Career Employer

Your FREE CompTIA CySA+ (Cybersecurity Analyst) Practice Test 2026 – 180+ Q&A

Realistic CompTIA CySA+ CS0-003 practice questions across all four official exam domains — take a full practice test or drill one domain.

How ready are you?

To find us again, just search “Career Employer CySA+”

By

Click Start Test above to launch a full-length CompTIA CySA+ practice test weighted exactly like the real CS0-003 exam, or drill a single domain — Security Operations, Vulnerability Management, Incident Response & Management, or Reporting & Communication. Every question includes a clear explanation so you learn the reasoning, not just the answer.

The CompTIA Cybersecurity Analyst+ (CySA+) exam, code CS0-003, validates the behavioral-analytics and threat-detection skills security analysts use to defend live environments. It is a DoD 8140/8570-approved, ISO/ANSI-accredited credential administered by CompTIA.

[1] These free CySA+ practice questions and test prep mirror the official CS0-003 objectives so you practice the way the real exam is built.[2]

To round out your prep, pair these with our free study guide, flashcards, and cheat sheet. Want extra insurance for exam day? Capital Prep’s CySA+ premium study materials come with a CySA+ exam pass guarantee: your money back if you don’t pass, plus up to $439 toward your retake fee — and Career Employer students get a special discount.

CySA+ is one of the 14 CompTIA certifications — explore all our CompTIA practice tests to compare and prep across the whole family.

Career Employer CySA+ Student Data

Updated daily

Career Employer CySA+ practice-test data · through Oct 8, 2026 · 162 students

CySA+ students on Career Employer get 79% of practice questions right on the first try; Vulnerability Management is the most-missed section.[7]

79%
first-try accuracy
6,678 answers · previous question set
86%
median first full practice exam
111 students · 67% scored 80%+

What 162 CySA+ students on Career Employer got wrong

First-try accuracy by exam section, hardest first[7]

  1. Vulnerability Management31% of exam · data from the previous question set
    72%n=2,079
  2. Reporting and Communication17% of exam · data from the previous question set
    80%n=1,128
  3. Security Operations33% of exam · data from the previous question set
    81%n=2,155
  4. Incident Response and Management20% of exam · data from the previous question set
    85%n=1,316

Vulnerability Management is both the most-missed CySA+ section (72% correct on the first try) and the section where students lose the most points — it’s 31% of the exam. Start here.[7]

Get Capital Prep’s CySA+ Premium with an exam pass guarantee: your money back if you don’t pass, up to $439 of your retake fee reimbursed, plus a CE student discount →

See Career Employer’s full CySA+ student data ↓Our data & methodology

Source: Career Employer CySA+ practice-test data, first attempt at each question only, Aug 29, 2026 – Oct 8, 2026. Sections marked “previous question set” were rewritten recently; they show the earlier version until the new one qualifies. Our practice questions written to the official outline, not the official exam; self-selected sample; a student is one browser.

CySA+ at a Glance

CySA+ (CS0-003) at a glance
DetailCySA+ (CS0-003)
Certifying bodyCompTIA
Exam codeCS0-003 (retires in English Dec 22, 2026); newer V4 CS0-004 launched June 23, 2026
Total questionsMaximum of 85 (multiple-choice and performance-based)
Time limit165 minutes
Passing score750 on a scale of 100–900
Recommended experienceNetwork+, Security+, and about 4 years of security analyst experience
Exam costAbout $392 USD (verify current pricing with CompTIA)
RecertificationValid for 3 years; renew via CompTIA continuing education (CEUs)

What’s Changed on the CySA+ Exam (2026–2027)

Checked against official sources: Sep 30, 2026

Coming up

  • Dec 22, 2026

    The CS0-003 (V3) exam retires in English on December 22, 2026 (English learning products retire November 22, 2026). Japanese, Portuguese and Spanish versions retire March 23, 2027.

    Source: CompTIA (opens in a new tab)

Recently changed

  • Jun 23, 2026

    CySA+ V4 (exam code CS0-004) launched June 23, 2026. It keeps a maximum of 85 questions, 165 minutes and a 750 passing score, but reweights the domains: Security Operations 34%, Vulnerability Management 26%, Incident Response and Management 24%, Reporting and Communication 16%.

    Source: CompTIA (opens in a new tab)

What Is on the CySA+ Exam?

The CySA+ CS0-003 exam covers four domains: Security Operations (33%), Vulnerability Management (30%), Incident Response and Management (20%), and Reporting and Communication (17%).[2]

New version: The newer CySA+ V4 exam (CS0-004) launched June 23, 2026 with the same 85-question maximum, 165-minute limit and 750 passing score, reweighted to Security Operations 34%, Vulnerability Management 26%, Incident Response and Management 24%, and Reporting and Communication 16%.[6] CS0-003 retires in English on December 22, 2026. The weights, chart and practice test on this page follow CS0-003 — if you are booking CS0-004, study to the V4 objectives.[2]

Security Operations is the largest section, covering system and network architecture, threat intelligence, malicious-activity analysis, and the tools used to improve security operations.

Vulnerability Management covers scanning, analysis and prioritization, mitigating controls, and secure coding.

Incident Response and Management addresses attack frameworks and the incident response process, and Reporting and Communication covers vulnerability and incident reporting and stakeholder communication. Our full practice test is weighted to match:

CySA+ CS0-003 weighting by domain
Security Operations33% · ≈28 Qs
Vulnerability Management30% · ≈26 Qs
Incident Response and Management20% · ≈17 Qs
Reporting and Communication17% · ≈14 Qs
CompTIA CySA+ practice test — practice questions by domain with answer explanations

Practice Questions by Domain

Use Start Test for a full weighted CySA+ simulation, or open the hub and pick a single domain to drill your weak area. After each full exam, your results show a per-domain breakdown so you know exactly where to focus — most candidates need the most reps on Security Operations and the performance-based analysis scenarios.

What Are the Requirements to Take CySA+?

CySA+ has no mandatory prerequisites — anyone may register and sit for the CS0-003 exam.[1] CompTIA recommends, but does not require, that candidates hold CompTIA Network+ and Security+ (or equivalent knowledge) and have about four years of hands-on security experience.

That recommended experience is in roles such as SOC analyst, threat intelligence analyst, or incident response analyst. Because the exam is heavy on performance-based questions, practical analyst experience is strongly advised.

How Do You Register for the CySA+ Exam?

You register for CS0-003 through CompTIA and schedule your exam with Pearson VUE, either at a physical testing center or via OnVUE online proctoring.[5]

Purchase an exam voucher from the CompTIA Store (or an authorized reseller), create or sign in to your CompTIA account, then book a date and delivery method. Exam pricing is approximately $392 USD but varies by region and promotion, so verify the current voucher price before you buy.

Bundles that pair the voucher with CertMaster Learn, practice tests, or retake assurance are also available.[3]

What Is the Passing Score for CySA+?

The passing score for CySA+ is 750 on a scaled range of 100 to 900.[2]

The exam blends multiple-choice with performance-based questions (PBQs) that place you in simulated environments to demonstrate hands-on analysis; PBQs typically carry more weight than standard multiple-choice items.

Because scoring is scaled rather than a simple percentage correct, there is no fixed number of questions you must answer correctly. Your result is reported as pass or fail immediately after testing, and CompTIA does not release a domain-by-domain numeric breakdown beyond the pass/fail outcome.

How Hard Is CySA+? (Pass Rate)

CompTIA does not publish official pass-rate statistics for CySA+. Industry and training-provider estimates commonly place the first-attempt pass rate in roughly the 60 to 75 percent range, with the performance-based questions and the breadth of Security Operations content cited as the most common stumbling blocks.[4] Treat any specific pass-rate figure as an unofficial estimate rather than a CompTIA-published number.

~60–75%
Est. pass rate
first attempt (unofficial)
750
Passing scaled score
of 100–900
33%
Security Operations
largest domain

The takeaway: practice reading real tool output (SIEM, scanners, packet captures) and drill until you’re consistently scoring above target on full-length practice — especially Security Operations — before you book your exam date.

On Career Employer, CySA+ students get 79% right on the first try and miss Vulnerability Management most[7] — see the CySA+ student data above.

What to Expect on Exam Day

Arrive at your Pearson VUE test center at least 15 minutes early to check in — bring a valid, unexpired government-issued photo ID whose name matches your CompTIA registration.[5]You’ll store phones and personal items in a locker; no notes are allowed.

A short tutorial precedes the exam, then you have 165 minutes to answer up to 85 questions, including the performance-based tasks that usually appear first. If you test via OnVUE online proctoring, expect a similar room scan and ID check. Your pass/fail result is reported immediately after testing.

Having simulated the full timing with practice tests makes that clock feel routine.

How to Use This CySA+ Practice Test

  • Recreate exam conditions. Take the full test timed, with no notes.
  • Diagnose, then drill. Use a full simulation to find weak domains, then drill them.
  • Read real tool output. Practice interpreting SIEM, scanner, and threat-intel data.
  • Practice PBQ-style scenarios. Hands-on analysis is where most points are lost.
  • Learn the why. Read every explanation — understanding beats memorizing.

Plan for the full sitting. 54% of CySA+ students on Career Employer who start a full-length practice exam finish one (107 of 198)[7] — set aside the full sitting before you press Start Test.

Why Get CySA+ Certified?

CySA+ is a DoD 8140/8570-approved, ISO/ANSI-accredited credential that validates the applied analysis skills employers look for in SOC and security-analyst roles, sitting above Security+ on the cybersecurity career path.[1] These free CySA+ practice tests are the most efficient way to get there.

Conclusion

Passing CySA+ comes down to applied analysis — reading tool output, prioritizing vulnerabilities, and working through incident response under time pressure. Use this free CySA+ practice test to find your weak domains, drill them to mastery, and reinforce them with our study guide, flashcards, and cheat sheet. On Career Employer, CySA+ students lose the most points on Vulnerability Management (72% correct on the first try), so start your drilling there.[7]

CySA+ Practice Test FAQ

CySA+ is the CompTIA Cybersecurity Analyst+ certification, administered by CompTIA and delivered through Pearson VUE. Two versions are live in 2026: CS0-003 (V3), which retires in English on December 22, 2026, and CS0-004 (V4), which launched June 23, 2026. This page and its practice questions are built on the CS0-003 objectives. It validates the threat-detection, vulnerability-management, and incident-response skills used by security analysts in security operations roles, and it is DoD 8140/8570-approved and ISO/ANSI-accredited.

Career Employer CySA+ practice-test data, through Oct 8, 2026 · 162 students
Every published Career Employer CySA+ practice-test number, with its sample size, source and date
MetricValuenStudentsSourceData through
Students who answered practice questions162—162all question versionsOct 8, 2026
First-try answers (all question versions)7,7227,722162all question versionsOct 8, 2026
First-try accuracy, whole exam78.5%6,678 answers140previous question setOct 5, 2026
First-try accuracy: Vulnerability Management (30.6% of the exam; costs 8.6 of every 100 exam points)71.9%2,079 answers131previous question setOct 5, 2026
First-try accuracy: Reporting and Communication (16.5% of the exam; costs 3.3 of every 100 exam points)79.7%1,128 answers120previous question setOct 5, 2026
First-try accuracy: Security Operations (32.9% of the exam; costs 6.4 of every 100 exam points)80.5%2,155 answers129previous question setOct 5, 2026
First-try accuracy: Incident Response and Management (20% of the exam; costs 3.1 of every 100 exam points)84.7%1,316 answers122previous question setOct 5, 2026
Median score on first full-length practice exam86%111 students111all question versionsOct 8, 2026
Scored 80%+ on first full-length practice exam66.7%111 students111all question versionsOct 8, 2026
Started a full-length practice exam198—198all question versionsOct 8, 2026
Finished a full-length practice exam107of 198 starters107all question versionsOct 8, 2026
Full-length practice exam finish rate54%198 starters198all question versionsOct 8, 2026

First attempt at each question only; repeats, answers after revealing the explanation, bots and staff excluded. Aug 29, 2026 – Oct 8, 2026. Our practice questions written to the official outline, not the official exam; self-selected sample; a student is one browser. Free to reuse under CC BY 4.0 — cite “Career Employer practice-test data, careeremployer.com/data”.

CySA+ question bank

All 182 questions, by domain

A reference copy of every question in this practice test. Each answer stays hidden until you choose to show it. To practice with scoring, timing and your readiness score, use Start Test at the top of the page.

Security Operations (57)

  1. In the context of cybersecurity, which technique is used in an IDS to detect threats based on known attack patterns?

    • A.Weighing traffic against learned probabilistic baselines
    • B.Scoring traffic against adjustable behavioral heuristics
    • C.Matching traffic against catalogued malicious signatures
    • D.Checking traffic against standardized protocol semantics
    Show answerHide answer

    Correct answer: Matching traffic against catalogued malicious signatures

    Correct answer: Matching traffic against catalogued malicious signatures. Signature-based detection is the IDS technique built on known attack patterns: the sensor holds a catalog of byte sequences, packet structures and command strings already observed in real attacks and alerts when live traffic matches one. Weighing traffic against learned probabilistic baselines is anomaly-based detection, which reports statistical deviation from what the network normally does and therefore needs no known pattern at all. Scoring traffic against adjustable behavioral heuristics is heuristic analysis, which reasons about suspicious characteristics rather than matching a recorded attack. Checking traffic against standardized protocol semantics is stateful protocol analysis, which compares traffic to how a protocol is defined to behave, not to a library of attacks.

  2. What is the primary purpose of a honeypot in network security?

    • A.Attracting attackers onto an instrumented decoy asset
    • B.Planting fake credentials that raise alerts when used
    • C.Detonating suspect files inside a controlled guest VM
    • D.Rerouting malware callbacks to a controlled sinkhole
    Show answerHide answer

    Correct answer: Attracting attackers onto an instrumented decoy asset

    A honeypot's purpose is attracting attackers onto an instrumented decoy asset: a system with no production role, so every interaction with it is suspicious and the attacker's tools and techniques are recorded. Planting fake credentials that raise alerts when used describes a honeytoken, a decoy piece of data rather than a decoy system. Detonating suspect files inside a controlled guest VM is sandboxing, which runs samples the defenders already hold rather than luring attackers. Rerouting malware callbacks to a controlled sinkhole is DNS sinkholing, which captures infected hosts' traffic rather than drawing in the attacker.

  3. In threat intelligence, what is the primary objective of indicator of compromise IoC analysis?

    • A.Forecasting which adversaries will target the finance sector next
    • B.Estimating the regulatory expense that a confirmed breach creates
    • C.Ranking which vendor patches deserve the earliest possible action
    • D.Identifying endpoints that show artifacts of an ongoing intrusion
    Show answerHide answer

    Correct answer: Identifying endpoints that show artifacts of an ongoing intrusion

    Correct answer: Identifying endpoints that show artifacts of an ongoing intrusion. Indicators of compromise are forensic artifacts left behind by intrusion activity, such as malicious file hashes, beaconing destinations, registry changes and anomalous log entries. Analysts match them against telemetry to answer one question: has this environment already been breached. Forecasting which adversaries will target the finance sector next is strategic threat intelligence, which reasons about future intent rather than present evidence. Estimating the regulatory expense that a confirmed breach creates is business impact analysis, a financial exercise that only begins once detection has happened. Ranking which vendor patches deserve the earliest possible action is vulnerability remediation planning, which addresses exposure that has not yet been exploited.

  4. Which type of attack involves overwhelming a target with traffic to make it inaccessible?

    • A.ARP poisoning that reroutes the target's local traffic through the attacker
    • B.Distributed flooding that exhausts the victim's available network bandwidth
    • C.Aggressive port scanning that probes all of the target's listening services
    • D.DNS hijacking that repoints the target's domain to attacker-run web servers
    Show answerHide answer

    Correct answer: Distributed flooding that exhausts the victim's available network bandwidth

    The answer is distributed flooding that exhausts the victim's available network bandwidth: a DDoS sends traffic from many sources until capacity runs out and legitimate users are refused. ARP poisoning reroutes local traffic for an on-path interception, not an outage. Aggressive port scanning generates probes for reconnaissance and does not aim to exhaust anything. DNS hijacking can make a site unreachable, but it does so by repointing the domain, not by overwhelming the target with traffic.

  5. What is the primary purpose of a Security Information and Event Management (SIEM) system?

    • A.Relaying unaltered syslog messages from many servers into one archive
    • B.Correlating logged telemetry collected from numerous independent systems
    • C.Automating playbook responses triggered by alerts raised on many systems
    • D.Recording endpoint telemetry and then isolating hosts that raised alerts
    Show answerHide answer

    Correct answer: Correlating logged telemetry collected from numerous independent systems

    A SIEM's primary purpose is correlating logged telemetry collected from numerous independent systems, normalising events so activity that looks harmless in one log raises an alert beside another. Relaying unaltered syslog messages from many servers into one archive is the job of a log forwarder or collector, which centralises data without analysing it. Automating playbook responses triggered by alerts is SOAR, which acts on alerts after detection. Recording endpoint telemetry and isolating hosts that raised alerts is EDR, which works on individual endpoints rather than correlating across sources.

  6. Which cybersecurity framework focuses on improving the cyber resilience of critical infrastructure?

    • A.The ISO standard, aimed at management system certification
    • B.The COBIT model, aimed at enterprise technology governance
    • C.The OWASP project, aimed at website application weaknesses
    • D.The NIST guidance, aimed at operational exposure reduction
    Show answerHide answer

    Correct answer: The NIST guidance, aimed at operational exposure reduction

    Correct answer: The NIST guidance, aimed at operational exposure reduction. The NIST Cybersecurity Framework was commissioned specifically to raise the cyber resilience of critical infrastructure operators, and its core functions give owners and regulators a shared risk language for exactly that purpose. The ISO standard, aimed at management system certification, is ISO/IEC 27001, an auditable specification for an information security management system that any organization may certify against, with no infrastructure focus. The COBIT model, aimed at enterprise technology governance, addresses the governance of information technology as a whole rather than cyber resilience. The OWASP project, aimed at website application weaknesses, is a community effort concerned with application-layer software defects.

  7. In cybersecurity, what is the main purpose of threat hunting?

    • A.Proactively seeking intruders missed by existing detection alerts
    • B.Systematically containing intruders after one alert has triggered
    • C.Safely simulating intruders under an approved engagement contract
    • D.Routinely ranking system weaknesses intruders could exploit later
    Show answerHide answer

    Correct answer: Proactively seeking intruders missed by existing detection alerts

    Correct answer: Proactively seeking intruders missed by existing detection alerts. Threat hunting starts from the assumption that an adversary is already inside and that automated controls have not fired; the hunter forms a hypothesis and searches telemetry for the activity that would confirm it. Systematically containing intruders after one alert has triggered is incident response, which is reactive by definition and begins from a detection that already exists. Safely simulating intruders under an approved engagement contract is penetration testing or red teaming, which emulates an adversary instead of looking for a real one. Routinely ranking system weaknesses intruders could exploit later is vulnerability management, which measures unexploited exposure rather than searching for a live intrusion.

  8. Which attack method involves injecting malicious scripts into web pages viewed by users?

    • A.Query injection in loosely validated database statements
    • B.Command injection in poorly filtered process invocations
    • C.Script injection in dynamically rendered browser content
    • D.Header injection in improperly cached upstream responses
    Show answerHide answer

    Correct answer: Script injection in dynamically rendered browser content

    Correct answer: Script injection in dynamically rendered browser content. Cross-site scripting places attacker-controlled script into output that a web application returns to other users, so the code runs in each victim's browser with the trust of the visited site. Query injection in loosely validated database statements is SQL injection, which executes on the database server rather than in a user's browser. Command injection in poorly filtered process invocations executes on the underlying host operating system, not in the page. Header injection in improperly cached upstream responses is response splitting or cache poisoning, which manipulates the HTTP response envelope rather than planting script inside rendered page content.

  9. What is the primary function of file integrity monitoring (FIM) in cybersecurity?

    • A.Alerting when signatures match a freshly downloaded binary
    • B.Alerting when logins exceed the accepted lockout threshold
    • C.Alerting when regulated records leave the network boundary
    • D.Alerting when a guarded system object changes unexpectedly
    Show answerHide answer

    Correct answer: Alerting when a guarded system object changes unexpectedly

    Correct answer: Alerting when a guarded system object changes unexpectedly. File integrity monitoring takes a cryptographic baseline of critical binaries, configuration files, registry keys and system directories, then reports any deviation from it, because unexplained modification is a reliable sign of tampering, malware persistence or unauthorized administration. Alerting when signatures match a freshly downloaded binary is antimalware scanning, which recognizes known bad content rather than measuring change. Alerting when logins exceed the accepted lockout threshold is an authentication control aimed at credential guessing, not at file state. Alerting when regulated records leave the network boundary is data loss prevention, which watches data in motion rather than the integrity of files at rest.

  10. In the context of cybersecurity, what is 'credential stuffing'?

    • A.Automated testing of popular passwords against many different accounts
    • B.Automated brute-force of alphanumeric strings against a specific login
    • C.Automated replay of breached username pairs against unrelated websites
    • D.Automated lookup of captured hashes against precomputed rainbow tables
    Show answerHide answer

    Correct answer: Automated replay of breached username pairs against unrelated websites

    Correct answer: Automated replay of breached username pairs against unrelated websites. Credential stuffing feeds username and password pairs recovered from an earlier breach into login forms at other services, betting on password reuse; the attacker never guesses, they replay known-good pairs. Automated testing of popular passwords against many different accounts is password spraying, which tries a small set of likely passwords broadly to stay under lockout thresholds. Automated brute-force of alphanumeric strings against a specific login exhausts a keyspace instead of reusing stolen pairs. Automated lookup of captured hashes against precomputed rainbow tables is offline hash cracking, which needs stolen hashes and never touches the login form.

  11. What technique is commonly used in cyber threat intelligence for correlating large sets of data to identify potential threats?

    • A.Data normalization that aligns mismatched log formats between vendors
    • B.Data mining that surfaces recurring patterns inside enormous datasets
    • C.Data masking that suppresses regulated customer fields from operators
    • D.Data retention that preserves archived incident evidence across years
    Show answerHide answer

    Correct answer: Data mining that surfaces recurring patterns inside enormous datasets

    Correct answer: Data mining that surfaces recurring patterns inside enormous datasets. Correlating very large volumes of telemetry to expose relationships no analyst would find by inspection is exactly what data mining contributes to cyber threat intelligence, and it is how clusters of related indicators and repeated adversary behavior are discovered. Data normalization that aligns mismatched log formats between vendors is a preparation step that makes records comparable but discovers nothing by itself. Data masking that suppresses regulated customer fields from operators is a privacy control applied to protect data rather than analyze it. Data retention that preserves archived incident evidence across years governs how long records are kept and performs no correlation.

  12. In cybersecurity, what is the main purpose of using a sandbox environment?

    • A.Detonating unknown binaries inside a fully isolated instrumented container
    • B.Disassembling suspect binaries and reading their code without running them
    • C.Holding flagged binaries in quarantine without running them until deletion
    • D.Luring live intruders onto an instrumented decoy and logging keystrokes
    Show answerHide answer

    Correct answer: Detonating unknown binaries inside a fully isolated instrumented container

    The main purpose of a sandbox is detonating unknown binaries inside a fully isolated instrumented container, so behavior, callbacks and file changes can be observed without risk to production. Disassembling suspect binaries and reading their code without running them is static analysis, which never executes the sample. Holding flagged binaries in quarantine without running them until deletion is antimalware quarantine, which stores a detected file rather than studying it. Luring live intruders onto an instrumented decoy and logging keystrokes is a honeypot, which observes attackers rather than unknown files.

  13. Which method is most effective for detecting zero-day exploits?

    • A.Behavioral analysis measured against a learned traffic baseline
    • B.Signature matching measured against a published malware catalog
    • C.Hash comparison measured against a circulated malware blocklist
    • D.Version checking measured against a vendor maintained inventory
    Show answerHide answer

    Correct answer: Behavioral analysis measured against a learned traffic baseline

    Correct answer: Behavioral analysis measured against a learned traffic baseline. A zero-day exploit has no published indicator, so the only approach with a realistic chance of catching it is one that models normal activity and reports departures from it, such as unusual process lineage, unexpected outbound destinations or abnormal volumes. Signature matching measured against a published malware catalog can only recognize what has already been documented, which a zero-day by definition has not. Hash comparison measured against a circulated malware blocklist has the same limitation and fails the moment a sample is recompiled. Version checking measured against a vendor maintained inventory reports missing fixes, and for a zero-day no fix yet exists to be missing.

  14. What is the primary goal of a DDoS (Distributed Denial of Service) attack?

    • A.To tie up the defenders and steal records from the hosts
    • B.To exhaust capacity and deny the legitimate users access
    • C.To hijack live sessions and impersonate logged-in users
    • D.To enlist compromised hosts and rent them out as botnets
    Show answerHide answer

    Correct answer: To exhaust capacity and deny the legitimate users access

    The primary goal is to exhaust capacity and deny the legitimate users access, an attack on availability. Tying up defenders while records are stolen is a smokescreen motive some attackers layer on top, but it is a secondary use, not what defines a DDoS. Hijacking live sessions to impersonate logged-in users is session hijacking, an attack on authentication. Enlisting compromised hosts and renting them out as botnets is the preparation that makes a DDoS possible, not its objective.

  15. In threat management, what is the primary function of a SIEM (Security Information and Event Management) system?

    • A.Executing automated playbook actions to contain incidents
    • B.Isolating compromised endpoints from the networks automatically
    • C.Reporting correlated incident signals to responders immediately
    • D.Profiling normal account behavior to flag insider misuse sooner
    Show answerHide answer

    Correct answer: Reporting correlated incident signals to responders immediately

    The primary function of a SIEM is reporting correlated incident signals to responders immediately: it aggregates and correlates events from many sources and surfaces prioritised alerts. Executing automated playbook actions to contain incidents is SOAR, which acts on alerts the SIEM produces. Isolating compromised endpoints from the network is an EDR response capability. Profiling normal account behavior to flag insider misuse is UEBA, a specialised behavioural analytics layer rather than the SIEM's core correlation and reporting function.

  16. Which type of cyber attack involves manipulating a user into disclosing confidential information or performing actions?

    • A.Covert keylogging that records every key a user types at login
    • B.Credential stuffing that retries a user's breached password
    • C.Cookie theft that lets an attacker reuse a user's live session
    • D.Deceptive messaging that persuades a user to surrender secrets
    Show answerHide answer

    Correct answer: Deceptive messaging that persuades a user to surrender secrets

    Deceptive messaging that persuades a user to surrender secrets is phishing, a social engineering attack in which the person is manipulated into disclosing information or acting. Covert keylogging records what a user types, but captures it silently without persuading anyone. Credential stuffing retries a breached password against other services with no user interaction. Cookie theft lets an attacker reuse a live session token, again taking access without manipulating the user into doing anything.

  17. What is the primary focus of behavioral analytics in cybersecurity?

    • A.Matching packet payloads and flagging known exploit signature patterns
    • B.Comparing outbound traffic and flagging addresses on threat-intel feeds
    • C.Baselining user activity and flagging unusual authentication deviations
    • D.Correlating events across hosts and flagging predefined rule violations
    Show answerHide answer

    Correct answer: Baselining user activity and flagging unusual authentication deviations

    Behavioral analytics focuses on baselining user activity and flagging unusual authentication deviations, which catches insider misuse and stolen credentials when no signature exists. Matching packet payloads against known exploit signatures is signature-based IDS detection, which only finds what is already known. Comparing outbound traffic with threat-intel feeds is indicator matching against known bad addresses. Correlating events against predefined rule violations is SIEM rule logic, which follows fixed rules rather than a learned baseline.

  18. Which cybersecurity tool is primarily used for deep packet inspection of network traffic?

    • A.NetFlow collectors that record summarized session flow metadata
    • B.Physical taps that mirror traffic towards monitoring appliances
    • C.SIEM platforms that index forwarded application event summaries
    • D.Intrusion detection sensors that inspect entire packet payloads
    Show answerHide answer

    Correct answer: Intrusion detection sensors that inspect entire packet payloads

    Correct answer: Intrusion detection sensors that inspect entire packet payloads. Deep packet inspection means opening the payload rather than reading only addressing information, and that is precisely what an IDS sensor does when it matches signatures and protocol behavior against the contents of traffic. NetFlow collectors that record summarized session flow metadata deliberately keep only header-derived facts such as addresses, ports, byte counts and timestamps, never the payload itself. Physical taps that mirror traffic towards monitoring appliances duplicate packets at the physical layer and perform no inspection of their own. SIEM platforms that index forwarded application event summaries analyze logs produced elsewhere and never see the packets.

  19. In the context of threat intelligence, what is the main purpose of STIX (Structured Threat Information eXpression)?

    • A.Transporting threat reports among federated intelligence sharing peer servers
    • B.Expressing threat activity in one standard machine-readable structured format
    • C.Scoring threat exploitability using a standardized industry numerical formula
    • D.Cataloging threat-related software defects under one public labeling registry
    Show answerHide answer

    Correct answer: Expressing threat activity in one standard machine-readable structured format

    Correct answer: Expressing threat activity in one standard machine-readable structured format. STIX is a modeling language: it defines objects and relationships for actors, campaigns, malware, indicators and observed data so intelligence written by one organization can be parsed unchanged by another organization's tooling. Transporting threat reports among federated intelligence sharing peer servers is TAXII, the companion transport protocol that moves STIX content without defining it. Scoring threat exploitability using a standardized industry numerical formula is CVSS, which rates how serious a flaw is rather than describing threat activity. Cataloging threat-related software defects under one public labeling registry is CVE, a naming scheme for individual vulnerabilities.

  20. What is the role of a threat actor in the context of cybersecurity?

    • A.The individual or group that mounts a deliberate intrusion
    • B.The route or channel through which an intrusion arrives
    • C.The weakness or flaw that any intrusion is able to exploit
    • D.The tactics or techniques that an attacker habitually uses
    Show answerHide answer

    Correct answer: The individual or group that mounts a deliberate intrusion

    A threat actor is the individual or group that mounts a deliberate intrusion: the adversary, from lone criminals and insiders to hacktivists and state-sponsored teams. The route or channel through which an intrusion arrives is the threat vector, the path rather than the person. The weakness or flaw an intrusion exploits is a vulnerability. The tactics or techniques an attacker habitually uses are TTPs, which describe how an actor operates rather than who the actor is.

  21. Which of the following is a primary characteristic of Advanced Persistent Threats (APTs)?

    • A.Stealthy misuse of legitimate access by a trusted, long-term insider
    • B.Prolonged stealthy occupation of a silently compromised enterprise estate
    • C.Stealthy smash-and-grab data theft followed by an immediate clean getaway
    • D.Targeted phishing burst which harvests insider access data and then halts
    Show answerHide answer

    Correct answer: Prolonged stealthy occupation of a silently compromised enterprise estate

    The defining trait of an advanced persistent threat is prolonged stealthy occupation of a silently compromised enterprise estate: a well-resourced external adversary keeps redundant footholds and collects intelligence for months while avoiding detection. Stealthy misuse of legitimate access by a trusted, long-term insider is an insider threat, which starts from authorised access rather than compromise. Stealthy smash-and-grab data theft is quiet but deliberately short, so it lacks persistence. A targeted phishing burst that harvests insider access data and then halts is a single campaign, often an APT's entry step, not its defining characteristic.

  22. Which attack involves intercepting and altering communications between two parties without their knowledge?

    • A.Replay attacks capturing a valid exchange and resending it untouched
    • B.Packet-sniffing attacks passively capturing a valid exchange in a log
    • C.Session-hijacking attacks stealing one host's token to impersonate it
    • D.Man-in-the-middle attacks silently relaying one host's traffic onward
    Show answerHide answer

    Correct answer: Man-in-the-middle attacks silently relaying one host's traffic onward

    Man-in-the-middle attacks silently relaying one host's traffic onward are the on-path attack: the attacker sits between both parties, each believing it talks directly to the other, and can read and alter everything in transit. Replay attacks resend a captured exchange unaltered, so nothing is changed between two live parties. Packet sniffing passively captures traffic and never alters it. Session hijacking steals a token to impersonate one party, taking its place rather than relaying between both.

  23. In threat management, what is the function of a 'sinkhole' in terms of network security?

    • A.Rate-limiting harmful traffic toward a protected origin service
    • B.Mirroring harmful traffic toward a passive inspection appliance
    • C.Tarpitting harmful traffic toward a deliberately slowed session
    • D.Redirecting harmful traffic toward a controlled analysis server
    Show answerHide answer

    Correct answer: Redirecting harmful traffic toward a controlled analysis server

    Correct answer: Redirecting harmful traffic toward a controlled analysis server. A sinkhole answers requests for known malicious destinations with an address the defender owns, so traffic that would have reached attacker infrastructure is steered off the network and into a system that logs and studies it. Rate-limiting harmful traffic toward a protected origin service throttles volume while still delivering the connections to their intended destination. Mirroring harmful traffic toward a passive inspection appliance copies packets for analysis while the originals continue on their way, so nothing is diverted. Tarpitting harmful traffic toward a deliberately slowed session delays a sender to waste its time, again without changing where the traffic is bound.

  24. Which cybersecurity principle involves the use of multiple layers of security controls and defenses?

    • A.Defense in depth, layering redundant safeguards behind one another
    • B.Least privilege, granting the minimum rights an operation requires
    • C.Separation of duties, splitting a sensitive process between people
    • D.Zero trust, verifying each request before allowing session traffic
    Show answerHide answer

    Correct answer: Defense in depth, layering redundant safeguards behind one another

    Correct answer: Defense in depth, layering redundant safeguards behind one another. The principle assumes any single control will eventually fail or be bypassed, so overlapping and independent measures are stacked across the network, host, application and data tiers and an attacker must defeat all of them in sequence. Least privilege, granting the minimum rights an operation requires, is a single access principle that limits blast radius but supplies no redundancy. Separation of duties, splitting a sensitive process between people, stops one person completing a harmful action alone and is administrative rather than layered. Zero trust, verifying each request before allowing session traffic, removes implicit trust from the network and is an architectural model, not a stack of layers.

  25. Which technique is used in cybersecurity to disguise and hide data in plain sight, typically within another file or data stream?

    • A.Tokenization, substituting a surrogate value for a stored identifier
    • B.Steganography, embedding a hidden payload inside a harmless document
    • C.Obfuscation, rewriting program logic so it resists casual inspection
    • D.Encryption, transforming readable text into an unreadable coded form
    Show answerHide answer

    Correct answer: Steganography, embedding a hidden payload inside a harmless document

    Correct answer: Steganography, embedding a hidden payload inside a harmless document. Steganography conceals the very existence of a message by hiding it inside ordinary-looking media such as an image, audio track or document, so an observer sees only the carrier and has no reason to suspect anything is present. Tokenization, substituting a surrogate value for a stored identifier, swaps sensitive data for a meaningless reference that is openly visible as a placeholder. Obfuscation, rewriting program logic so it resists casual inspection, makes code hard to follow but leaves it plainly present. Encryption, transforming readable text into an unreadable coded form, hides the content of a message while advertising that a protected message exists.

  26. What is the main function of a Security Operations Center (SOC.) in an organization?

    • A.Watching enterprise telemetry and triaging credible intrusion incidents
    • B.Watching network availability and restoring degraded links to endpoints
    • C.Emulating real adversaries on enterprise endpoints to test the defenses
    • D.Scanning enterprise endpoints and assigning remediation of new findings
    Show answerHide answer

    Correct answer: Watching enterprise telemetry and triaging credible intrusion incidents

    The main function of a SOC is watching enterprise telemetry and triaging credible intrusion incidents, monitoring around the clock and driving confirmed events into response. Watching network availability and restoring degraded links to endpoints is the network operations center, which tracks uptime rather than security. Emulating real adversaries on enterprise endpoints to test the defenses is red teaming, an offensive exercise usually run against the SOC. Scanning enterprise endpoints and assigning remediation of new findings is vulnerability management, a separate preventive program.

  27. What is the primary goal of implementing a Security Information and Event Management (SIEM) system in the context of vulnerability management?

    • A.To run playbooks that act on events with no analyst
    • B.To baseline user behavior and flag deviating events
    • C.To log endpoint behavior and isolate infected hosts
    • D.To correlate logged events into ranked alert queues
    Show answerHide answer

    Correct answer: To correlate logged events into ranked alert queues

    A SIEM exists to correlate logged events into ranked alert queues: it aggregates logs from many sources, normalizes them and applies correlation rules so related records become one prioritized alert. Running playbooks that act without an analyst is SOAR, which consumes SIEM alerts. Baselining user behavior and flagging deviations is UEBA. Logging endpoint behavior and isolating infected hosts is EDR, which works on individual endpoints rather than correlating across the estate.

  28. In vulnerability management, what is the purpose of implementing a honeypot?

    • A.To detonate suspect files inside an isolated sandbox
    • B.To redirect malicious domain lookups into a sinkhole
    • C.To lure network intruders onto an instrumented decoy
    • D.To plant fake credentials that alert when touched
    Show answerHide answer

    Correct answer: To lure network intruders onto an instrumented decoy

    A honeypot exists to lure network intruders onto an instrumented decoy: a system with no legitimate users, so any interaction is suspicious and the attacker's tools and techniques can be watched safely. Detonating suspect files in an isolated sandbox is malware analysis, which examines samples rather than attracting attackers. Redirecting malicious domain lookups is DNS sinkholing, which cuts off callbacks. Planting fake credentials that alert when used is a honeytoken, a decoy piece of data rather than a decoy system.

  29. In the context of cybersecurity incident response, what is a 'honeypot' primarily used for?

    • A.Slowing scanning connections to waste the attacker's time
    • B.Redirecting botnet callback traffic to a controlled server
    • C.Attracting intruders onto a deceptive host worth observing
    • D.Executing suspicious samples in an isolated analysis space
    Show answerHide answer

    Correct answer: Attracting intruders onto a deceptive host worth observing

    A honeypot is used for attracting intruders onto a deceptive host worth observing: a decoy with no production role, so every interaction is suspicious and attacker behaviour can be studied safely. Slowing scanning connections to waste attacker time is a tarpit, which delays rather than lures. Redirecting botnet callback traffic to a controlled server is a sinkhole, which intercepts existing infections. Executing suspicious samples in an isolated space is a sandbox, which analyses files the defender already holds.

  30. What is the role of 'situational awareness' in the context of cybersecurity incident response?

    • A.Hunting proactively for threats that alerts have missed
    • B.Scoping the hosts and accounts the incident has touched
    • C.Maintaining a current picture of the threat environment
    • D.Mapping the hosts and accounts exposed to the internet
    Show answerHide answer

    Correct answer: Maintaining a current picture of the threat environment

    Situational awareness means maintaining a current picture of the threat environment, combining intelligence, sensor data and knowledge of normal operations so responders understand what is happening now. Threat hunting is an activity that draws on that picture to search for missed threats, not the picture itself. Scoping identifies which hosts and accounts one incident touched. Mapping exposed hosts is attack surface management, a point-in-time inventory rather than an awareness of the evolving threat.

  31. In the context of security architecture, what is the primary purpose of a Data Loss Prevention (DLP) system?

    • A.Encrypting the sensitive records at rest on the file servers
    • B.Stopping sensitive records from leaving the internal network
    • C.Labelling sensitive records with their classification levels
    • D.Restricting what the recipients can do with opened documents
    Show answerHide answer

    Correct answer: Stopping sensitive records from leaving the internal network

    A DLP system is about stopping sensitive records from leaving the internal network by email, upload, removable media or cloud sync. Encrypting sensitive records at rest on the file servers protects stored data if media is stolen but does not watch what leaves. Labelling records with classification levels is a prerequisite DLP relies on, not its purpose. Restricting what recipients can do with opened documents is information rights management, which controls use after delivery rather than blocking the transfer.

  32. Which security concept involves distributing a set of backup keys to trusted individuals for safekeeping?

    • A.Public key infrastructure issuing certificates to the client
    • B.Multifactor authentication combining a password plus a token
    • C.Symmetric encryption sharing a single secret between parties
    • D.Key escrow depositing duplicated copies with an intermediary
    Show answerHide answer

    Correct answer: Key escrow depositing duplicated copies with an intermediary

    Key escrow lodges a duplicate of a cryptographic key with a trusted third party, so encrypted material can still be recovered when the holder loses the key or a lawful demand requires access. Public key infrastructure issues and validates certificates; it does not retain spare private keys for recovery. Multifactor authentication proves identity using more than one factor. Symmetric encryption describes a single shared secret used in both directions. None of those is a custodial arrangement for spare keys.

  33. What is the primary function of a Security Information and Event Management (SIEM) system?

    • A.Automating the response playbooks started on managed hosts
    • B.Baselining the typical logon behavior of each user account
    • C.Correlating the audit trails gathered by monitored devices
    • D.Forwarding the raw log records gathered from managed hosts
    Show answerHide answer

    Correct answer: Correlating the audit trails gathered by monitored devices

    The primary function of a SIEM is correlating the audit trails gathered by monitored devices: it aggregates, normalizes and correlates logs so unrelated records become one actionable alert. Automating the response playbooks started on managed hosts is SOAR, which acts on alerts after a SIEM raises them. Baselining the typical logon behavior of each user account is UEBA, a behavioral analytics layer rather than the correlation platform. Forwarding the raw log records gathered from managed hosts is a syslog forwarder, which ships logs to the SIEM but correlates nothing.

  34. In cybersecurity, what is the primary purpose of implementing a Zero Trust architecture?

    • A.Concentrating stronger defences at a single outer boundary
    • B.Verifying each request regardless of its network placement
    • C.Layering repeated controls behind the main defensive lines
    • D.Splitting sensitive duties so lone operators cannot finish
    Show answerHide answer

    Correct answer: Verifying each request regardless of its network placement

    Zero Trust removes location as a basis for trust: every request is authenticated, authorised and judged against device and context signals, whether it arrives from a coffee shop or a corporate switch port. Concentrating stronger defences at one outer boundary is the perimeter model Zero Trust was built to replace. Stacking repeated controls behind the main line is defence in depth. Splitting sensitive duties so no lone operator can finish a transaction is separation of duties. Only one of them removes implicit internal trust.

  35. Which tool is primarily used for real-time monitoring of network traffic and packet analysis?

    • A.Wireshark
    • B.Snort
    • C.Suricata
    • D.NetworkMiner
    Show answerHide answer

    Correct answer: Wireshark

    Wireshark is a protocol analyzer that captures packets live and decodes every field of every frame, which is real-time traffic monitoring and packet analysis. Snort and Suricata watch traffic too, but they are intrusion detection engines that match signatures and raise alerts rather than letting an analyst dissect packets. NetworkMiner is a network forensic tool that extracts files, hosts and credentials from captured sessions rather than decoding live packets field by field.

  36. What is the function of a Web Application Firewall (WAF) in cybersecurity?

    • A.To filter packets by port numbers at the internal firewall
    • B.To screen HTTP requests sent to one hosted web application
    • C.To spread client sessions over a farm of identical servers
    • D.To encrypt a browser session with a public key certificate
    Show answerHide answer

    Correct answer: To screen HTTP requests sent to one hosted web application

    A web application firewall works at the application layer: it examines each HTTP request and response destined for a protected site and blocks the ones carrying injection, cross-site scripting or other web attack payloads. A traditional packet firewall decides on addresses and ports and cannot read the request body. A load balancer distributes sessions for capacity and availability, which is a performance function rather than an inspection one. Transport encryption protects data in transit but does nothing about a malicious request arriving inside the encrypted channel.

  37. Which technology is primarily used to isolate and run suspicious code or files in a controlled environment?

    • A.Host-based network isolation
    • B.Isolated honeynet deployment
    • C.Automated sandbox detonation
    • D.Antivirus quarantine folder
    Show answerHide answer

    Correct answer: Automated sandbox detonation

    Automated sandbox detonation runs a suspicious file or code sample inside an instrumented, disposable environment so its behaviour can be observed without risk to production. Host-based network isolation cuts a compromised endpoint off from the network but does not execute samples for analysis. An isolated honeynet deployment lures attackers into a decoy network rather than running files an analyst submits. An antivirus quarantine folder stores a flagged file in an inaccessible location so it cannot run at all, which is the opposite of controlled execution.

  38. What is the primary purpose of a Network Access Control NAC system?

    • A.To enforce settings on enrolled phones with an MDM agent
    • B.To isolate an infected host on the LAN with an EDR agent
    • C.To split the LAN into VLANs by department and function
    • D.To admit devices onto the LAN after a posture assessment
    Show answerHide answer

    Correct answer: To admit devices onto the LAN after a posture assessment

    The primary purpose of network access control is to admit devices onto the LAN after a posture assessment: identity, patch level, agent presence and configuration are checked before the port is opened, quarantined or refused. Enforcing settings on enrolled phones with an MDM agent is mobile device management, which configures devices it already owns rather than gating network admission. Isolating an infected host on the LAN with an EDR agent is an endpoint response action taken after compromise is detected. Splitting the LAN into VLANs by department and function is segmentation, which a NAC may assign to but which is not its purpose.

  39. In the context of cloud security, what is the main function of a Cloud Access Security Broker CASB?

    • A.To audit the cloud account settings against a secured baseline
    • B.To replicate cloud data buckets into a distant provider region
    • C.To police the way staff reach any sanctioned cloud application
    • D.To rotate the tenant secrets for objects inside cloud archives
    Show answerHide answer

    Correct answer: To police the way staff reach any sanctioned cloud application

    A cloud access security broker sits in the path between users and the cloud services they consume and acts as a policy enforcement point there, giving visibility into who is using which service and applying access, data protection and threat controls to that usage. Posture auditing grades the provider-side configuration instead. Cross-region replication is a durability measure. Secret rotation protects stored objects. None of those three mediates the user-to-service session the question describes.

  40. What is the primary role of an Intrusion Detection System (IDS) in a network security architecture?

    • A.To block each session inline when its packets match a rule
    • B.To log each session's flow metadata as its packets pass by
    • C.To correlate the log events from many hosts into one alert
    • D.To raise an alert when inbound traffic matches a signature
    Show answerHide answer

    Correct answer: To raise an alert when inbound traffic matches a signature

    The primary role of an IDS is to raise an alert when inbound traffic matches a signature, detecting and notifying from a passive copy of the traffic. To block each session inline when its packets match a rule is what an intrusion prevention system does; in-path blocking is exactly what a detection-only sensor lacks. To log each session's flow metadata as its packets pass by is NetFlow collection, which records conversations without inspecting content. To correlate the log events from many hosts into one alert is the SIEM's job, working on logs rather than packets.

  41. What is the primary purpose of the Security Assertion Markup Language (SAML) in cloud security?

    • A.To hand a signed authentication claim between two trusted parties
    • B.To register fresh user accounts inside each linked cloud platform
    • C.To wrap each browser session within a negotiated transport cipher
    • D.To store the group permissions for an on-premises document server
    Show answerHide answer

    Correct answer: To hand a signed authentication claim between two trusted parties

    SAML is an XML standard for passing signed assertions about a subject between an identity provider and a service provider, so one party can vouch to another for who the user is and what attributes they carry. Account creation across linked services is handled by a provisioning standard. Negotiating a transport cipher protects the channel but says nothing about identity. Storing group permissions on a file server is local access control and never crosses a trust boundary.

  42. In cybersecurity, what is the function of a Threat Intelligence Platform (TIP)?

    • A.To define a structured language for describing threat behaviours
    • B.To gather feeds of adversary indicators into one enriched archive
    • C.To match incoming threat indicators against logs and raise alerts
    • D.To map observed threat techniques onto a matrix of tactic columns
    Show answerHide answer

    Correct answer: To gather feeds of adversary indicators into one enriched archive

    A TIP exists to gather feeds of adversary indicators into one enriched archive: it ingests commercial, open and sharing-community feeds, deduplicates and normalises them, and adds actor and campaign context for analysts and tools. Defining a structured language for describing threat behaviours is what STIX does; a TIP consumes STIX rather than defining it. Matching incoming threat indicators against logs and raising alerts is SIEM correlation, which the TIP feeds. Mapping techniques onto a matrix of tactic columns is the MITRE ATT&CK framework.

  43. In a cybersecurity context, what is the main purpose of implementing microsegmentation in a network?

    • A.To place public-facing servers inside a screened subnet
    • B.To check every device's posture before it joins the LAN
    • C.To split broadcast domains among the departmental VLANs
    • D.To stop lateral spread between two close workload zones
    Show answerHide answer

    Correct answer: To stop lateral spread between two close workload zones

    Microsegmentation is used to stop lateral spread between two close workload zones, enforcing policy on east-west traffic at the workload level. Placing public-facing servers inside a screened subnet is a DMZ, which separates internet-facing hosts from the internal network but leaves the inside flat. Checking device posture before it joins the LAN is network access control at the point of entry. Splitting broadcast domains among departmental VLANs is coarse segmentation for traffic management, not per-workload policy.

  44. What is the primary goal of Security Orchestration, Automation, and Response (SOAR)?

    • A.To correlate the aggregated security logs into a central console
    • B.To aggregate threat intelligence feeds into one scored IoC list
    • C.To run stored response playbooks across the linked defence tools
    • D.To record endpoint telemetry so response teams can isolate hosts
    Show answerHide answer

    Correct answer: To run stored response playbooks across the linked defence tools

    The primary goal of SOAR is to run stored response playbooks across the linked defence tools, so enrichment, containment and ticketing steps execute without waiting for an analyst. Correlating aggregated security logs in a central console is the job of a SIEM. Aggregating threat intelligence feeds into a scored indicator list is a threat intelligence platform. Recording endpoint telemetry so hosts can be isolated is EDR, a tool SOAR calls rather than replaces.

  45. Which technology is primarily used to protect sensitive data by transforming it into an unreadable format?

    • A.Classification
    • B.Retention
    • C.Watermarking
    • D.Tokenization
    Show answerHide answer

    Correct answer: Tokenization

    Tokenization replaces a sensitive value such as a card number with a surrogate token that is meaningless outside the vault that maps it back, so downstream systems hold unreadable data. Classification labels data by sensitivity so controls can be applied, but leaves the value readable. Retention governs how long data is kept before disposal, but stored values stay readable throughout. Watermarking embeds an identifying mark to trace leaks and ownership without making the content unreadable.

  46. What is the main function of a Next-Generation Firewall (NGFW) in cybersecurity?

    • A.To relay each client's web requests and cache the pages sent
    • B.To check each client's device posture before it joins a LAN
    • C.To judge sessions by application type rather than port alone
    • D.To record each connection in a state table and admit replies
    Show answerHide answer

    Correct answer: To judge sessions by application type rather than port alone

    The defining function of a next-generation firewall is to judge sessions by application type rather than port alone, folding application identification, user identity and intrusion prevention into one policy decision. Relaying each client's web requests and caching the pages sent is the job of a forward proxy, not a firewall. Checking each client's device posture before it joins a LAN is network access control (NAC). Recording each connection in a state table and admitting replies is a stateful firewall, the older capability an NGFW builds on rather than the function that defines it.

  47. In cybersecurity, what is the primary role of an Endpoint Detection and Response (EDR) tool?

    • A.To record laptop process activity then isolate one infected host
    • B.To gather firewall proxy records into one central review console
    • C.To bar unknown hardware from the corporate wired network segment
    • D.To scramble the contents of a missing workstation disk partition
    Show answerHide answer

    Correct answer: To record laptop process activity then isolate one infected host

    Endpoint detection and response instruments the host itself, streaming process, file, registry and network telemetry to a console where behavioural detections fire and an analyst can kill a process, quarantine a file or cut the machine off the network remotely. Gathering network device records into a console is SIEM collection. Barring unknown hardware from a network segment is admission control. Full-disk encryption defends data on a missing machine but produces no telemetry and takes no action against a live intrusion.

  48. In cybersecurity, what is the purpose of a Secure Web Gateway (SWG)?

    • A.To shield a public web server from active injection attempts
    • B.To filter staff web traffic against an acceptable use policy
    • C.To grant remote workers an encrypted tunnel into head office
    • D.To rank bandwidth priority for real-time voice over the link
    Show answerHide answer

    Correct answer: To filter staff web traffic against an acceptable use policy

    A secure web gateway sits between users and the internet and inspects their outbound browsing, applying URL categorisation, malware scanning and the organisation's acceptable use rules before a page is delivered. Shielding a public site from injection is the job of a web application firewall, which protects the server side rather than the user side. A remote access tunnel provides confidentiality for staff working off site. Prioritising voice traffic is quality of service, a capacity control with no policy or content role.

  49. Which cybersecurity tool is specifically designed to protect against malware and exploits targeting mobile devices?

    • A.Mobile device management
    • B.Mobile application management
    • C.Mobile application wrapping
    • D.Mobile content management
    Show answerHide answer

    Correct answer: Mobile device management

    Mobile device management is the tool built to protect the handset itself: it enrols the device, enforces hardened settings, pushes operating system updates that close exploits, and restricts installs to approved sources. Mobile application management governs only managed corporate apps and their data, not the device's patch level. Mobile application wrapping is a MAM technique that adds policy to an individual app and leaves the rest of the device unprotected. Mobile content management controls access to corporate documents and does nothing about malware on the platform.

  50. Which technology is primarily used to detect and prevent data exfiltration via email in an organization?

    • A.Inbound email sandboxing
    • B.S/MIME email encryption
    • C.Gateway email encryption
    • D.Outbound email filtering
    Show answerHide answer

    Correct answer: Outbound email filtering

    Outbound email filtering inspects recipients, message bodies and attachments as mail leaves and blocks or quarantines content that breaches data-loss rules, which is what stops exfiltration by email. Inbound sandboxing detonates attachments arriving from outside, so it guards against malware, not leakage. S/MIME and gateway encryption protect the confidentiality of a message in transit, but an insider can still encrypt and send sensitive data out, so neither detects or prevents exfiltration.

  51. What is the main purpose of employing a Security Assertion Markup Language (SAML) in a federated identity management system?

    • A.To push a second factor challenge onto the primary handset
    • B.To copy directory group records into a linked account list
    • C.To let a single login unlock many partner service gateways
    • D.To sign the audit archive so entries cannot be overwritten
    Show answerHide answer

    Correct answer: To let a single login unlock many partner service gateways

    In a federation the identity provider authenticates the user once and then issues an assertion that each participating service provider trusts, so the user reaches every partner application without presenting credentials again; that is single sign-on. A second-factor challenge strengthens one authentication event but does not carry it to another party. Copying directory records into a downstream list is provisioning. Signing an audit archive protects its integrity, and none of those three removes the repeated login.

  52. In the context of security architecture, what is a primary function of a Botnet Detection System?

    • A.To scrub inbound flood traffic before it hits the web server
    • B.To flag internal hosts in constant contact with a controller
    • C.To lure attacker traffic onto a decoy server to record tools
    • D.To flag user accounts whose logins drift from their baseline
    Show answerHide answer

    Correct answer: To flag internal hosts in constant contact with a controller

    A botnet detection system works to flag internal hosts in constant contact with a controller, spotting the regular command-and-control beacons and lookups that betray an enrolled machine. Scrubbing inbound flood traffic is DDoS mitigation, which defends against a botnet's attack but does not find infected hosts inside. Luring attackers to a decoy server is a honeypot. Flagging accounts whose logins drift from a baseline is UEBA, which watches users rather than command channels.

  53. A SOC analyst is reviewing firewall connection logs and notices that an internal workstation opens a small outbound HTTPS connection to the same external IP address every 60 seconds, give or take a few seconds, around the clock with very little data transferred each time. Which malicious activity does this pattern most strongly indicate?

    • A.Exfiltrating archived data away over an encrypted upload pipeline
    • B.Spraying reused passwords across the whole domain controller pool
    • C.Beaconing to the attacker-run control server at regular intervals
    • D.Tunnelling the stolen records inside crafted name lookup requests
    Show answerHide answer

    Correct answer: Beaconing to the attacker-run control server at regular intervals

    Small, low-volume outbound sessions to one fixed destination at a near-constant interval with slight jitter is the signature of malware checking in with its command-and-control infrastructure for instructions. Bulk exfiltration would show large sustained transfers rather than a few bytes each cycle. Password spraying is an authentication pattern aimed at many accounts and would surface in logon telemetry, not as a single repeating outbound session. Smuggling data inside name resolution traffic would appear on resolver traffic and would also move far more data than this pattern shows.

  54. After a phishing victim's laptop is compromised, the attacker uses the victim's harvested domain credentials to authenticate to several other internal servers over SMB and RDP, expanding access without deploying new malware. In the MITRE ATT&CK framework, this behavior is best categorized as which tactic?

    • A.Lateral movement, reusing stolen accounts to reach other hosts
    • B.Defense evasion, using valid accounts so no malware is spotted
    • C.Credential access, harvesting the domain passwords by phishing
    • D.Initial access, signing in with the phished valid user account
    Show answerHide answer

    Correct answer: Lateral movement, reusing stolen accounts to reach other hosts

    The behaviour is lateral movement, reusing stolen accounts to reach other hosts: the attacker pivots from the first laptop to additional internal servers over SMB and RDP with harvested credentials. Defense evasion also lists Valid Accounts as a technique, but the tactic being described is the expansion to new systems, not hiding. Credential access, harvesting the domain passwords by phishing, is the earlier theft that has already happened. Initial access, signing in with the phished account, describes the first foothold, not spreading from it to other servers.

  55. A security team wants to reduce analyst workload by automatically enriching alerts, querying threat intelligence, and executing predefined containment playbooks when a high-confidence detection fires. Which technology is specifically designed to orchestrate and automate these response workflows across multiple security tools?

    • A.SIEM, which correlates the alerts many security tools generate
    • B.EDR, which records the process behaviour of enrolled endpoints
    • C.CASB, which mediates staff access to sanctioned cloud services
    • D.SOAR, which chains the response playbooks over vendor consoles
    Show answerHide answer

    Correct answer: SOAR, which chains the response playbooks over vendor consoles

    Security orchestration, automation and response is the platform category built to connect separate products, run codified playbooks against them and carry out enrichment or containment automatically once a high-confidence detection fires. A SIEM aggregates and correlates telemetry to raise the detection but does not execute cross-product response. An EDR agent inspects and can contain a single endpoint, so its reach stops at the host. A cloud access security broker governs how users reach cloud services and orchestrates nothing across the wider tool set.

  56. An analyst is explaining the difference between an indicator of compromise (IoC) and an indicator of attack (IoA) to a junior teammate. Which statement correctly distinguishes the two?

    • A.An IoC is a behaviour signature; an IoA is a stored artefact
    • B.An IoC names the threat actor group; an IoA rates the damage
    • C.An IoC is proof a breach occurred; an IoA shows early intent
    • D.An IoC is a vendor detection alert; an IoA is scanner output
    Show answerHide answer

    Correct answer: An IoC is proof a breach occurred; an IoA shows early intent

    An indicator of compromise is forensic residue proving an intrusion already took place, such as a malicious hash, a callback address or a rogue registry key, while an indicator of attack describes adversary behaviour and objective while the operation is still unfolding, which is what allows detection before the damage lands. Reversing the two mislabels post-event artefacts as live behaviour. Neither term identifies a threat actor group or scores impact; that is attribution and impact analysis. Neither is a vendor detection alert or a scanner output, which are tooling products rather than indicator classes.

  57. A malware analyst needs to extract the behavior of a suspicious executable, including the network connections it makes and the files it drops, but wants to do so without studying its raw code line by line. Which analysis approach should the analyst use, and where should it be performed?

    • A.Dynamic analysis, by detonating the sample inside a sealed sandbox
    • B.Dynamic analysis, by attaching a debugger on the analyst's machine
    • C.Static analysis, by disassembling the binary within a code browser
    • D.Static analysis, by comparing the file hash against threat records
    Show answerHide answer

    Correct answer: Dynamic analysis, by detonating the sample inside a sealed sandbox

    Running the sample and watching what it does is dynamic analysis, and doing it in an isolated, instrumented sandbox is what safely yields the dropped files, spawned processes and outbound callbacks the analyst wants. Attaching a debugger on a working laptop is still dynamic but places live malware on a production-connected machine with no containment. Disassembling the binary is static analysis and means reading code line by line, the very thing the analyst wants to avoid. Comparing a hash against threat feeds is a static reputation lookup that reveals no behaviour at all.

Vulnerability Management (60)

  1. What is the primary purpose of a vulnerability scanner in cybersecurity?

    • A.Enumerating known weaknesses on hosts and their loaded applications
    • B.Exploiting live flaws on target systems to show the attacker impact
    • C.Mapping live systems and listening services across local subnets
    • D.Pushing vendor patches to the servers and workstations missing them
    Show answerHide answer

    Correct answer: Enumerating known weaknesses on hosts and their loaded applications

    A vulnerability scanner's primary purpose is enumerating known weaknesses on hosts and their loaded applications, comparing versions, patch levels, services and settings against a database of published flaws. Exploiting live flaws on target systems to show the attacker impact is penetration testing, which goes past identification to proof. Mapping live systems and listening services across local subnets is network discovery with a mapper such as Nmap, a step that comes before vulnerability assessment. Pushing vendor patches to the servers and workstations missing them is patch management, the remediation that acts on scan results rather than producing them.

  2. In cybersecurity, what is the primary purpose of conducting a vulnerability scan?

    • A.To inventory each host and listening service on the network
    • B.To exploit the discovered flaws and demonstrate real impact
    • C.To reveal unpatched software and weak server configurations
    • D.To rank discovered flaws by their CVSS score for patching
    Show answerHide answer

    Correct answer: To reveal unpatched software and weak server configurations

    The primary purpose of a vulnerability scan is to reveal unpatched software and weak server configurations, producing a list of known exposures to fix before attackers find them. Inventorying each host and listening service is asset discovery, a mapping step that precedes the vulnerability check. Exploiting discovered flaws to demonstrate real impact is penetration testing, which a scan deliberately stops short of. Ranking discovered flaws by CVSS score is prioritisation that happens after the scan, using its output rather than being its purpose.

  3. Which of the following vulnerability scanning techniques is LEAST likely to be detected by intrusion detection systems?

    • A.Credentialed scanning, authenticating remotely onto each targeted system
    • B.Non-credentialed scanning, probing exposed services from public networks
    • C.Passive scanning, interpreting traffic silently duplicated onto monitors
    • D.Active scanning, transmitting crafted packets towards identified targets
    Show answerHide answer

    Correct answer: Passive scanning, interpreting traffic silently duplicated onto monitors

    Correct answer: Passive scanning, interpreting traffic silently duplicated onto monitors. A passive scanner infers software versions and weaknesses from traffic copied to it by a span port or network tap, so it generates no packets of its own and leaves an intrusion detection system nothing to notice. Credentialed scanning, authenticating remotely onto each targeted system, logs in and queries the host, producing authentication events and local activity that are readily logged. Non-credentialed scanning, probing exposed services from public networks, still sends live requests to open ports and trips the same signatures. Active scanning, transmitting crafted packets towards identified targets, is the noisiest of all and is exactly the behavior detection rules are written to catch.

  4. In vulnerability management, what is the main purpose of a "false negative" result?

    • A.It escalates a harmless finding that no exposure substantiates
    • B.It reports a passing scan while exploitable weaknesses persist
    • C.It confirms a protected host after exhaustive probing succeeds
    • D.It validates a genuine finding that matching evidence supports
    Show answerHide answer

    Correct answer: It reports a passing scan while exploitable weaknesses persist

    Correct answer: It reports a passing scan while exploitable weaknesses persist. A false negative is a miss: the test returns a clean result although a genuine, exploitable flaw is present, and because the output looks healthy the exposure is never queued for remediation. That is the outcome analysts fear most, which is why scan results are validated against a second source. It escalates a harmless finding that no exposure substantiates describes a false positive, which wastes triage effort but hides no risk. It confirms a protected host after exhaustive probing succeeds is a true negative, an accurate clean result. It validates a genuine finding that matching evidence supports is a true positive, an accurate detection of a real flaw.

  5. Which of the following best describes the role of fuzzing in vulnerability management?

    • A.Reading source code for flaws without running it
    • B.Submitting malformed inputs until programs crash
    • C.Sending known attack strings to the running site
    • D.Sending valid inputs to verify the site's output
    Show answerHide answer

    Correct answer: Submitting malformed inputs until programs crash

    Fuzzing is submitting malformed inputs until programs crash, watching for the crashes, hangs and memory faults that expose unhandled code paths. Reading source code for flaws without running it is static analysis, which never executes the program. Sending known attack strings to the running site is dynamic scanning with a fixed payload library, which tests for recognised attacks rather than generating malformed input. Sending valid inputs to verify the site's output is functional testing, which confirms expected behavior instead of hunting for failures under unexpected input.

  6. In the context of vulnerability scanning, what does the term "pivot" refer to?

    • A.Rotating stored scanner logins between audit windows
    • B.Raising administrator privileges on a trusted server
    • C.Switching scan profiles midway through an assessment
    • D.Relaying traffic through an already compromised host
    Show answerHide answer

    Correct answer: Relaying traffic through an already compromised host

    Correct answer: Relaying traffic through an already compromised host. Explanation: Pivoting means routing further reconnaissance and attack traffic through a machine the attacker already controls, so internal systems that were never exposed to the attacker directly become reachable through the foothold. Rotating stored scanner logins between audit windows is credential hygiene for the assessment platform and involves no attacker movement at all. Raising administrator privileges on a trusted server is privilege escalation, which increases rights on one host rather than extending reach to another. Switching scan profiles midway through an assessment is retuning the scan, not using a foothold as a relay.

  7. What is a primary concern when conducting authenticated vulnerability scans?

    • A.Intrusive probes destabilizing the scanned server
    • B.Signature feeds trailing behind vendor advisories
    • C.Scanner findings duplicating the stored inventory
    • D.Firewall policies blocking outbound probe traffic
    Show answerHide answer

    Correct answer: Intrusive probes destabilizing the scanned server

    Correct answer: Intrusive probes destabilizing the scanned server. Explanation: A credentialed scan logs in and runs far deeper checks than an external sweep, enumerating services, reading local configuration and exercising interfaces the network never exposes, so the leading operational risk is that a fragile service or host becomes unstable while the scan runs. Signature feeds trailing behind vendor advisories degrades every scan equally, credentialed or not, so it is not what changes when credentials are supplied. Scanner findings duplicating the stored inventory is an asset-management annoyance and poses no risk to the target. Firewall policies blocking outbound probe traffic describes an obstacle to unauthenticated external scanning, which local credentialed checks largely bypass.

  8. Which term best describes a situation where a vulnerability scanner incorrectly identifies a secure system as vulnerable?

    • A.True positive scan outcome
    • B.False negative scan report
    • C.False positive scan result
    • D.True negative scan finding
    Show answerHide answer

    Correct answer: False positive scan result

    Correct answer: False positive scan result. Explanation: A false positive is a finding the scanner raises against a system that is not actually vulnerable, so effort is spent chasing a condition that does not exist and confidence in the tool erodes. False negative scan report names the opposite failure, a real weakness the scanner missed entirely. True positive scan outcome names a finding that is both raised and real, which cannot describe a system the stem tells us is secure. True negative scan finding names a healthy system correctly left unflagged, and here the scanner did flag it.

  9. In vulnerability management, what is the significance of CVSS scoring?

    • A.Predicting the chance a flaw is exploited soon
    • B.Assigning a unique identifier to each new flaw
    • C.Ranking remediation tasks by measured severity
    • D.Flagging flaws known to be exploited by actors
    Show answerHide answer

    Correct answer: Ranking remediation tasks by measured severity

    CVSS matters because it supports ranking remediation tasks by measured severity, giving a repeatable score a team can use to order a backlog. Predicting the chance a flaw is exploited soon is what EPSS does, a probability rather than a severity. Assigning a unique identifier to each flaw is the CVE program. Flagging flaws known to be exploited by actors is the CISA KEV catalog, which lists exploitation evidence rather than scoring severity.

  10. Which vulnerability assessment technique involves examining the system from within to simulate an attack by a malicious insider?

    • A.White box testing engagements
    • B.Black box testing engagements
    • C.Gray box testing walkthroughs
    • D.Red team adversary emulations
    Show answerHide answer

    Correct answer: White box testing engagements

    Correct answer: White box testing engagements. Explanation: A white box engagement hands the tester full internal information, including source, architecture, configuration and credentials, which is exactly the position a trusted insider already occupies, so it is the technique that reproduces insider abuse. Black box testing engagements withhold that information and model an outsider working blind. Gray box testing walkthroughs share only partial detail, so they reproduce neither the insider's full visibility nor the outsider's blindness. Red team adversary emulations measure whether defenders detect and respond to a goal-driven attack, so their product is a picture of the response rather than an exhaustive internal review.

  11. When a vulnerability scanner reports a vulnerability due to outdated software, but the software is actually up to date, this is an example of:

    • A.False negative result
    • B.Type II error result
    • C.True negative result
    • D.False positive alert
    Show answerHide answer

    Correct answer: False positive alert

    A false positive alert is a scanner reporting a weakness that verification shows is not present, here outdated software that is actually current. A false negative result is the reverse error, where a genuinely stale package goes unreported. A Type II error result is the statistical name for that same false negative, so it is wrong for the same reason; the false positive is a Type I error. A true negative result would mean the scanner correctly stayed silent about a healthy host, but it raised a finding.

  12. What is the primary benefit of using automated vulnerability scanning tools in an organization?

    • A.Ranking the findings by the business risk they pose
    • B.Repeating thorough checks with little manual effort
    • C.Proving the findings by exploiting the weak systems
    • D.Fixing the weak systems once the scans are finished
    Show answerHide answer

    Correct answer: Repeating thorough checks with little manual effort

    The primary benefit of automated scanning is repeating thorough checks with little manual effort: the same broad checkset runs across the whole estate on a schedule no team could match by hand. Ranking the findings by the business risk they pose is analyst work; a scanner supplies generic CVSS scores, not business context. Proving the findings by exploiting the weak systems is a penetration test, since a scanner infers a flaw from version and configuration data. Fixing the weak systems once the scans are finished is remediation, which scanners do not perform and which must go through change management.

  13. Which of the following best describes the purpose of a penetration test in the context of vulnerability management?

    • A.Emulating a real adversary to prove exploitability
    • B.Enumerating known flaws to build a remediation log
    • C.Rescanning a patched asset to confirm the fix held
    • D.Scoring each finding to rank the remediation queue
    Show answerHide answer

    Correct answer: Emulating a real adversary to prove exploitability

    A penetration test is about emulating a real adversary to prove exploitability: it moves past the theoretical finding and shows which weaknesses an attacker can actually convert into access. Enumerating known flaws to build a remediation log is vulnerability scanning, which identifies but never exploits. Rescanning a patched asset to confirm the fix held is validation after remediation. Scoring each finding to rank the remediation queue is CVSS-based prioritisation, which estimates risk without demonstrating it.

  14. In vulnerability management, what is the primary role of a patch management system?

    • A.Enforcing hardened baselines across the network
    • B.Discovering unmanaged assets across the network
    • C.Scheduling vendor updates for managed endpoints
    • D.Approving change requests before any deployment
    Show answerHide answer

    Correct answer: Scheduling vendor updates for managed endpoints

    A patch management system is responsible for scheduling vendor updates for managed endpoints: it obtains updates, rolls them through test and production rings, and reports what remains outstanding. Enforcing hardened baselines across the network is configuration management, which controls settings rather than vendor code. Discovering unmanaged assets across the network is asset discovery, which feeds patching but deploys nothing. Approving change requests before any deployment is the change advisory board's role, a governance step rather than the patching tool.

  15. Which vulnerability assessment methodology focuses on the security of third-party components within a system?

    • A.Static application code analysis
    • B.Open source composition analysis
    • C.Dynamic runtime traffic analysis
    • D.External network banner analysis
    Show answerHide answer

    Correct answer: Open source composition analysis

    Correct answer: Open source composition analysis. Explanation: Composition analysis inventories the third-party and open-source packages an application pulls in, resolves their transitive dependencies, and matches each one against published advisories, so it is the method aimed squarely at code the team did not write. Static application code analysis inspects the organization's own source for insecure patterns and generally ignores what arrives from a package manager. Dynamic runtime traffic analysis exercises the deployed application from outside and cannot attribute a fault to a particular library version. External network banner analysis identifies exposed service versions at the network edge, which reveals nothing about libraries linked into an application.

  16. In the context of vulnerability management, what is the main objective of threat modeling?

    • A.Searching live systems for intruders already inside
    • B.Exploiting live systems to prove a weakness is real
    • C.Tracking named adversary groups through intel feeds
    • D.Predicting adversary moves against a planned design
    Show answerHide answer

    Correct answer: Predicting adversary moves against a planned design

    Threat modeling is predicting adversary moves against a planned design: it names likely attackers and walks their paths through the architecture so controls are chosen before the system ships. Searching live systems for intruders already inside is threat hunting, which looks for a present compromise in production. Exploiting live systems to prove a weakness is real is penetration testing, which validates flaws in deployed systems rather than reasoning about a design. Tracking named adversary groups through intel feeds is threat intelligence, an input to modeling rather than the modeling itself.

  17. Which of the following best defines a zero-day vulnerability?

    • A.A flaw its vendor patched that's awaiting rollout
    • B.A flaw rebuilt by attackers from a vendor's patch
    • C.A flaw disclosed publicly along with a vendor fix
    • D.A flaw still lacking published vendor remediation
    Show answerHide answer

    Correct answer: A flaw still lacking published vendor remediation

    A zero-day is a flaw still lacking published vendor remediation: the vendor has had zero days to fix it, so defenders have no patch and must rely on mitigation and detection. A flaw its vendor patched that's awaiting rollout is an n-day, a patching failure where a fix already exists. A flaw rebuilt by attackers from a vendor's patch is patch diffing, which by definition starts from a released fix. A flaw disclosed publicly along with a vendor fix is coordinated disclosure, and the shipped fix is exactly what a zero-day lacks.

  18. What is the primary benefit of continuous vulnerability scanning as compared to periodic scanning?

    • A.Revealing flaws that credentialed scanners spot
    • B.Finding new exposures that scheduled scans miss
    • C.Catching zero-days that signature scanners miss
    • D.Sparing the bandwidth that network scanners use
    Show answerHide answer

    Correct answer: Finding new exposures that scheduled scans miss

    The benefit is finding new exposures that scheduled scans miss: continuous assessment closes the window between periodic sweeps, so new hosts and newly disclosed weaknesses surface quickly. Revealing flaws that credentialed scanners spot is the benefit of authenticated scanning, which is about depth, not cadence. Catching zero-days that signature scanners miss is not possible for any scanner, since checks exist only for known flaws. Sparing the bandwidth that network scanners use is an agent-based scanning benefit, not a continuous-scanning one.

  19. In vulnerability management, what is the primary purpose of a baseline configuration?

    • A.To restore lost records after a controller failure
    • B.To flag unusual outbound traffic from user subnets
    • C.To capture the approved settings for server builds
    • D.To scramble records kept on portable media devices
    Show answerHide answer

    Correct answer: To capture the approved settings for server builds

    Correct answer: To capture the approved settings for server builds. Explanation: A baseline is the documented secure state a system is built to and the reference every later audit compares against, which is what makes drift measurable and what gives a hardening standard something to enforce. To restore lost records after a controller failure is backup and recovery, which returns data rather than defining a standard. To flag unusual outbound traffic from user subnets is network monitoring, which reacts to observed behavior instead of prescribing state. To scramble records kept on portable media devices is media encryption, a data-protection control that leaves system settings untouched.

  20. Which technology is primarily used to isolate applications in their own secure environment to prevent vulnerabilities from affecting other applications?

    • A.Container based workload isolation
    • B.Host based application allow lists
    • C.Network based application segments
    • D.Least privilege service identities
    Show answerHide answer

    Correct answer: Container based workload isolation

    Container based workload isolation gives each application its own namespaces, filesystem view and resource limits, so a vulnerability exploited in one stays inside that boundary on the shared host. Host based application allow lists control which programs may run but do not separate the programs that are allowed. Network based application segments limit traffic between hosts and subnets, not between applications sharing a host. Least privilege service identities reduce what a compromised account can do but give the application no separate runtime environment.

  21. What is the role of a vulnerability feed in a vulnerability management program?

    • A.Delivering signed patches directly to managed hosts
    • B.Supplying current advisory data on known weaknesses
    • C.Streaming alerts about intrusions already under way
    • D.Logging privileged sessions for later abuse reviews
    Show answerHide answer

    Correct answer: Supplying current advisory data on known weaknesses

    Correct answer: Supplying current advisory data on known weaknesses. Explanation: A vulnerability feed is a subscription stream of advisory records, carrying identifiers, affected versions, severity and fix status, which keeps scanner checks and the analyst's picture of the landscape current. Delivering signed patches directly to managed hosts is distribution performed by a patch management system, and a feed carries descriptions rather than binaries. Streaming alerts about intrusions already under way is detection telemetry, which reports live activity instead of catalogued weaknesses. Logging privileged sessions for later abuse reviews is monitoring of insider activity and produces audit trails, not advisory content.

  22. What is a primary consideration when performing vulnerability scans on production systems?

    • A.Throttling probes to protect busy customer workloads
    • B.Maintaining the scanner signature feed fully current
    • C.Storing finished reports inside an encrypted archive
    • D.Verifying asset owners before granting any exception
    Show answerHide answer

    Correct answer: Throttling probes to protect busy customer workloads

    Correct answer: Throttling probes to protect busy customer workloads. Explanation: Scanning consumes bandwidth, sockets and processor time on live systems, so on production the governing consideration is pacing, which means limiting concurrency, tuning intrusive checks and picking windows so revenue-bearing services do not degrade while the assessment runs. Maintaining the scanner signature feed fully current matters for every scan, in the laboratory as much as in production, so it does not describe what production changes. Storing finished reports inside an encrypted archive protects the output after the fact and has no bearing on the target's stability. Verifying asset owners before granting any exception belongs to the risk acceptance workflow that follows a finding.

  23. Which aspect of vulnerability management is specifically concerned with identifying weak points in wireless networks?

    • A.Capturing traffic from a mirrored network port
    • B.Sending fake phishing lures to staff mailboxes
    • C.Surveying radio beacons from a passing vehicle
    • D.Reviewing firewall rule sets for stale entries
    Show answerHide answer

    Correct answer: Surveying radio beacons from a passing vehicle

    Correct answer: Surveying radio beacons from a passing vehicle. Explanation: War driving means moving through an area while recording the wireless networks that advertise themselves, so weak encryption, default network names and unsanctioned access points are found from outside the building where the signal actually reaches. Capturing traffic from a mirrored network port is wired packet capture and cannot see coverage leaking past the walls. Sending fake phishing lures to staff mailboxes tests human susceptibility, which is a different exposure entirely. Reviewing firewall rule sets for stale entries is a configuration review of a wired control and finds nothing about rogue radios.

  24. What is the primary function of a Web Application Firewall (WAF) in the context of vulnerability management?

    • A.Probing web applications for flaws in their code
    • B.Blocking exploit signatures across network hosts
    • C.Spreading incoming traffic across backend nodes
    • D.Filtering hostile requests aimed at hosted sites
    Show answerHide answer

    Correct answer: Filtering hostile requests aimed at hosted sites

    A web application firewall's primary function is filtering hostile requests aimed at hosted sites: it sits in front of the application and inspects HTTP traffic so injection, scripting and similar attacks are blocked before the code handles them, often acting as a virtual patch. Probing web applications for flaws in their code is what a dynamic application scanner does; it finds weaknesses rather than stopping requests. Blocking exploit signatures across network hosts describes a network intrusion prevention system, which is not focused on web application traffic. Spreading incoming traffic across backend nodes is load balancing, which distributes traffic without judging whether it is hostile.

  25. When conducting a vulnerability scan, what does "credential scanning" imply?

    • A.Probing exposed services without any login session
    • B.Logging into targets with supplied domain accounts
    • C.Testing logins for reused or predictable passwords
    • D.Dumping cached password hashes from process memory
    Show answerHide answer

    Correct answer: Logging into targets with supplied domain accounts

    Correct answer: Logging into targets with supplied domain accounts. Explanation: A credentialed scan is given working accounts by the asset owner so the scanner can sign in and read installed package versions, registry state and local configuration, which yields findings an outside view can only infer. Probing exposed services without any login session is the uncredentialed mode this term is defined against. Testing logins for reused or predictable passwords is a password strength audit, which attacks accounts rather than using granted ones. Dumping cached password hashes from process memory is attacker credential theft and is never an agreed assessment method.

  26. Which strategy in vulnerability management focuses on prioritizing the remediation of vulnerabilities based on the potential impact to the organization?

    • A.Risk weighted remediation ordering
    • B.CVSS severity remediation queueing
    • C.CVSS exploitability score queueing
    • D.Oldest findings first SLA queueing
    Show answerHide answer

    Correct answer: Risk weighted remediation ordering

    Risk weighted remediation ordering is the strategy that ranks fixes by what a weakness would cost this organization, weighing asset criticality, exposure, active exploitation and compensating controls together. CVSS severity remediation queueing uses the generic base score, which ignores how critical the affected asset is to this business. CVSS exploitability score queueing ranks only by how easy a flaw is to exploit, which is likelihood rather than organizational impact. Oldest findings first SLA queueing works through findings by age against a deadline and weighs no business consequence at all.

  27. What is the main purpose of a "black box" testing approach in vulnerability assessment?

    • A.Assessing an environment with no internal knowledge
    • B.Assessing with the defenders given no prior warning
    • C.Testing with partial knowledge such as network maps
    • D.Testing with full knowledge such as the source code
    Show answerHide answer

    Correct answer: Assessing an environment with no internal knowledge

    Black box testing means assessing an environment with no internal knowledge, the unknown-environment position, so findings show what an outside attacker could discover unaided. Assessing with the defenders given no prior warning describes a blind or double-blind exercise, which concerns the defenders' knowledge rather than the tester's. Testing with partial knowledge such as network maps is gray box. Testing with full knowledge such as source code is white box.

  28. In vulnerability management, what is the significance of a vulnerability's "attack vector"?

    • A.The privileges an intruder needs before the exploit
    • B.The path that an intruder follows toward compromise
    • C.The total set of entry points that a system exposes
    • D.The code an intruder runs after a flaw is triggered
    Show answerHide answer

    Correct answer: The path that an intruder follows toward compromise

    The attack vector is the path that an intruder follows toward compromise, whether network, adjacent, local or physical, and it drives CVSS severity. The privileges an intruder needs before the exploit is the separate Privileges Required metric. The total set of entry points a system exposes is the attack surface, which contains many vectors rather than defining one. The code an intruder runs after a flaw is triggered is the payload, which is what happens after reach is achieved.

  29. Which of the following best describes the role of "red teaming" in vulnerability management?

    • A.Pairing attack and defense teams to tune detections
    • B.Umpiring the rules between attack and defense teams
    • C.Mounting covert attacks to test defensive readiness
    • D.Exploiting each scanned flaw to prove its real risk
    Show answerHide answer

    Correct answer: Mounting covert attacks to test defensive readiness

    Red teaming means mounting covert attacks to test defensive readiness: the red team pursues an objective quietly and the result shows whether the blue team detected and responded. Pairing attack and defense teams to tune detections is purple teaming, which is collaborative rather than covert. Umpiring the rules between the teams is the white team's job. Exploiting each scanned flaw to prove its risk is a penetration test focused on breadth of vulnerabilities, not on defender readiness.

  30. Which type of security testing focuses on evaluating software by observing its execution and monitoring responses to different inputs?

    • A.Reading through the source tree for unsafe function call patterns
    • B.Driving a running build with crafted input while watching replies
    • C.Listing out each third-party library beside a published flaw list
    • D.Mapping the design against a catalogue of probable attacker goals
    Show answerHide answer

    Correct answer: Driving a running build with crafted input while watching replies

    Dynamic application security testing exercises the application while it is running: inputs are supplied from the outside, the responses and error behaviour are observed, and defects are inferred from how the live system reacts. Reading the source without executing it is static analysis. Enumerating third-party components against advisories is software composition analysis, which reports defects someone else has already published. Mapping a design against attacker goals is threat modelling, a paper exercise performed before any code runs.

  31. Which type of tool is most effective for detecting vulnerabilities in a network before an attacker does?

    • A.An authenticated network scanner
    • B.A continuous performance monitor
    • C.A distributed perimeter firewall
    • D.An automated detection appliance
    Show answerHide answer

    Correct answer: An authenticated network scanner

    A vulnerability scanner enumerates hosts, services and software versions and compares what it finds against a defect database, which surfaces exposures while they can still be fixed; running it with credentials produces the fullest and most accurate picture. A performance monitor watches throughput and latency and is blind to security defects. A perimeter firewall enforces an allow or deny decision on traffic but never inventories the weaknesses behind it. A detection appliance alerts on attacks in progress, which is knowledge arriving after the attacker has already begun.

  32. Which tool is essential for identifying unknown vulnerabilities in software applications before they are deployed?

    • A.A crawler probing a running instance for missing input validation
    • B.A checker matching each named library against public defect lists
    • C.A scanner reading the whole codebase for insecure coding patterns
    • D.A monitor watching the live servers for unusual outbound sessions
    Show answerHide answer

    Correct answer: A scanner reading the whole codebase for insecure coding patterns

    Static application security testing inspects source or byte code without running it, so insecure patterns such as unvalidated input reaching a query, hard-coded secrets or unsafe memory handling are found in the developer's own code well before a build is released. Probing a running instance requires a deployed application and is dynamic testing. Matching named libraries against public defect lists finds flaws already published by someone else. Monitoring live servers reports on software that is already exposed.

  33. A security analyst references CVE-2024-XXXXX in a remediation ticket. What does a CVE identifier actually represent?

    • A.A severity grade produced by a public open score formula
    • B.A unique global name tied to one disclosed software flaw
    • C.A catalogue of flaws confirmed to be under active attack
    • D.A class of source weakness outlined in a shared taxonomy
    Show answerHide answer

    Correct answer: A unique global name tied to one disclosed software flaw

    A Common Vulnerabilities and Exposures identifier is a catalogue entry: one unambiguous public name for a specific disclosed flaw, so that vendors, scanners and analysts all refer to the same thing. The numeric severity grade comes from CVSS, a separate scoring framework. The list of flaws under active exploitation is a distinct catalogue maintained for prioritisation, not an identifier scheme. A class of weakness is what CWE describes, a taxonomy of flaw types rather than a name for one concrete instance.

  34. An analyst is explaining the difference between CVE and CVSS to a junior teammate. Which statement is correct?

    • A.CVE gives a flaw its severity range; CVSS gives it a plain marker
    • B.CVE gives a flaw an exploited status; CVSS gives it the fix state
    • C.CVE gives a flaw its own fault type; CVSS gives the product label
    • D.CVE gives a flaw its unique name; CVSS measures how serious it is
    Show answerHide answer

    Correct answer: CVE gives a flaw its unique name; CVSS measures how serious it is

    The two schemes do different jobs: CVE assigns one unique identifier to a specific disclosed flaw so everyone can name it the same way, while CVSS produces a numeric severity score from defined metrics so findings can be compared and ranked. Swapping the two roles inverts the relationship and is the most common confusion. Neither scheme records whether a flaw is under exploitation or whether a vendor fix exists; those are separate catalogues. Neither one names weakness categories or affected products, which are the jobs of a weakness taxonomy and an asset inventory.

  35. A vulnerability has a CVSS v3.1 base score of 7.4. Which qualitative severity rating does that score fall into?

    • A.High, a grade that demands a fast remediation push
    • B.Low, a verdict that owners accept as residual risk
    • C.Medium, a score that fits the ordinary patch cycle
    • D.Critical, a flaw that most teams call an emergency
    Show answerHide answer

    Correct answer: High, a grade that demands a fast remediation push

    Under the CVSS version 3.1 qualitative scale a base score of 7.4 sits in the High band, which runs from 7.0 to 8.9. It is above the Medium band, which stops at 6.9, and below the Critical band, which starts at 9.0, so neither of those labels applies. The Low band tops out at 3.9 and is far below this score. Translating a raw number into the right band matters because remediation timelines in most policies are written against the band rather than the decimal.

  36. Which set of values correctly maps CVSS v3.1 base scores to their qualitative severity labels?

    • A.0.1-2.9 Low, 3.0-5.9 Medium, 6.0-8.9 High, 9.0-10.0 Critical
    • B.0.1-4.9 Low, 5.0-7.9 Medium, 8.0-9.4 High, 9.5-10.0 Critical
    • C.0.1-3.9 Low, 4.0-6.9 Medium, 7.0-8.9 High, 9.0-10.0 Critical
    • D.0.1-3.9 Low, 4.0-7.9 Medium, 8.0-8.9 High, 9.0-10.0 Critical
    Show answerHide answer

    Correct answer: 0.1-3.9 Low, 4.0-6.9 Medium, 7.0-8.9 High, 9.0-10.0 Critical

    The published CVSS version 3.1 qualitative severity ranges are 0.1 to 3.9 Low, 4.0 to 6.9 Medium, 7.0 to 8.9 High, and 9.0 to 10.0 Critical, with a score of exactly zero rated None. Every other mapping shown here shifts one or more of those boundaries, so a score would be labelled a band too high or a band too low. Knowing the real boundaries lets an analyst convert a raw base score into the wording used in policy, ticket priorities and executive reporting without looking it up.

  37. What does the CVSS base score group specifically measure about a vulnerability?

    • A.The maturity of public exploit code and the state of fixes
    • B.The stable traits of the flaw itself and its direct impact
    • C.The value of the affected asset and the controls around it
    • D.The chance the issue gets exploited and the pace of spread
    Show answerHide answer

    Correct answer: The stable traits of the flaw itself and its direct impact

    Base metrics capture the qualities of a vulnerability that do not change with time or with where it is deployed: attack vector, attack complexity, privileges required, user interaction, scope, and the confidentiality, integrity and availability impact. How mature public exploit code is and whether a vendor fix exists are temporal factors that shift week by week. How valuable the affected asset is and what compensating controls surround it are environmental factors specific to one deployment. The probability of exploitation in a coming window is a threat-driven estimate produced outside the base group entirely.

  38. A CVSS vector string for a flaw shows the Attack Vector metric as Network (AV:N). What does this indicate?

    • A.The flaw can be reached with no privilege on the target
    • B.The flaw can be reached with no click by a network user
    • C.The flaw can be reached from the shared network segment
    • D.The flaw can be reached from any routable network route
    Show answerHide answer

    Correct answer: The flaw can be reached from any routable network route

    AV:N means the flaw can be reached from any routable network route: the vulnerable component is bound to the network stack and can be attacked across routers, up to the open internet. Being reachable with no privilege on the target is what Privileges Required: None (PR:N) records, a separate metric that also uses the letter N. Being exploitable with no click by a network user is User Interaction: None (UI:N), again a different metric. Reachable only from the shared network segment, the same broadcast domain, is the Adjacent value (AV:A), which is more constrained than Network.

  39. When manually deriving a CVSS v3.1 score, which inputs feed the Exploitability sub-score of the base metric group?

    • A.The Confidentiality, Integrity and Availability impacts with Scope changes
    • B.Exploit Code Maturity, Remediation Level and Report Confidence assessments
    • C.Attack Vector, Attack Complexity, Privileges Required and User Interaction
    • D.Asset criticality, deployment context and the in-place mitigation strength
    Show answerHide answer

    Correct answer: Attack Vector, Attack Complexity, Privileges Required and User Interaction

    The exploitability sub-score of the base group is built from attack vector, attack complexity, privileges required and user interaction, the four metrics describing how hard the flaw is to reach and to trigger. The confidentiality, integrity and availability impacts, together with any change of scope, feed the separate impact sub-score instead. Exploit code maturity, remediation level and report confidence belong to the temporal group and adjust an already published base score. Asset criticality, deployment context and the mitigations already in place belong to the environmental group, which tailors a score to one site.

  40. Which CVSS metric group adjusts a base score over time based on factors like exploit code maturity and patch availability?

    • A.Temporal metrics, which track how the threat picture develops
    • B.Base metrics, which represent the flaw's own fixed properties
    • C.Environmental metrics, which weigh one site's own local setup
    • D.Impact metrics, which quantify the damage one breach inflicts
    Show answerHide answer

    Correct answer: Temporal metrics, which track how the threat picture develops

    The temporal group exists to move a score as real-world conditions change, using exploit code maturity, remediation level and report confidence, so a flaw whose proof-of-concept becomes a weaponised exploit or whose vendor patch ships is rescored accordingly. Base metrics are deliberately fixed and describe the flaw itself. Environmental metrics adjust for one organisation's asset value and compensating controls rather than for the passage of time. The impact metrics measure the damage a successful exploit causes and sit inside the base group.

  41. An organization wants its CVSS scores to reflect that a vulnerable server holds highly sensitive data and sits behind strict network segmentation. Which CVSS metric group should it apply?

    • A.Temporal metrics, which follow how the exploit code ages
    • B.Environmental metrics, which retune a score for one site
    • C.Base metrics, which stay fixed wherever the flaw appears
    • D.Impact metrics, which weigh the damage a breach produces
    Show answerHide answer

    Correct answer: Environmental metrics, which retune a score for one site

    Environmental metrics let an organisation restate a published score for its own deployment, raising it where the asset carries highly sensitive data through the security requirement metrics and lowering it where controls such as strict segmentation reduce exposure through the modified base metrics. Temporal metrics track how the wider threat and fix picture evolve, not local asset value. Base metrics are constant by design and cannot express local context. The impact metrics sit inside the base group and describe generic damage, not this organisation's own stakes.

  42. A vulnerability management program follows a repeatable lifecycle. Which sequence best represents the vulnerability management lifecycle?

    • A.Contain the threat, wipe it out, restore work, then debrief
    • B.Probe the target, load a payload, transmit it, then exploit
    • C.Gather the needs, design a plan, ship it, then decommission
    • D.Discover the assets, rank each flaw, fix them, then confirm
    Show answerHide answer

    Correct answer: Discover the assets, rank each flaw, fix them, then confirm

    Vulnerability management is a continuous loop: enumerate and scan the estate, analyse and prioritise what the scan returns, remediate or mitigate according to that priority, then verify the fix held and report the result before the cycle repeats. Containment, eradication, recovery and a debrief describe the incident response life cycle, which begins only once something has already gone wrong. Reconnaissance through exploitation describes an attacker's kill chain. Requirements through decommissioning describes a system development life cycle, not the handling of findings.

  43. What is the primary purpose of a vulnerability scan?

    • A.To list the known weaknesses on each machine so they get ranked
    • B.To exploit the weaknesses found on each host so impact is shown
    • C.To map the live hosts found on each subnet so assets are listed
    • D.To watch the traffic crossing each segment so attacks are seen
    Show answerHide answer

    Correct answer: To list the known weaknesses on each machine so they get ranked

    A vulnerability scan exists to list the known weaknesses on each machine so they get ranked and remediated in priority order. Exploiting weaknesses to show real impact is penetration testing, which goes beyond a scan. Mapping live hosts on each subnet is discovery, the step that builds the asset list a scan later works from. Watching traffic so attacks are seen is intrusion detection, which finds attacks in progress rather than latent weaknesses.

  44. A credentialed (authenticated) vulnerability scan differs from a non-credentialed scan primarily in that it:

    • A.It launches far more probes per second to map the open ports
    • B.It reads a mirror of the traffic rather than touch the hosts
    • C.It signs in with a valid credential to check the patch state
    • D.It drops a tiny local scan agent onto the target host itself
    Show answerHide answer

    Correct answer: It signs in with a valid credential to check the patch state

    A credentialed scan authenticates to the target and inspects installed software, patch state and configuration from the inside, which is why it returns far more accurate results and far fewer unconfirmed findings than an unauthenticated view of the same host. Sending more probes faster describes scan intensity, which is independent of whether credentials are supplied. Reading mirrored traffic instead of touching hosts describes passive scanning. Installing a local agent describes agent-based scanning, a different collection model that needs no interactive logon at scan time.

  45. An analyst runs a non-credentialed scan against a web server and the report flags many findings as potential but unconfirmed. Why does a non-credentialed scan tend to produce this kind of result?

    • A.It polls the vendor feed on a lengthy delay, so its data lags weekly
    • B.It runs a local agent on a timetable, so it skips the periodic check
    • C.It probes at a slow rate by design, so it overlooks the silent hosts
    • D.It must infer the flaw from a banner, so it guesses the patch status
    Show answerHide answer

    Correct answer: It must infer the flaw from a banner, so it guesses the patch status

    Without credentials a scanner sees only what a service exposes externally, so it reasons from banners, response behaviour and version strings and cannot read the actual patch state, which is why so many findings come back as potential rather than confirmed and why false positives rise. A non-credentialed scan does not depend on a vendor feed refresh cycle. It runs no local agent, so agent scheduling cannot explain the result. Scan rate affects coverage and timing, not whether a finding can be confirmed.

  46. A team needs continuous visibility into endpoints that frequently disconnect from the corporate network. Which scanning approach is best suited, and why?

    • A.Agentless remote scanning, which contacts hosts during that scan window
    • B.Agent-based scanning, which reports back once a roaming host reconnects
    • C.Passive network scanning, which reads whatever the mirrored flows carry
    • D.Cloud connector scanning, which harvests inventory through a broker API
    Show answerHide answer

    Correct answer: Agent-based scanning, which reports back once a roaming host reconnects

    A locally installed agent keeps collecting vulnerability and configuration data while the endpoint is away from the corporate network and uploads its results the next time the device connects, which is the only model giving continuous coverage of roaming laptops. Agentless remote scanning can assess a host only if it happens to be reachable during the scan window. Passive collection from mirrored traffic sees a device only while it is generating traffic on the monitored segment. A cloud connector reads a provider's inventory and never reaches a roaming corporate endpoint.

  47. A SOC wants to discover vulnerable systems without sending any probe packets that might disrupt fragile operational technology devices. Which technique meets this requirement?

    • A.Passive scanning that fingerprints systems from a mirrored data tap
    • B.Credentialed scanning with the safe checks enabled for each OT host
    • C.Discovery scanning that sends one throttled ICMP sweep per subnet
    • D.Non-credentialed scanning of the systems with safe checks turned on
    Show answerHide answer

    Correct answer: Passive scanning that fingerprints systems from a mirrored data tap

    Passive scanning that fingerprints systems from a mirrored data tap reads a copy of traffic off a SPAN port or tap, so it transmits nothing toward fragile operational technology devices. A credentialed scan with safe checks enabled still logs in to and queries every host. A throttled ICMP discovery sweep is gentler but still sends probe packets. A non-credentialed scan with safe checks only skips the dangerous plugins; it still connects to every port it tests.

  48. What distinguishes active vulnerability scanning from passive vulnerability scanning?

    • A.Active scanning logs in with credentials; passive scanning uses no logins
    • B.Active scanning installs a resident agent; passive scanning uses no agent
    • C.Active scanning pushes probes at a target; passive scanning just observes
    • D.Active scanning exploits found flaws; passive scanning merely lists them
    Show answerHide answer

    Correct answer: Active scanning pushes probes at a target; passive scanning just observes

    The dividing line is generated traffic: active scanning pushes probes at a target; passive scanning just observes existing traffic and infers from it. Logging in with credentials is the credentialed versus non-credentialed distinction, which applies within active scanning. Installing a host agent is the agent-based versus agentless distinction, which is separate again. Exploiting found flaws is penetration testing, which neither kind of scan does.

  49. In vulnerability scanning, what is a false positive?

    • A.A gap the scan missed while enumerating the same exposed web server
    • B.A signal the tool confirmed by exploiting the fault it had reported
    • C.A result the owner closed by duly accepting the leftover known risk
    • D.A finding the scanner published for a flaw missing from the machine
    Show answerHide answer

    Correct answer: A finding the scanner published for a flaw missing from the machine

    A false positive is a reported vulnerability that is not actually present, for example a version banner that looks vulnerable when the vendor has back-ported the fix without changing it, and validating findings is what keeps analysts from spending remediation effort on nothing. A weakness the scan failed to report although it was present is a false negative, the more dangerous opposite. A finding proven real by exploitation is a true positive. A finding closed because the organisation has formally accepted the risk is a risk acceptance decision, not a scanner error.

  50. An analyst is comparing two scan errors. Which statement correctly contrasts a false positive with a false negative?

    • A.A false positive ignores a verified defect, while a false negative invents a fictional defect
    • B.A false positive reports a phantom weakness, while a false negative misses a genuine weakness
    • C.A false positive overstates a real finding, while a false negative understates a real finding
    • D.A false positive follows a credentialed scan, while a false negative follows a discovery scan
    Show answerHide answer

    Correct answer: A false positive reports a phantom weakness, while a false negative misses a genuine weakness

    A false positive is a finding the scanner reports when the weakness is not actually present, and a false negative is a real weakness the scanner fails to report at all. False positives cost analyst hours on non-issues; false negatives are the more dangerous error because a live exposure stays unremediated. Reversing the two definitions describes the opposite pair of errors. Overstating or understating a proven finding is a severity-scoring problem, not a detection error, since the flaw was correctly found either way. And both error types occur in credentialed and unauthenticated discovery scans alike, so scan mode does not define which error is which.

  51. A scanner reports a critical vulnerability on a server, but the analyst confirms the patch was actually applied via a vendor backport that did not change the version banner. How should this finding be classified and handled?

    • A.As a true positive needing this instant patch reapplication
    • B.As a false negative needing a repeated credentialed recheck
    • C.As a true negative needing no further analyst investigation
    • D.As a false positive needing a validated scanner suppression
    Show answerHide answer

    Correct answer: As a false positive needing a validated scanner suppression

    The fix is already on the box: the vendor backported it without advancing the version banner, so the scanner inferred a flaw from the banner alone and reported something that does not exist. That is a false positive, and the correct handling is to validate the result against the package changelog, document the rationale, and tune or suppress the signature so the noise does not return next cycle. Calling it a true positive would send engineers to reinstall a patch that is already applied. A false negative is the opposite error, a real flaw the scan missed, which would call for a deeper scan rather than suppression. A true negative would mean the scanner correctly reported nothing, but here it reported a critical.

  52. Three vulnerabilities all have a CVSS base score of 9.0. One appears in the CISA Known Exploited Vulnerabilities (KEV) catalog and has a high EPSS probability. Under risk-based prioritization, how should the analyst rank it?

    • A.Remediate it urgently, since the active exploitation lifts the real risk
    • B.Remediate it urgently, since the EPSS value adds to the CVSS base score
    • C.Hold it at peer rank, since the temporal score already reflects exploits
    • D.Hold it at peer rank, since asset criticality resolves equal risk scores
    Show answerHide answer

    Correct answer: Remediate it urgently, since the active exploitation lifts the real risk

    The analyst should remediate it urgently, since the active exploitation lifts the real risk: a KEV listing confirms attackers are using the flaw now and a high EPSS probability predicts more, so it outranks two peers with identical inherent severity. Urgency is right, but the EPSS value does not add to the CVSS base score; the two are separate inputs, and the base score stays 9.0. Holding it at peer rank because the temporal score reflects exploits ignores that only base scores were given and that KEV evidence is stronger than any exploit-maturity estimate. Asset criticality is one input, but it does not resolve equal risk scores on its own or override confirmed exploitation.

  53. What is the primary goal of patch management within a vulnerability management program?

    • A.To apply hardened baselines so insecure defaults become locked down
    • B.To add compensating controls so the unpatched flaws become shielded
    • C.To deploy verified vendor updates so known defects become corrected
    • D.To rescan remediated hosts so that closed findings become confirmed
    Show answerHide answer

    Correct answer: To deploy verified vendor updates so known defects become corrected

    Patch management exists to deploy verified vendor updates so known defects become corrected, removing the flaw itself after the update has been tested. Applying hardened baselines so insecure defaults become locked down is configuration management, which tightens settings but does not fix vendor code. Adding compensating controls shields an unpatched flaw while it still exists, a stopgap rather than the goal. Rescanning remediated hosts confirms closed findings, which is validation that follows patching.

  54. A critical vulnerability is found on a legacy system that cannot be patched without breaking a required business application. Which response is the best example of a compensating control?

    • A.Documenting the exception in the governance records with owner signoff
    • B.Applying the patches in the scheduled maintenance window with downtime
    • C.Logging the finding in the central register with remediation deadlines
    • D.Isolating the legacy machine in the restricted segment with monitoring
    Show answerHide answer

    Correct answer: Isolating the legacy machine in the restricted segment with monitoring

    A compensating control is an alternative safeguard that lowers exposure when the primary fix cannot be applied, and isolating the legacy machine inside a restricted segment under closer monitoring is exactly that: the flaw remains, but reachability collapses. Segmentation, virtual patching at a web application firewall or intrusion prevention sensor, and tightened access rights are the usual forms. Documenting the exception in a governance record with owner signoff is risk acceptance, a decision that changes no technical exposure. Applying the vendor patch is the primary remediation, and the stem rules it out because it breaks the required business application. Logging the finding in a register with a remediation deadline is tracking, which schedules work rather than reducing risk in the meantime.

  55. A web application accepts a username field and passes it directly into a database query. An attacker enters input that closes the intended query and appends their own statement, returning all rows from the users table. What attack is this, and what is the best prevention?

    • A.SQL injection, stopped by binding parameterized database statements
    • B.LDAP injection, stopped by escaping distinguished directory entries
    • C.Command injection, stopped by strictly allowlisting shell arguments
    • D.Cross-site scripting, stopped by contextual browser output encoding
    Show answerHide answer

    Correct answer: SQL injection, stopped by binding parameterized database statements

    Untrusted input is concatenated straight into a database query, letting the attacker terminate the intended statement and append one of their own that returns every row of the users table. That is SQL injection, and the strongest defense is prepared parameterized statements, which bind input as data so it can never be parsed as query syntax, backed by input validation and a least-privilege database account. LDAP injection abuses directory filter syntax and is escaped at the distinguished name, not the database. Command injection abuses an operating system shell and is contained by allowlisting arguments. Cross-site scripting is defeated by encoding output in the browser, which does nothing to the query the database parses.

  56. An analyst reviews web server logs and sees repeated requests containing strings like ' OR '1'='1, UNION SELECT, and a comment marker after the input. What does this pattern most likely indicate?

    • A.Directory traversal probing aimed at fetching files outside webroot
    • B.Credential stuffing probing aimed at reusing breached SSO passwords
    • C.SQL injection probing aimed at controlling backend database queries
    • D.Cross-site scripting probing aimed at sending scripts into browsers
    Show answerHide answer

    Correct answer: SQL injection probing aimed at controlling backend database queries

    A tautology that always evaluates true, a UNION clause bolted onto an existing SELECT, and a trailing comment marker that truncates the rest of the original statement are the three canonical fingerprints of someone testing whether a parameter reaches the database unfiltered. Log review for these patterns pairs with web application firewall signatures and source review to confirm the exposure. Directory traversal leaves dot-dot-slash sequences and absolute paths, not query syntax. Credential stuffing shows as high-volume authentication attempts from many accounts, not as clauses inside a parameter. Cross-site scripting payloads carry script tags and event handlers meant for the browser, not query operators meant for the parser.

  57. What is cross-site scripting (XSS)?

    • A.An attack that captures traffic flowing past nearby network relays
    • B.An attack that injects active script inside innocent user browsers
    • C.An attack that inserts crafted clauses inside one database request
    • D.An attack that floods punishing volume inside one service frontend
    Show answerHide answer

    Correct answer: An attack that injects active script inside innocent user browsers

    Cross-site scripting places attacker-controlled script into a page so that it executes in the browser of whoever loads that page, which is what makes session token theft, defacement, and forced redirection possible. Its target is the client, which is why output encoding for the correct context plus a content security policy are the primary defenses. Capturing traffic as it flows past network relays describes an on-path interception attack. Inserting crafted clauses inside a database request describes injection against the backend database engine. Flooding a service frontend with punishing volume until its resources exhaust describes a denial of service, which affects availability and injects nothing into any page.

  58. An analyst is categorizing XSS findings. Which set correctly names the main types of cross-site scripting?

    • A.Persistent, reflected, and DOM-based variants
    • B.Agent-based, NIDS-based, and cloud collectors
    • C.Stack-based, heap-based, and NULL dereference
    • D.Uncredentialed, SNMP-based, and passive scans
    Show answerHide answer

    Correct answer: Persistent, reflected, and DOM-based variants

    Cross-site scripting is categorized as persistent, where the payload is stored on the server and served to every later viewer; reflected, where the payload is echoed back from one crafted request; and DOM-based, where client-side script writes attacker input into the page without safe handling. Agent-based, NIDS-based, and cloud collectors are monitoring deployment models, describing where a sensor sits rather than how a script is delivered. Stack-based, heap-based, and NULL dereference faults are memory-corruption classes affecting compiled code, not browser script. Uncredentialed, SNMP-based, and passive collection are vulnerability scanning modes, which describe how findings are gathered.

  59. During analysis, an attacker who gained access as a standard user exploits a misconfigured service to gain SYSTEM-level rights. What is this technique called?

    • A.Persistence, holding host rights across restarts
    • B.Execution, running the attacker's code on a host
    • C.Privilege escalation, raising the account rights
    • D.Initial access, gaining the first host foothold
    Show answerHide answer

    Correct answer: Privilege escalation, raising the account rights

    Moving from a standard user context to SYSTEM by abusing a misconfigured service is privilege escalation, raising the account rights beyond what was originally granted; this is vertical escalation. Persistence, holding host rights across restarts, is about surviving restarts, for example by installing a service, and does not by itself raise the attacker's level. Execution, running the attacker's code on a host, covers launching code at whatever privilege is already held. Initial access, gaining the first host foothold, describes the attacker's first foothold, which in this scenario already existed as the standard user account.

  60. A researcher discovers a flaw in a vendor's product and privately notifies the vendor, agreeing to withhold public details until a patch is released. What practice is this?

    • A.Full disclosure, posting the finding after brief notice
    • B.Coordinated disclosure, granting the vendor repair time
    • C.Private disclosure, keeping the finding sealed for good
    • D.Bug bounty submission, selling the finding to a vendor
    Show answerHide answer

    Correct answer: Coordinated disclosure, granting the vendor repair time

    Notifying the vendor privately and agreeing to hold back public details until a patch ships is coordinated disclosure, granting the vendor repair time on an agreed timeline. Full disclosure, even when it follows a brief notice, publishes the finding before any fix exists. Private disclosure, keeping the finding sealed for good, means it is never published even after the fix, which contradicts a release once patched. A bug bounty submission, selling the finding to a vendor, is a paid reporting channel rather than the timed-release agreement itself.

Incident Response and Management (35)

  1. In cybersecurity, what does the term 'chain of custody' refer to?

    • A.The cryptographic digest confirming an image matches its source
    • B.The volatility order guiding which artifact gets captured first
    • C.The written record tracking each transfer of collected evidence
    • D.The legal authorization permitting a lawful search of equipment
    Show answerHide answer

    Correct answer: The written record tracking each transfer of collected evidence

    Correct answer: The written record tracking each transfer of collected evidence. Chain of custody is the continuous documentation showing who seized an item, who held it, when every handover occurred and how it was stored, from collection through to presentation; a gap in that record lets opposing counsel argue the evidence could have been altered. The cryptographic digest confirming an image matches its source is integrity verification, which shows data is unchanged but says nothing about who possessed it. The volatility order guiding which artifact gets captured first is the order of volatility, a collection sequencing rule. The legal authorization permitting a lawful search of equipment is the warrant or consent that makes collection lawful.

  2. What is the primary purpose of "chain of custody" documentation in the context of vulnerability management?

    • A.To measure how quickly responders answered each alert
    • B.To inventory the machines touched during an intrusion
    • C.To record approvals for changes to security standards
    • D.To keep seized evidence admissible in future hearings
    Show answerHide answer

    Correct answer: To keep seized evidence admissible in future hearings

    Correct answer: To keep seized evidence admissible in future hearings. Explanation: Chain of custody records who collected each item, who held it, when it moved and what was done to it, so a court can be satisfied that the material presented is the material collected and that nothing altered it along the way. To measure how quickly responders answered each alert is a response metric and speaks to team performance. To inventory the machines touched during an intrusion is scoping work that establishes the extent of the event. To record approvals for changes to security standards is governance documentation and carries no evidentiary weight.

  3. During a cyber incident response, which type of analysis focuses on identifying the tactics, techniques, and procedures (TTPs) of attackers?

    • A.Malware static code analysis
    • B.Malware memory dump analysis
    • C.Root cause incident analysis
    • D.Threat intelligence analysis
    Show answerHide answer

    Correct answer: Threat intelligence analysis

    Threat intelligence analysis studies adversary behaviour across campaigns and expresses it as tactics, techniques and procedures that defenders can map to frameworks such as MITRE ATT&CK and hunt for. Malware static code analysis characterises one sample's code and capabilities, not the actor's wider tradecraft. Malware memory dump analysis recovers what was running in RAM on one host, which is evidence rather than a behavioural profile of the attacker. Root cause incident analysis explains which weakness allowed this incident to happen, not how the adversary operates.

  4. In the context of incident response, what is the primary purpose of a 'kill chain' model?

    • A.To assign responder roles across the duty rotation
    • B.To rank fresh findings by their exploit likelihood
    • C.To characterize the ordered stages of an intrusion
    • D.To record lessons captured once an incident closes
    Show answerHide answer

    Correct answer: To characterize the ordered stages of an intrusion

    Correct answer: To characterize the ordered stages of an intrusion. Explanation: A kill chain breaks an attack into sequential phases, running from reconnaissance through delivery and exploitation to actions on objectives, so defenders can place detection and disruption at each step and reason about how far an intrusion progressed before it was caught. To assign responder roles across the duty rotation is staffing for the response function. To rank fresh findings by their exploit likelihood is vulnerability prioritization, which orders defects rather than describing attacker progression. To record lessons captured once an incident closes belongs to the post-incident review that follows containment and recovery.

  5. Which of the following is a key activity in the Preparation phase of the Incident Response Lifecycle?

    • A.Drafting notification plans for likely incident types
    • B.Isolating infected devices from the corporate network
    • C.Reconstructing the contributing causes of an incident
    • D.Estimating how many customer records were exfiltrated
    Show answerHide answer

    Correct answer: Drafting notification plans for likely incident types

    Correct answer: Drafting notification plans for likely incident types. Explanation: Preparation is the work done while nothing is on fire, covering the team, tooling, playbooks and the settled question of who must be told, through which channel and how fast, so nobody has to invent a notification path during a live event. Isolating infected devices from the corporate network is containment, which happens once an incident is confirmed. Reconstructing the contributing causes of an incident is analysis and post-incident activity performed after the fact. Estimating how many customer records were exfiltrated is impact assessment carried out during and after the response, never before it.

  6. What is the main objective of triage in cybersecurity incident response?

    • A.Returning the failed services to earlier working status
    • B.Logging the custody handoff for each seized workstation
    • C.Ranking the incoming reports by assessed severity level
    • D.Deleting the hostile binaries left on infected desktops
    Show answerHide answer

    Correct answer: Ranking the incoming reports by assessed severity level

    Triage sits at the front of the response: reports arrive faster than a team can work them, so each is assessed and ranked by severity and urgency, and the most damaging get an analyst first. Returning failed services to a working state is recovery, which happens only after the threat is gone. Logging a custody handoff is evidence handling that supports a later investigation. Deleting hostile binaries is eradication, and both of those presume the incident has already been classified and prioritised.

  7. In incident response, what is the significance of the term 'Indicators of Compromise' (IoCs)?

    • A.Observed traces suggesting a server was silently breached
    • B.Live behaviours signalling an intrusion attempt under way
    • C.Recorded patterns describing how one actor group operates
    • D.Recorded weaknesses describing how a server can be hit
    Show answerHide answer

    Correct answer: Observed traces suggesting a server was silently breached

    Indicators of compromise are observed traces suggesting a server was silently breached, such as altered files or beaconing, and they drive detection and scoping after the fact. Live behaviours signalling an attack in progress are indicators of attack, which look at intent rather than completed compromise. Recorded patterns of how an actor group operates are TTPs. Recorded weaknesses are vulnerabilities, which show exposure, not that a breach happened.

  8. Which tool is most commonly used in the containment phase of a cybersecurity incident response to isolate affected systems?

    • A.A monitor alerting on suspicious packets it observes
    • B.A gateway checking outbound files for tagged content
    • C.A scanner removing known malware from infected disks
    • D.A firewall discarding traffic bound for the endpoint
    Show answerHide answer

    Correct answer: A firewall discarding traffic bound for the endpoint

    Containment means isolating the affected host, and the firewall or equivalent network access control is the usual instrument: rules are changed so traffic to and from the compromised endpoint is discarded, cutting the attacker's reach while the machine stays powered on for analysis. An intrusion detection sensor observes and alerts but blocks nothing on its own. A data loss prevention gateway inspects outbound content against policy rather than quarantining a host. Antimalware cleans infected media, which is eradication, not isolation.

  9. What is the primary goal of 'chain of custody' in the context of cyber incident response?

    • A.Building the event timeline reconstructed from server logs
    • B.Showing the seized evidence stayed intact between handlers
    • C.Assigning the response duties handled by each investigator
    • D.Publishing the breach notices required by state regulators
    Show answerHide answer

    Correct answer: Showing the seized evidence stayed intact between handlers

    Chain of custody is the unbroken record of who held each item, when, and why, and its purpose is to show that evidence was not altered as it moved between handlers. Without it, otherwise sound findings can be excluded from a proceeding. An incident timeline reconstructed from logs describes what the attacker did, not who held the evidence. Assigning response duties is a staffing matter fixed by the response plan. Publishing a breach notice discharges a regulatory obligation and has no bearing on evidentiary integrity.

  10. In cyber incident response, what is the primary purpose of performing a root cause analysis?

    • A.Mapping the full list of systems touched by the compromise
    • B.Finding the technical fault behind the observed compromise
    • C.Measuring the financial impact that the compromise caused
    • D.Identifying the threat actor who carried out the intrusion
    Show answerHide answer

    Correct answer: Finding the technical fault behind the observed compromise

    Root cause analysis means finding the technical fault behind the observed compromise: the unpatched service, misconfiguration or missing control that made the attack possible, so it can be fixed and not recur. Mapping every system touched by the compromise is scoping, which sizes the incident. Measuring the financial impact is business impact analysis. Identifying the threat actor is attribution, which names who attacked rather than explaining why the attack succeeded.

  11. Which phase of the Incident Response Lifecycle involves analyzing the incident to improve future response and prevention measures?

    • A.Preparing the checklists consulted by the analyst rosters
    • B.Analyzing the telemetry gathered from the alerting probes
    • C.Isolating the intruders inside a single network partition
    • D.Reviewing the response once the affected services resumed
    Show answerHide answer

    Correct answer: Reviewing the response once the affected services resumed

    The post-incident activity phase runs once operations are back: the team reviews the response, captures lessons learned, and feeds concrete changes into detection content, tooling and the plan itself. Preparing playbooks and rosters is preparation, done before any alert exists. Working through telemetry from alerting probes is detection and analysis, which establishes that an incident is real. Isolating an intruder in a network partition is containment, taken while the incident is still live.

  12. In the context of cyber incident response, what is the purpose of using sandboxes?

    • A.Detonating unknown files inside a walled test environment
    • B.Holding suspect malware in quarantine without running it
    • C.Luring live intruders toward a decoy host for close study
    • D.Diverting malware callbacks into an internal DNS sinkhole
    Show answerHide answer

    Correct answer: Detonating unknown files inside a walled test environment

    A sandbox is used for detonating unknown files inside a walled test environment, an instrumented and isolated system where analysts watch what the sample drops, contacts and persists without risking production hosts. Holding suspect malware in quarantine isolates it but never executes it, so no behaviour is observed. Luring live intruders toward a decoy host describes a honeypot, which studies attackers rather than samples. Diverting malware callbacks into a DNS sinkhole disrupts command-and-control traffic for already infected hosts instead of analysing an unknown file.

  13. What role does 'attribution' play in cyber incident response?

    • A.Estimating the business disruption produced by the shutdown
    • B.Rebuilding the compromised hosts from trusted vendor images
    • C.Identifying the outside group responsible for the intrusion
    • D.Deploying the extra controls chosen during remediation work
    Show answerHide answer

    Correct answer: Identifying the outside group responsible for the intrusion

    Attribution ties the observed tradecraft, infrastructure and tooling to the actor behind the intrusion, which shapes what the team should expect next and any law-enforcement or disclosure path. Estimating business disruption is impact assessment. Rebuilding compromised hosts from trusted media is recovery. Deploying extra controls during remediation hardens the environment against a repeat. All three follow from the incident, but none of them establishes who conducted it.

  14. During an incident response, what is the significance of 'time stamps' in log files?

    • A.They establish the sequencing of the separate logged events
    • B.They prove each record was not altered after it was written
    • C.They show the time zone the attacker worked from per record
    • D.They set the retention period applied to each stored log
    Show answerHide answer

    Correct answer: They establish the sequencing of the separate logged events

    Timestamps matter because they establish the sequencing of the separate logged events, letting an analyst merge records from many systems into one timeline and see what happened first. They do not prove each record was not altered after it was written; integrity comes from hashing, signing or write-once storage. They do not show the time zone the attacker worked from, only the clock of the logging system. They do not set the retention period applied to each stored log, which is a policy setting on the log platform.

  15. What is the purpose of 'data exfiltration analysis' in cyber incident response?

    • A.Measuring the analyst tickets completed within each shift
    • B.Establishing the records copied out during the compromise
    • C.Verifying the nightly jobs finished without logged errors
    • D.Confirming the restored files match the original checksum
    Show answerHide answer

    Correct answer: Establishing the records copied out during the compromise

    Exfiltration analysis works out exactly what data left the environment, which stores were touched and where it went, because that answer drives notification duties, regulatory exposure and the scope statement given to customers. Measuring analyst caseload per shift is an operations metric. Verifying that nightly jobs finished is backup monitoring. Confirming that restored files match their original checksum validates a recovery. None of those establishes what the attacker took.

  16. In incident response, what is the main goal of 'eradication'?

    • A.Recovering the disrupted services to their prior operation
    • B.Explaining the underlying weakness exploited by the actors
    • C.Archiving the closing write-up retained for later auditors
    • D.Stripping the attacker tooling from the compromised assets
    Show answerHide answer

    Correct answer: Stripping the attacker tooling from the compromised assets

    Eradication removes the attacker's footholds from the affected assets: malware, web shells, scheduled tasks, added accounts and modified binaries all have to go, or the environment is reinfected as soon as it is returned to service. Recovering disrupted services to their prior operation is the recovery step that follows. Explaining the underlying weakness is root cause analysis. Archiving a closing write-up is post-incident documentation. Each is a genuine stage, but none of them strips out the hostile components.

  17. Which activity in cyber incident response involves determining the scope and impact of the incident?

    • A.Preparation of the checklists rehearsed by the responders
    • B.Containment of the damage limited by network segmentation
    • C.Restoration of the databases recovered from clean backups
    • D.Identification of the machines disturbed by the intruders
    Show answerHide answer

    Correct answer: Identification of the machines disturbed by the intruders

    Identification is where the team confirms the incident is real and sizes it: which machines were disturbed, which accounts were abused, and what data was reachable. That scope statement is what every later decision depends on. Preparation covers the checklists and rosters put in place beforehand. Containment limits damage once the scope is known. Restoration brings services back at the end. None of those establishes how far the intrusion actually reached.

  18. In cyber incident response, what is the purpose of using 'SIEM' (Security Information and Event Management) tools?

    • A.Running scripted playbook steps automatically on every alert
    • B.Collecting alerts from multiple sources for central analysis
    • C.Recording endpoint telemetry and isolating any suspect hosts
    • D.Forwarding raw syslog events from all hosts to one collector
    Show answerHide answer

    Correct answer: Collecting alerts from multiple sources for central analysis

    Collecting alerts from multiple sources for central analysis is the SIEM's purpose: it ingests and normalises events from firewalls, endpoints, servers and applications, then correlates them so an analyst sees one picture. Running scripted playbook steps automatically on every alert is SOAR, which acts on alerts rather than gathering them. Recording endpoint telemetry and isolating suspect hosts is EDR, scoped to the endpoint. Forwarding raw syslog events to one collector is a log forwarder, which moves data but performs no correlation or analysis.

  19. In the context of cyber incident response, what is the role of 'digital forensics'?

    • A.Examining the captured images to reconstruct the compromise
    • B.Searching the networks proactively for undetected attackers
    • C.Isolating the affected hosts so the compromise can't spread
    • D.Estimating the business impact of the compromise on revenue
    Show answerHide answer

    Correct answer: Examining the captured images to reconstruct the compromise

    Digital forensics means examining the captured images to reconstruct the compromise: analysing disk and memory images, packet captures and logs to establish what the attacker did, in what order and with what access. Searching networks proactively for undetected attackers is threat hunting, which looks for activity not yet found. Isolating affected hosts is containment, which stops spread but analyses nothing. Estimating the business impact on revenue is impact analysis, a business judgement rather than evidence examination.

  20. Which phase in the incident response process involves taking actions to minimize the impact of the incident?

    • A.Removing the malware and its persistence from each server
    • B.Restoring the affected hosts from known-good backup copies
    • C.Disconnecting the intruder from the remaining clean estate
    • D.Rebuilding the affected hosts from a known-good OS image
    Show answerHide answer

    Correct answer: Disconnecting the intruder from the remaining clean estate

    Containment, disconnecting the intruder from the remaining clean estate, is the phase that limits impact by stopping the spread while the investigation continues. Removing the malware and its persistence is eradication, which follows containment and eliminates the threat rather than limiting its reach. Restoring hosts from known-good backups and rebuilding them from a known-good OS image are recovery actions that return systems to service after the threat is gone.

  21. In incident response, what is the primary purpose of 'war gaming' exercises?

    • A.Stressing the response plan against a simulated adversary
    • B.Walking through the response plan in a discussion meeting
    • C.Proving the failover site can carry the live workload
    • D.Validating the failover plan through a live cutover drill
    Show answerHide answer

    Correct answer: Stressing the response plan against a simulated adversary

    War gaming is about stressing the response plan against a simulated adversary: an opposing team acts out an attack and adapts while responders work it, exposing gaps that a scripted test never reaches. Walking through the response plan in a discussion meeting is a tabletop exercise, which talks through decisions with no opponent. Proving the failover site can carry the live workload is a parallel or capacity test of disaster recovery. Validating the failover plan through a live cutover drill is a full-interruption recovery test, which exercises infrastructure rather than responders against an attacker.

  22. What is the primary goal of 'containment strategies' in the incident response process?

    • A.Removing the attacker's foothold from each affected host
    • B.Trapping the intrusion inside an already affected segment
    • C.Restoring the affected systems to normal business service
    • D.Scoping the breach to find each affected host and account
    Show answerHide answer

    Correct answer: Trapping the intrusion inside an already affected segment

    The goal of containment is trapping the intrusion inside an already affected segment so it cannot spread to clean systems while the response continues. Removing the attacker's foothold from each host is eradication, which follows containment. Restoring systems to normal business service is recovery. Scoping the breach to find each affected host and account is detection and analysis work that informs containment but does not itself stop the spread.

  23. In the aftermath of a cybersecurity incident, what is the main focus of 'recovery strategies'?

    • A.Reinstating the operations to their expected service level
    • B.Removing the malware and attacker accounts from every host
    • C.Isolating the affected hosts to stop the incident's spread
    • D.Documenting the root cause and the improvements required
    Show answerHide answer

    Correct answer: Reinstating the operations to their expected service level

    Recovery strategies focus on reinstating the operations to their expected service level: restoring systems from known-good sources, validating them and returning them to production under heightened monitoring. Removing the malware and attacker accounts from every host is eradication, which must finish before recovery begins. Isolating the affected hosts to stop the incident's spread is containment, an earlier phase. Documenting the root cause and the improvements required is the lessons-learned activity that follows recovery.

  24. In cybersecurity, what is an 'incident playbook' primarily used for?

    • A.Defining the incident team's authority, roles and scope
    • B.Listing who must be notified when a breach is confirmed
    • C.Restoring critical business services after a breach
    • D.Detailing the response steps for each incident category
    Show answerHide answer

    Correct answer: Detailing the response steps for each incident category

    An incident playbook is used for detailing the response steps for each incident category, such as ransomware or phishing, so responders act consistently. Defining the team's authority, roles and scope is the incident response plan or policy, which governs the program rather than prescribing steps. Listing who must be notified when a breach is confirmed is the communication plan or escalation list. Restoring critical business services after a breach is the disaster recovery plan, focused on continuity rather than incident handling.

  25. What is the main purpose of conducting 'tabletop exercises' in incident response planning?

    • A.Reviewing the plan's call trees against the current staff
    • B.Executing the response live with real systems and staff
    • C.Rehearsing the documented plan with a discussion scenario
    • D.Pitting the defenders against a live and hostile red team
    Show answerHide answer

    Correct answer: Rehearsing the documented plan with a discussion scenario

    A tabletop exercise means rehearsing the documented plan with a discussion scenario: participants talk through decisions around a table, exposing unclear roles and gaps cheaply without touching production. Reviewing the plan's call trees against current staff is a checklist review, which checks contact details but does not walk a scenario. Executing the response live with real systems and staff is a full-scale or functional exercise, not a discussion. Pitting the defenders against a live, hostile red team is war gaming or a red team exercise, which tests capability under real adversarial pressure.

  26. Which factor is most critical when establishing the severity level of a cybersecurity incident?

    • A.The disruption striking the firm's core business operations
    • B.The number of infected hosts the intruder's malware reached
    • C.The CVSS base score of the weakness the intruders exploited
    • D.The skill level of the threat actor behind the attack
    Show answerHide answer

    Correct answer: The disruption striking the firm's core business operations

    Severity is driven by the disruption striking the firm's core business operations, together with the sensitivity of data affected and how recoverable the systems are; that impact sets escalation, notification and resourcing. The number of infected hosts the intruder's malware reached measures scope, and many low-value hosts can matter less than one critical one. The CVSS base score of the weakness the intruders exploited rates the vulnerability in the abstract, not this incident's harm. The skill level of the threat actor is attribution context, not a measure of consequence.

  27. In incident response, what is the importance of 'root cause analysis'?

    • A.Mapping each host the attacker reached after the first entry
    • B.Estimating the business losses the hostile activity incurred
    • C.Naming the attacker group that was responsible for the entry
    • D.Uncovering the flaws permitting the initial hostile foothold
    Show answerHide answer

    Correct answer: Uncovering the flaws permitting the initial hostile foothold

    Root cause analysis matters because it is uncovering the flaws permitting the initial hostile foothold, such as an unpatched edge device or missing multifactor, so the fix closes the class of problem rather than the symptom. Mapping each host the attacker reached after the first entry is scoping, which measures spread, not the cause of entry. Estimating the business losses the hostile activity incurred is impact analysis. Naming the attacker group that was responsible for the entry is attribution: it answers who, not which weakness let them in.

  28. What role does a Security Information and Event Management (SIEM) system play in the Incident Response process?

    • A.It runs the playbooks so routine response steps fire fast
    • B.It merges the log feeds so events line up chronologically
    • C.It records endpoint events so the host can be quarantined
    • D.It baselines user events by host so odd logins stand out
    Show answerHide answer

    Correct answer: It merges the log feeds so events line up chronologically

    A SIEM's role in incident response is simple: it merges the log feeds so events line up chronologically, correlating firewall, endpoint and server telemetry into one timeline responders can work from. Running playbooks so routine response steps fire automatically is SOAR. Recording endpoint events so the host can be quarantined is EDR. Baselining user events by host so odd logins stand out is UEBA, an analytics layer that feeds detections rather than building the timeline.

  29. What is the primary purpose of a root cause analysis (RCA) during post-incident activity?

    • A.To pin the root cause on one actor for criminal attribution
    • B.To understand the root cause so the incident cannot reoccur
    • C.To log the incident timeline so the case report is complete
    • D.To gauge the incident impact so the loss report is complete
    Show answerHide answer

    Correct answer: To understand the root cause so the incident cannot reoccur

    The purpose of root cause analysis is to understand the root cause so the incident cannot reoccur: it finds the weakness or process gap that let the attack succeed so the fix removes it. Attribution names who attacked, not why the attack worked. Building the timeline feeds the incident report but describes events rather than their cause. Gauging impact is business impact analysis, which measures losses and says nothing about how to prevent a repeat.

  30. When are 'lessons learned' meetings most appropriately conducted in the incident response life cycle?

    • A.During the recovery phase, once the hosts are cleared to run
    • B.During the eradication phase, once the implants are cleared
    • C.During the post-incident phase, after the recovery work ends
    • D.During the preparation phase, once an incident drill is held
    Show answerHide answer

    Correct answer: During the post-incident phase, after the recovery work ends

    Lessons-learned meetings belong during the post-incident phase, after the recovery work ends, when the facts are settled and the whole response can be reviewed. During recovery, even once hosts are cleared to run, they are still being validated and monitored, so the response is not finished. During eradication, implants are removed but recovery has not happened yet. Preparation, even after an incident drill is held, is where lessons learned are later applied, not where the review of a finished incident is held.

  31. An analyst is documenting an intrusion and wants to capture, for a single malicious event, the actor behind it, the tooling used, the systems that delivered the attack, and the targeted organization. Which analytical model is built around exactly these four core features?

    • A.The Lockheed Martin Cyber Kill Chain framework
    • B.The STRIDE model of software threat categories
    • C.The MITRE ATT&CK matrix of adversary behaviors
    • D.The Diamond Model of Intrusion Analysis method
    Show answerHide answer

    Correct answer: The Diamond Model of Intrusion Analysis method

    The Diamond Model defines a single intrusion event by exactly four core features, adversary, capability, infrastructure, and victim, joined by the edges between them, which is precisely the actor, tooling, delivering systems, and targeted organization the analyst wants to capture. The Cyber Kill Chain is a sequence of attack phases running from reconnaissance to actions on objectives, so it models progression through time rather than the four atomic features of one event. STRIDE is a design-time threat categorization aid built around spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege. The MITRE matrix catalogs adversary tactics and techniques rather than defining the feature set of an individual event.

  32. A SOC manager explains that the team maintains two kinds of documents: a high-level document describing the overall workflow and decision points for handling a phishing incident, and a separate set of precise step-by-step instructions for the specific commands an analyst runs to pull email headers and quarantine a mailbox. Which pairing correctly matches these descriptions?

    • A.The overall workflow is the runbook; the precise commands are the playbook
    • B.The team playbook automates each response; the runbook sets the broad goal
    • C.The strategic document is the playbook; the command steps form the runbook
    • D.The playbook is the runbook; the two names describe one identical document
    Show answerHide answer

    Correct answer: The strategic document is the playbook; the command steps form the runbook

    A playbook is the strategic layer: the overall workflow, decision points, and escalation paths for handling a whole category of incident such as phishing. A runbook is the operational layer beneath it: the precise, often automatable steps and commands that carry out one part of that response, such as pulling message headers or quarantining a mailbox. Swapping the two labels is the standard trap, because the granular command-level procedure is the runbook and never the strategic overview. Automation also belongs to the runbook layer rather than the playbook, so assigning automated response to the playbook and strategy to the runbook inverts both roles. And the two are not synonyms for one file: they are distinct documents at different levels of detail, which is exactly the distinction the manager drew.

  33. A first responder arrives at a compromised but still-powered server and must collect evidence in the correct order of volatility per RFC 3227. Which source should be captured first?

    • A.The active routing table and the stored address resolution entries
    • B.The processor register file and the onboard hardware cache entries
    • C.The document files and directories recorded onto the system volume
    • D.The offsite archival tapes and disks holding the overnight backups
    Show answerHide answer

    Correct answer: The processor register file and the onboard hardware cache entries

    The order of volatility directs a responder to collect the most perishable evidence first, and nothing is more perishable than the processor register file and the onboard hardware cache, whose contents change continuously and vanish the instant power is lost. Routing tables and address resolution entries sit at the next level down, alongside process tables, kernel statistics, and memory, so they are captured second rather than first. Files and directories written to the system volume survive a reboot and are collected later still. Offsite archive media is the least volatile source of all and sits at the end of the sequence, since it changes only when a new backup is written.

  34. After a ransomware outage, an executive asks an analyst to distinguish two planning efforts: one focused on keeping critical business functions operating during a disruption, and another focused specifically on restoring IT systems and data after they have failed. Which mapping is correct?

    • A.Disaster recovery keeps critical functions working; continuity rebuilds affected systems
    • B.Business continuity covers physical events; disaster recovery covers deliberate breaches
    • C.Business continuity schedules nightly backups; disaster recovery transfers these offsite
    • D.Business continuity sustains ongoing services; disaster recovery restores broken systems
    Show answerHide answer

    Correct answer: Business continuity sustains ongoing services; disaster recovery restores broken systems

    Business continuity is the broad discipline of keeping the organization's critical functions delivering throughout a disruption, using workarounds, alternate sites, and manual processes as needed. Disaster recovery is the narrower technology effort of bringing failed systems and data back after the failure, and it is normally treated as a subset that supports the continuity goal. Reversing the two assigns the during-the-event role to the recovery plan and the after-the-event role to continuity, which inverts both definitions. Neither discipline is tied to a cause: a ransomware outage and a hurricane both trigger the same planning. And nightly backup scheduling with offsite storage is one supporting control, not the definition of either plan.

  35. While mapping observed adversary behavior in MITRE ATT&CK, an analyst notes the attacker's goal was credential access, achieved specifically through brute forcing a login. In ATT&CK terminology, how do these two elements relate?

    • A.Credential access is the tactic; brute force is the chosen technique
    • B.Credential access is the technique; brute force is its sub-technique
    • C.Credential access is the objective; brute force is its procedure
    • D.Credential access is the technique; brute force is a named procedure
    Show answerHide answer

    Correct answer: Credential access is the tactic; brute force is the chosen technique

    In ATT&CK, credential access is the tactic; brute force is the chosen technique, so the tactic is the why and the technique is the how. Credential access is not a technique, so neither technique option fits, and brute force is a technique in its own right rather than a sub-technique such as password spraying. Calling brute force a procedure is also wrong: procedures are a specific group's implementation of a technique, one layer below it.

Reporting and Communication (30)

  1. What is a primary consideration when choosing a communication method during a cyber incident response?

    • A.Whether the channel retains each message for legal hold
    • B.Whether the channel reaches the entire stakeholder list
    • C.Whether the channel remains outside an intruder's reach
    • D.Whether the channel matches the tool staff use each day
    Show answerHide answer

    Correct answer: Whether the channel remains outside an intruder's reach

    The primary consideration is whether the channel remains outside an intruder's reach, because an attacker still inside the estate may be reading the mail and chat the responders would normally use, so out-of-band communication comes first. Whether the channel retains each message for legal hold matters for later evidence preservation but is secondary. Whether the channel reaches the entire stakeholder list cuts against need-to-know; incident communication is limited to the people who must act. Whether the channel matches the tool staff use each day is actually a warning sign, since the everyday tool is the one most likely to be compromised.

  2. Which type of report in cybersecurity incident response typically includes detailed technical information about the incident and its remediation?

    • A.An executive report framing the commercial impact concisely
    • B.A closing report capturing the improvement actions proposed
    • C.An advance report announcing the newly confirmed detections
    • D.An engineering report detailing the remediation steps taken
    Show answerHide answer

    Correct answer: An engineering report detailing the remediation steps taken

    The technical incident report is written for engineers and security staff. It carries the indicators, the affected systems, the attack path and the remediation actually applied, at a depth the rest of the audience does not need. An executive report deliberately compresses all of that to commercial consequence. A closing report records the improvement actions to be pursued. An early notification announces a confirmed detection before the technical picture exists. Only one of them carries the technical detail.

  3. During a cyber incident, what is the role of a 'crisis communication plan'?

    • A.Dividing what the responder handles inside a workstream
    • B.Governing what the organisation tells the outside world
    • C.Encrypting what the senior leaders discuss each evening
    • D.Tracking what the newspapers publish about the incident
    Show answerHide answer

    Correct answer: Governing what the organisation tells the outside world

    A crisis communication plan governs external messaging: who speaks, what has been confirmed, when customers, regulators and the press are told, and through which channel, so the organisation says one accurate thing rather than several conflicting ones. Dividing work inside the response team is set out in the response plan. Encrypting what leaders discuss is a secure-channel control. Tracking what newspapers publish is media monitoring, which watches the outside world rather than addressing it.

  4. In a CySA+ vulnerability management report, which element communicates the relative urgency of remediating a specific finding to stakeholders?

    • A.The severity score derived from the CVSS base metrics
    • B.The CVE entry assigned to the flaw by the issuing CNA
    • C.The plugin ID assigned to the detection by a scanner
    • D.The CPE name derived from vendor, product and version
    Show answerHide answer

    Correct answer: The severity score derived from the CVSS base metrics

    The severity score derived from the CVSS base metrics is the element that ranks one finding against another, so it is what tells stakeholders how urgently to remediate. A CVE entry from the issuing CNA only identifies the flaw. A scanner plugin ID only identifies the check that fired. A CPE name only identifies the affected product and version. None of the three carries any measure of urgency.

  5. An analyst is preparing a vulnerability report and notices the same critical finding reappears on a host after each monthly scan. Which reporting element best captures this?

    • A.Risk score
    • B.Exceptions
    • C.Prioritization
    • D.Recurrence
    Show answerHide answer

    Correct answer: Recurrence

    Recurrence is the reporting element for a finding that returns after it was closed, signalling that the fix did not hold because of a rebuild from an old image or a rolled-back patch. A risk score rates how severe a finding is, not whether it returns. Exceptions record findings formally accepted and left open, not ones that keep reappearing. Prioritization orders the remediation queue but says nothing about a finding coming back each month.

  6. A service-level agreement (SLA) requires critical vulnerabilities to be remediated within 15 days, but a legacy industrial system cannot be patched without halting production. What is this situation an example of?

    • A.An exception waiver signed off by the system owners
    • B.A compensating control built round the legacy system
    • C.A remediation inhibitor entered in the risk register
    • D.A change freeze ordered by the change advisory board
    Show answerHide answer

    Correct answer: A remediation inhibitor entered in the risk register

    A legacy industrial system that cannot be patched inside the SLA without halting production is a remediation inhibitor entered in the risk register, documented so the risk owner can decide how to respond. An exception waiver signed off by the system owners is risk acceptance, one possible response to the inhibitor rather than the situation itself. A compensating control built around the legacy system is likewise a later mitigation. A change freeze ordered by the change advisory board is an administrative block on changes, while here the obstacle is the production dependency.

  7. When a vulnerability cannot be immediately patched due to business constraints, which action plan element reduces risk in the interim?

    • A.Adding a compensating control around the exposed system
    • B.Documenting a formal exception signed by an asset owner
    • C.Scheduling the patch for the next planned outage window
    • D.Assigning the finding to the asset owner for follow-up
    Show answerHide answer

    Correct answer: Adding a compensating control around the exposed system

    The element that reduces risk in the interim is adding a compensating control around the exposed system, such as segmentation, access restriction, extra monitoring or a virtual patch, which lowers likelihood or impact while the defect remains. Documenting a formal exception signed by an asset owner records the decision to tolerate the exposure but leaves it unchanged. Scheduling the patch for the next planned outage window sets the end of the interim period and does nothing to protect the system before then. Assigning the finding to the asset owner for follow-up establishes accountability, not mitigation.

  8. Which of the following is a key performance indicator (KPI) commonly tracked in vulnerability management reporting?

    • A.The mean time between two unplanned data centre outages
    • B.The mean time required to remediate a reported weakness
    • C.The mean time a helpdesk ticket remains completely open
    • D.The mean time an analyst spends per unresolved incident
    Show answerHide answer

    Correct answer: The mean time required to remediate a reported weakness

    Mean time to remediate measures the interval between a vulnerability being discovered and the fix being verified, and tracking it over time shows whether the programme is getting faster and whether the agreed service levels are being met. Mean time between outages is a reliability measure for infrastructure availability. Ticket duration reports on service desk throughput. Analyst handling time measures workload in the operations centre. All are real metrics, but only remediation time reflects vulnerability management performance.

  9. A security manager asks for a report showing the most prevalent weaknesses across the environment so leadership can focus resources. Which metric best satisfies this request?

    • A.A list of the hosts holding the most open weaknesses
    • B.A count of the open weaknesses grouped by CVSS score
    • C.A trend of mean time to remediate open weaknesses
    • D.A ranked list of the weaknesses seen most frequently
    Show answerHide answer

    Correct answer: A ranked list of the weaknesses seen most frequently

    A ranked list of the weaknesses seen most frequently shows which single flaw recurs across the most systems, so one remediation effort removes the widest exposure, which is what leadership needs to focus resources. A list of the hosts holding the most open weaknesses points at individual machines, not at the weaknesses common across the environment. A count of the open weaknesses grouped by CVSS score shows severity distribution but not which weakness is most prevalent. A trend of mean time to remediate measures remediation performance, not where the weaknesses concentrate.

  10. What does a Service-Level Objective (SLO) define in the context of vulnerability management metrics?

    • A.The contractual penalty a supplier owes for repeated failures
    • B.The maximum data loss permitted during a prolonged disruption
    • C.The proportion of production systems a scanner reached lately
    • D.The measurable target used to gauge the programme performance
    Show answerHide answer

    Correct answer: The measurable target used to gauge the programme performance

    A service-level objective is the specific, measurable target a programme holds itself to, such as remediating critical findings inside an agreed number of days, and performance is reported against it to show whether commitments are being met. A penalty owed for repeated failures is a contractual remedy, not a target. A tolerance for data loss is a recovery point objective used in continuity planning. Scanner coverage is a useful metric, but it measures reach rather than setting the standard being measured against.

  11. Why is it important to identify the correct stakeholders when distributing a vulnerability or incident report?

    • A.So the retention schedule for audit evidence is satisfied
    • B.So each audience receives detail matched to its decisions
    • C.So the finished summary is encrypted before it circulates
    • D.So the wording matches the approved corporate style guide
    Show answerHide answer

    Correct answer: So each audience receives detail matched to its decisions

    Reports are written for people who have to act, and different readers act on different things: executives need business risk and cost, engineers need affected hosts and remediation steps, legal and compliance need regulatory exposure. Identifying the stakeholders first is what lets the writer pitch content at the right level for each. Meeting a retention schedule and encrypting the document before it moves are handling requirements that apply whoever receives it, and matching a house style changes presentation rather than substance.

  12. An executive audience is reading a security report. Which section is specifically written for them?

    • A.The findings matrix of rated risks for the system's owners
    • B.The methodology section of scope and testing for auditors
    • C.The opening summary of business exposure for the directors
    • D.The remediation plan of patch timelines for the sysadmins
    Show answerHide answer

    Correct answer: The opening summary of business exposure for the directors

    The executive summary is the opening summary of business exposure for the directors, written in plain language so leadership can make funding and risk-acceptance decisions. The findings matrix of rated risks is written for the system owners who must act on each finding. The methodology section documents the scope and testing approach for auditors and reviewers. The remediation plan of patch timelines is working detail for the administrators applying the fixes.

  13. Which type of report demonstrates that an organization meets the requirements of a regulation or standard such as PCI DSS or HIPAA?

    • A.A gap analysis report that lists controls missing per clause
    • B.A risk assessment report that ranks threats by likely impact
    • C.A compliance report that maps controls to regulatory clauses
    • D.A business impact analysis ranking processes by outage costs
    Show answerHide answer

    Correct answer: A compliance report that maps controls to regulatory clauses

    The artefact that shows conformance is a compliance report that maps controls to regulatory clauses such as PCI DSS or HIPAA requirements, which is what auditors and regulators ask to see. A gap analysis report lists controls still missing per clause, so it shows where the organisation does not yet comply. A risk assessment report ranks threats by likely impact without reference to a rule set. A business impact analysis ranks processes by outage costs for continuity planning.

  14. During incident response, which activity formally notifies leadership and triggers the response process based on defined criteria?

    • A.Declaring the incident once a threshold is crossed
    • B.Escalating the alert to the tier-two analyst queue
    • C.Notifying regulators after the breach is confirmed
    • D.Opening an incident ticket when an alert fires
    Show answerHide answer

    Correct answer: Declaring the incident once a threshold is crossed

    Declaring the incident once a threshold is crossed is the formal act that activates the response plan and the notification chain up to leadership, based on documented criteria. Escalating an alert to tier-two analysts is triage that happens before any declaration. Notifying regulators after a breach is confirmed is external notification, a later obligation. Opening an incident ticket when an alert fires records the event but does not formally declare anything or engage leadership.

  15. An analyst identifies that a contained incident now involves regulated customer data and possible legal exposure. What is the appropriate next communication step?

    • A.Notify the whole customer base through the open status page
    • B.Send the raw evidence over to the software vendor's experts
    • C.Prepare the service desk staff so they can answer questions
    • D.Escalate to the legal team along the defined response route
    Show answerHide answer

    Correct answer: Escalate to the legal team along the defined response route

    Once regulated data and legal exposure are in scope, the correct communication step is to move the incident up the documented path so counsel and executive decision makers own the disclosure question. Notifying customers directly through a public page pre-empts that decision and can create liability before counsel has assessed the breach. Sending raw evidence outside the organisation risks spoliation and uncontrolled disclosure. Briefing the service desk prepares call handling but leaves the people who must decide on notification uninformed.

  16. Which metric best communicates how quickly a SOC identifies an active incident?

    • A.Mean time to respond to an alert once it is raised
    • B.Mean time to detect an intrusion already under way
    • C.Mean time to acknowledge an alert once it is fired
    • D.Mean time to contain an intrusion once it is known
    Show answerHide answer

    Correct answer: Mean time to detect an intrusion already under way

    Mean time to detect an intrusion already under way measures the gap between malicious activity starting and the SOC identifying it, so it directly reports detection speed. Mean time to respond counts from the alert to the start of action, after detection. Mean time to acknowledge measures how fast an analyst picks up an alert that has already fired. Mean time to contain measures how quickly a known intrusion is stopped from spreading, a later stage.

  17. Why should incident reports and sensitive vulnerability findings be distributed through secure channels?

    • A.To keep exploitable details out of an attacker's hands
    • B.To keep the findings admissible as evidence in a trial
    • C.To keep the report's sender provable to its recipients
    • D.To keep the findings retained for the audit-term cycle
    Show answerHide answer

    Correct answer: To keep exploitable details out of an attacker's hands

    Reports and vulnerability findings list weak systems, missing patches and response gaps, so secure channels exist to keep exploitable details out of an attacker's hands through encryption and need-to-know distribution. Keeping findings admissible as evidence is the job of chain-of-custody handling, not transport security. Proving the report's sender to recipients is non-repudiation through digital signatures, which authenticates without hiding the content. Keeping findings for an audit term is a retention rule about how long records live, not who can read them in transit.

  18. A regulation requires notifying affected individuals within a fixed time window after a confirmed data breach. Which reporting consideration does this represent?

    • A.A compensating control logged in the local risk register
    • B.A tracking metric the remediation team checks each month
    • C.A standing advisory released by an industry threat group
    • D.A legal reporting duty imposed by the governing statutes
    Show answerHide answer

    Correct answer: A legal reporting duty imposed by the governing statutes

    A fixed deadline to notify affected individuals after a confirmed breach is a mandatory obligation created by law or regulation, so the analyst must give legal and compliance the facts they need to meet the clock. A compensating control is an alternative safeguard used when a required control cannot be implemented; it compels no notification. A tracking metric describes how the programme performs over time and carries no external obligation. An industry advisory is guidance an organisation can choose to follow, not a binding notification requirement.

  19. When communicating with non-technical executives versus the technical operations team about the same vulnerability, the analyst should primarily adjust which aspect of the message?

    • A.The severity score and the scanning tool identified in the report
    • B.The technical depth and the business framing of the whole message
    • C.The asset inventory and the exposure timing stated in the finding
    • D.The repair deadline and the owning team registered on each ticket
    Show answerHide answer

    Correct answer: The technical depth and the business framing of the whole message

    Audience-appropriate communication keeps the facts identical and changes only how much technical depth is presented and how the consequence is framed, so executives hear risk, cost and business impact while operations hears the technical remediation detail. The severity score and the tool that produced it are findings of record and must not shift with the audience. The affected asset list and the date exposure began are factual and equally fixed. The remediation deadline and the accountable owner are commitments that stay the same no matter who is briefed.

  20. A SOC manager reports that the team's mean time to respond (MTTR) dropped from 9 hours to 4 hours last quarter. What does this metric actually measure?

    • A.The average delay counted from intrusion until someone notices
    • B.The average runtime counted from restart until fresh breakdown
    • C.The average paperwork counted from closure until report filing
    • D.The average interval counted from detection until final repair
    Show answerHide answer

    Correct answer: The average interval counted from detection until final repair

    Mean time to respond runs from the moment an incident or vulnerability is detected to the moment it is contained or remediated, so a fall from nine hours to four means the team is closing issues in less than half the time it used to need. The clock starts at detection, which is why the period an intruder sits undetected belongs to mean time to detect instead. The span from a restart to the next breakdown is mean time between failures, a reliability measure of hardware and services rather than a response measure. Paperwork produced after an incident closes is documentation effort that falls outside the containment window this metric bounds.

  21. Which security metric specifically captures how long a vulnerability or threat exists in the environment before the security team becomes aware of it?

    • A.Mean time to acknowledge, measured from alert to the analyst
    • B.Mean time to contain, measured from alert to host isolation
    • C.Mean time to detect, measured from emergence to notification
    • D.Mean time to remediate, measured from disclosure to patching
    Show answerHide answer

    Correct answer: Mean time to detect, measured from emergence to notification

    The metric asked for is mean time to detect, measured from emergence to notification: it covers the window in which a threat or flaw is present but nobody knows, so it is the direct read on monitoring and scanning coverage. Mean time to acknowledge starts only after an alert already exists and measures how fast an analyst picks it up. Mean time to contain runs from the alert until the host is isolated, so awareness has already happened. Mean time to remediate tracks how long a known flaw stays unpatched after disclosure, which is a fixing delay, not a detection delay.

  22. A compliance officer asks the analyst to produce a compliance report ahead of an upcoming PCI DSS assessment. What is the primary purpose of such a report?

    • A.To show the auditors that operating controls satisfy a standard
    • B.To list the ASV scan findings that fail the next quarterly scan
    • C.To rank the open vulnerabilities that the patch team will fix
    • D.To estimate the fines that the business faces on a failed audit
    Show answerHide answer

    Correct answer: To show the auditors that operating controls satisfy a standard

    A compliance report exists to show the auditors that operating controls satisfy a standard, mapping each deployed control to the PCI DSS requirement it meets. Listing the ASV scan findings that fail the next quarterly scan is an external scan report, one input to compliance rather than the demonstration itself. Ranking the open vulnerabilities that the patch team will fix is a vulnerability management report aimed at remediation. Estimating the fines that the business faces on a failed audit is a business impact or risk analysis, which informs leadership but proves nothing about control coverage to an assessor.

  23. An incident response lead is asked to reduce the organization's mean time to respond. Which improvement would most directly lower this metric?

    • A.Tuning correlation rules so security analysts can detect intrusions sooner
    • B.Rehearsing prepared playbooks so responders can start containing instantly
    • C.Scheduling threat hunts so security analysts can find dormant actors early
    • D.Staging immutable backups so responders can restore services more quickly
    Show answerHide answer

    Correct answer: Rehearsing prepared playbooks so responders can start containing instantly

    Mean time to respond runs from detection to containment, so rehearsing prepared playbooks so responders can start containing instantly shortens exactly that window. Tuning correlation rules and scheduling threat hunts both shrink mean time to detect, the metric that ends where this one begins. Staging immutable backups speeds recovery after containment, which is mean time to recover, not respond.

  24. A CISO wants a small set of standardized measurements to track the health of the vulnerability management program over time. Which set best represents appropriate vulnerability management metrics?

    • A.Mean time to detect, alert triage backlog, and analyst handoffs
    • B.Mean time to remediate, patch service level, and reopening rate
    • C.Mean time to contain, phishing click rates, and training uptake
    • D.Open port counts, remote session peaks, and token renewal rates
    Show answerHide answer

    Correct answer: Mean time to remediate, patch service level, and reopening rate

    Mean time to remediate, the share of critical findings patched inside the agreed service-level window, and the count of findings that reopen after being closed are the standard trio for a vulnerability management program, because together they measure how fast it fixes things, how reliably it meets its commitments, and whether its fixes hold. Detection latency, triage volume, and handoff counts describe the monitoring pipeline and stop at the point a finding is raised. Containment time with phishing click and training completion rates mixes incident response with security awareness, neither of which measures remediation. Open port counts, session peaks, and token renewal rates are network and infrastructure hygiene figures.

  25. After completing a scan, an analyst compiles findings into a vulnerability report for the asset owners. What is the core purpose of a vulnerability report?

    • A.To record the weaknesses and severities so the owners can prioritize
    • B.To certify the assets and controls so that the auditors can sign off
    • C.To list the attack paths and pivots so the owners can grasp impacts
    • D.To log the risk exceptions and approvals so that auditors can review
    Show answerHide answer

    Correct answer: To record the weaknesses and severities so the owners can prioritize

    A vulnerability report exists to record the weaknesses and severities so the owners can prioritize remediation of the exposures that matter most. Certifying assets and controls so auditors can sign off is a compliance or attestation report, and no scan can prove an asset free of flaws. Listing attack paths and pivots so owners grasp impact describes a penetration test report, built from exploitation rather than scanning. Logging risk exceptions and approvals for auditor review is the risk register, which documents decisions not to remediate.

  26. A critical patch is available for a manufacturing control server, but applying it would force a production line shutdown that the business will not authorize. In a vulnerability report, how should the analyst categorize this barrier?

    • A.Compensating control already lowering the production server risk
    • B.Key risk indicators forecasting the critical production shutdown
    • C.Service level agreements restricting the production patch window
    • D.Recorded remediation inhibitor delaying the approved repair work
    Show answerHide answer

    Correct answer: Recorded remediation inhibitor delaying the approved repair work

    The barrier is an inhibitor to remediation, the category covering constraints that block or delay a fix, and the specific inhibitor here is business process interruption, since applying the patch would stop the production line. The recognized set also includes memoranda of understanding, service-level agreements, organizational governance, degrading functionality, legacy systems, and proprietary systems. It is not a compensating control, because no alternative safeguard has been put in place yet; the flaw is simply still open and nothing is lowering the exposure. A key risk indicator is a forward-looking forecast of exposure, not a named obstacle already blocking work. A service-level agreement restricts when the fix may be installed and sets the timeline it should meet, so it is one of the things this obstacle causes the team to miss rather than the obstacle itself.

  27. Which of the following is the best example of a key performance indicator (KPI) for a vulnerability management program, as opposed to a key risk indicator?

    • A.Projected likelihood that an unpatched server is exploited shortly
    • B.Estimated damage should a primary customer database be compromised
    • C.Percentage of critical findings remediated inside the agreed limit
    • D.Percentage of staff finishing the annual awareness training course
    Show answerHide answer

    Correct answer: Percentage of critical findings remediated inside the agreed limit

    A key performance indicator measures how well a program is doing against a target it owns, and the share of high and critical findings remediated inside the agreed service-level window does exactly that for vulnerability management. A projected chance of exploitation is a key risk indicator: it forecasts exposure rather than grading past work. An estimated loss figure is likewise a risk indicator, expressing potential impact in money. Training completion is a genuine performance indicator, but it grades the security awareness program rather than the vulnerability management program the question asks about, so it measures the wrong team's work.

  28. An analyst must brief both the board of directors and the system engineering team about the same newly discovered critical vulnerability. Which approach reflects sound stakeholder communication?

    • A.Tailor the briefing for each audience, matching specifics to the decisions
    • B.Give both audiences the executive summary, fielding questions as they come
    • C.Give both audiences the full technical report, keeping the facts identical
    • D.Brief the engineers in detail now, then update the board after remediation
    Show answerHide answer

    Correct answer: Tailor the briefing for each audience, matching specifics to the decisions

    Sound practice is to tailor the briefing for each audience, matching specifics to the decisions each must make: directors need business impact, exposure and the risk decision asked of them, while engineers need technical detail and remediation steps. Giving both audiences the executive summary leaves the engineers without the technical detail they need to fix the flaw. Giving both audiences the full technical report buries the board in detail it cannot act on; consistency is not the goal. Briefing the engineers now and updating the board after remediation denies leadership a risk decision while the critical exposure is still live.

  29. A vulnerability management policy states that critical findings must be remediated within 7 days and high findings within 30 days. What is this type of agreement called in a cybersecurity context?

    • A.A memorandum of understanding agreement between signing partners
    • B.A nondisclosure agreement covering the shared incident materials
    • C.A business associate agreement covering processed health records
    • D.A service level agreement carrying defined remediation deadlines
    Show answerHide answer

    Correct answer: A service level agreement carrying defined remediation deadlines

    Committing to fix critical findings within seven days and high findings within thirty is a service-level agreement: it states measurable performance targets with deadlines attached and holds the team accountable to them, which is what makes a metric such as percentage patched within window computable at all. A memorandum of understanding records broad intent to cooperate between parties and deliberately carries no enforceable service target. A nondisclosure agreement restricts how shared information may be disclosed and sets no repair timeline. A business associate agreement obligates a vendor handling protected health data to safeguard it, which is a confidentiality and privacy duty rather than a remediation clock.

  30. A monthly vulnerability report shows that the same critical finding on a single host has been reported, marked remediated, and then reappeared in each of the last three scans. Which reporting element most accurately captures this pattern, and what does it signal?

    • A.A compensating control, showing the residual risk stays covered
    • B.A re-opened finding, showing the applied repair keeps reverting
    • C.A missed detection, showing the scanner overlooked one endpoint
    • D.A zero-day exposure, showing the vendor patch stays unavailable
    Show answerHide answer

    Correct answer: A re-opened finding, showing the applied repair keeps reverting

    A finding that is reported, closed, and then detected again on the same host across consecutive scans is a recurring or reopened vulnerability, and the pattern says the remediation is not sticking: configuration drift, a redeployed golden image, or a reverted change keeps reintroducing it. Tracking the reopen rate is a useful program metric precisely because a rising count points at a broken remediation process rather than at new discovery. It is not a false negative, since the scanner is finding the flaw every time. It is not a zero-day, since a fix plainly exists and has been applied more than once. And no alternative safeguard has been introduced, so nothing is being compensated for.

References

  1. 1.CompTIA. “CySA+ Certification (official overview).” CompTIA.org, 2026. ↑
  2. 2.CompTIA. “CySA+ CS0-003 Exam Objectives (official PDF).” CompTIA.org. ↑
  3. 3.CompTIA Store. “CySA+ CS0-003 voucher and bundles.” CompTIA Store. ↑
  4. 4.CompTIA. “The New CompTIA Cybersecurity Analyst (CySA+): Your Questions Answered.” CompTIA Blog. ↑
  5. 5.Pearson VUE. “CompTIA exam scheduling.” Pearson VUE. ↑
  6. 6.CompTIA. “CySA+ V4 (CS0-004) — exam details.” CompTIA.org, 2026. ↑
  7. 7.Career Employer. “CySA+ practice-test performance data.” careeremployer.com, updated daily, CC BY 4.0. ↑
Career Employer

Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.

Follow Us:

All Posts

Career Employer’s Editorial Process

Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.