacker uses to achieve a tactic (e.g., a particular persistence mechanism).
- OWASP
Show answerHide answer
Open Worldwide Application Security Project — a community producing resources like the OWASP Top 10.
- Incident declaration
Show answerHide answer
The formal decision that an event is a security incident, triggering the response process.
- Escalation (IR)
Show answerHide answer
Routing an incident to higher-tier responders or management based on severity and predefined criteria.
- Communication plan (IR)
Show answerHide answer
The plan defining who is informed, how, and when during an incident — internal and external.
- Tabletop exercise
Show answerHide answer
A discussion-based drill that walks a team through an incident scenario to test the plan and readiness.
- Indicator of attack (IoA)
Show answerHide answer
Evidence of an attack in progress based on intent/behavior, as opposed to a backward-looking IoC.
- Ransomware (IR)
Show answerHide answer
Malware that encrypts data and demands payment; recover from tested backups rather than paying.
- Containment strategy
Show answerHide answer
Choosing between isolation, segmentation, or removal based on impact, evidence needs, and business continuity.
- Isolation
Show answerHide answer
Disconnecting an affected system from the network to stop an incident from spreading.
- Segmentation (containment)
Show answerHide answer
Restricting affected systems to a network segment to limit an incident while preserving some operation.
- IR playbook
Show answerHide answer
A documented set of response steps for a specific incident type, ensuring a consistent response.
- CSIRT / CIRT
Show answerHide answer
Computer Security Incident Response Team — the group responsible for handling incidents.
- Eradication validation
Show answerHide answer
Confirming the threat and its persistence are fully removed before returning systems to service.
- Threat actor
Show answerHide answer
An individual or group that carries out an attack — nation-state, organized crime, hacktivist, insider, or unskilled.
- Nation-state actor
Show answerHide answer
A highly sophisticated, well-resourced adversary (APT) usually motivated by espionage or strategic disruption.
- APT
Show answerHide answer
Advanced Persistent Threat — a skilled, well-resourced adversary that maintains long-term, stealthy access.
- Insider threat
Show answerHide answer
A current or former employee, contractor, or partner who misuses authorized access to cause harm.
- Hacktivist
Show answerHide answer
A threat actor motivated by an ideological cause rather than profit.
- Indicators (IR)
Show answerHide answer
Observable signs of an incident — from IoCs and IoAs to anomalies in logs and behavior.
- Timeline (incident)
Show answerHide answer
A chronological reconstruction of an incident's events, essential for root cause and reporting.
- Scope creep (IR)
Show answerHide answer
Failing to bound an investigation, leading to wasted effort; scope determination prevents it.
- Order of operations (IR)
Show answerHide answer
The correct sequence of response actions; getting it wrong can destroy evidence.
- Reimaging
Show answerHide answer
Rebuilding a compromised host from a known-good image to ensure no attacker artifacts remain.
- Known-good backup
Show answerHide answer
A verified, uncompromised backup used to restore systems during recovery.
- Data exfiltration
Show answerHide answer
Unauthorized transfer of data out of an organization — a common attacker objective.
- Command-and-control detection
Show answerHide answer
Identifying C2 channels (beaconing, unusual destinations) during analysis.
Reporting & Communication (43)
- MTTD
Show answerHide answer
Mean Time to Detect — the average time from when an incident begins to when it is detected.
- MTTR
Show answerHide answer
Mean Time to Respond/Remediate — the average time to contain and resolve an incident or remediate a vulnerability.
- MTTA
Show answerHide answer
Mean Time to Acknowledge — the average time from an alert to a responder acknowledging it.
- MTTC
Show answerHide answer
Mean Time to Contain — the average time to stop an incident from spreading once it is detected.
- KPI
Show answerHide answer
Key Performance Indicator — a measurable value (e.g., MTTD, MTTR, recurrence) showing how a program performs.
- Recurrence rate
Show answerHide answer
A metric tracking how often the same vulnerability or incident type reappears.
- Top vulnerabilities (metric)
Show answerHide answer
A report of the most frequent or highest-risk vulnerabilities, used to focus remediation.
- Risk score
Show answerHide answer
A combined measure of a finding's likelihood and impact used to prioritize and communicate risk.
- Stakeholder
Show answerHide answer
Anyone who needs incident or vulnerability information — technical teams, executives, legal, HR, PR, customers, or regulators.
- Stakeholder identification
Show answerHide answer
Determining who must receive which information so the right message reaches the right audience.
- Compliance report
Show answerHide answer
A report demonstrating that vulnerability or security posture meets a regulatory or contractual requirement.
- Action plan
Show answerHide answer
A report pairing each finding with an owner, remediation steps, and a realistic timeline.
- Inhibitor to remediation
Show answerHide answer
A real-world constraint (MOU/SLA, business interruption, legacy system, downtime cost) that delays or prevents a fix.
- MOU
Show answerHide answer
Memorandum of Understanding — a non-binding agreement outlining mutual intentions between parties.
- SLA
Show answerHide answer
Service Level Agreement — a contract defining expected service levels and metrics with a provider.
- Business process interruption
Show answerHide answer
An inhibitor where patching requires downtime the business cannot yet absorb.
- Degrading functionality
Show answerHide answer
An inhibitor where a fix breaks a needed feature or integration.
- Legacy system (inhibitor)
Show answerHide answer
An older or proprietary system with no available patch — mitigate with compensating controls.
- Accepted residual risk
Show answerHide answer
The remaining risk an organization knowingly and formally accepts after applying controls.
- Indicator of compromise generation
Show answerHide answer
Producing new IoCs from an incident so detection can be improved going forward.
- Incident report
Show answerHide answer
A document summarizing what happened, impact, timeline, root cause, response, and lessons learned.
- Executive summary
Show answerHide answer
A concise, business-focused overview of an incident or assessment for leadership.
- Technical report
Show answerHide answer
A detailed report for responders covering timeline, affected systems, root cause, and remediation.
- Breach notification
Show answerHide answer
A required disclosure to regulators and affected individuals after a data breach, within set timeframes.
- Metrics dashboard
Show answerHide answer
A visual summary of security KPIs (MTTD, MTTR, open vulnerabilities) for ongoing monitoring.
- Trend analysis
Show answerHide answer
Tracking metrics over time to show whether the security program is improving or declining.
- Audience tailoring
Show answerHide answer
Adjusting a report's depth and framing for its audience — risk for executives, detail for technical teams.
- Governance (reporting)
Show answerHide answer
The policies and oversight structures that direct how vulnerabilities and incidents are reported and handled.
- Vulnerability report
Show answerHide answer
A report communicating findings, severity, affected assets, and remediation guidance to stakeholders.
- Remediation timeline
Show answerHide answer
A realistic schedule for fixing findings that accounts for inhibitors and SLOs.
- Owner (action plan)
Show answerHide answer
The person or team accountable for remediating a specific finding.
- Escalation criteria
Show answerHide answer
Predefined thresholds that determine when to notify higher tiers or management.
- Communication matrix
Show answerHide answer
A table mapping stakeholders to what information they receive and through which channel.
- Regulatory reporting
Show answerHide answer
Disclosing incidents or compliance status to regulators as required by law or contract.
- PR / public communication
Show answerHide answer
Coordinated external messaging about an incident to customers and the public.
- Legal stakeholder
Show answerHide answer
Counsel involved to manage liability, evidence, and breach-notification obligations.
- HR stakeholder
Show answerHide answer
Human Resources, engaged when an incident involves an employee (e.g., insider threat).
- Customer notification
Show answerHide answer
Informing affected customers of a breach within legally required timeframes.
- Metrics maturity
Show answerHide answer
Improving MTTD/MTTR and recurrence over time as a sign of a maturing security program.
- Closed-loop reporting
Show answerHide answer
Feeding lessons learned and generated IoCs back into detection and preparation.
- Risk register (reporting)
Show answerHide answer
A documented list of risks with owner, likelihood, impact, and treatment, referenced in reports.
- Compliance vs. security
Show answerHide answer
Compliance proves a standard is met; security reduces actual risk — they overlap but aren't identical.
- Evidence in reports
Show answerHide answer
Including verified facts and, where needed, forensic findings (with chain of custody) to support conclusions.
References
- 1.CompTIA. “CompTIA CySA+ (CS0-003) Certification.” comptia.org. ↑
- 2.CompTIA. “CySA+ (CS0-003) Exam Objectives.” comptia.org. ↑
- 3.Forum of Incident Response and Security Teams. “Common Vulnerability Scoring System (CVSS).” first.org. ↑

Career Employer
Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.
All PostsCareer Employer’s Editorial Process
Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.
