Geschreven door studenten die geslaagd zijn Direct beschikbaar na je betaling Online lezen of als PDF Verkeerd document? Gratis ruilen 4,6 TrustPilot
logo-home
Tentamen (uitwerkingen)

COMPTIA CYSA+ – PRACTICE QUESTIONS AND CORRECT ANSWERS (VERIFIED ANSWERS) PLUS RATIONALES 2026 Q&A | INSTANT DOWNLOAD PDF.

Beoordeling
-
Verkocht
-
Pagina's
39
Cijfer
A+
Geüpload op
10-05-2026
Geschreven in
2025/2026

COMPTIA CYSA+ – PRACTICE QUESTIONS AND CORRECT ANSWERS (VERIFIED ANSWERS) PLUS RATIONALES 2026 Q&A | INSTANT DOWNLOAD PDF.

Instelling
COMPTIA CYSA+
Vak
COMPTIA CYSA+

Voorbeeld van de inhoud

COMPTIA CYSA+ – PRACTICE QUESTIONS AND CORRECT ANSWERS (VERIFIED ANSWERS) PLUS
RATIONALES 2026 Q&A | INSTANT DOWNLOAD PDF.
Core Domains
- Threat and Vulnerability Management
- Software and Systems Security
- Compliance and Assessment
- Security Operations and Monitoring
- Incident Response
- Identity and Access Management
- Network Security and Infrastructure
- Data Privacy and Protection
- Cloud and Hybrid Security
Introduction
The CompTIA CySA+ assessment is designed to validate the knowledge and technical skills required to
proactively monitor, detect, and respond to cybersecurity threats and vulnerabilities. This exam emphasizes the
application of behavioral analytics to networks and devices to identify and counter security risks before they
result in a breach. The structure consists of multiple-choice and complex scenario-based questions that
simulate real-world environments. Candidates are evaluated on their ability to perform data analysis, interpret
results, and implement effective security solutions. Success requires high-level critical thinking, ethical
judgment, and a deep understanding of regulatory compliance in a modern enterprise landscape.
1. An analyst is reviewing a vulnerability scan report and notices a high-severity vulnerability on a legacy
server that cannot be patched due to application compatibility issues. Which of the following is the best
course of action?

A. Accept the risk and document it in the risk register.
B. Implement a compensating control, such as an isolated VLAN.

,C. Ignore the vulnerability as the server is legacy.
D. Immediately decommission the server without notice.
🟢 B. Implement a compensating control, such as an isolated VLAN.
🔴 RATIONALE: Compensating controls allow for risk mitigation when a primary control, like patching, cannot
be applied due to technical constraints.
2. Which of the following best describes the "Diamond Model" of intrusion analysis?

A. A framework for calculating the financial impact of a breach.
B. A methodology for tracking the steps an attacker takes during an exploit.
C. A model relating adversary, infrastructure, capability, and victim.
D. A hierarchical structure for organizing a Security Operations Center.
🟢 C. A model relating adversary, infrastructure, capability, and victim.
🔴 RATIONALE: The Diamond Model focuses on the relationships between these four core features to
understand the context of an intrusion.
3. During an incident response, an analyst captures a suspicious file and wants to determine its behavior
without risking the host system. Which tool is most appropriate?

A. Wireshark
B. Nmap
C. Cuckoo Sandbox
D. Nessus
🟢 C. Cuckoo Sandbox
🔴 RATIONALE: A sandbox environment allows for the execution of suspicious files in an isolated environment
to observe their behavior safely.

, 4. A security analyst receives an alert regarding a spike in DNS traffic to a known malicious domain. Which
type of attack is most likely occurring?

A. SQL Injection
B. Command and Control (C2) communication
C. Cross-Site Scripting (XSS)
D. ARP Spoofing
🟢 B. Command and Control (C2) communication
🔴 RATIONALE: Malware often uses DNS to beacon out to a C2 server to receive instructions or exfiltrate
data.
5. Which regulatory framework is specifically focused on the protection of electronic protected health
information (ePHI) in the United States?

A. GDPR
B. PCI DSS
C. HIPAA
D. SOX
🟢 C. HIPAA
🔴 RATIONALE: The Health Insurance Portability and Accountability Act (HIPAA) mandates security and
privacy standards for health information.
6. An organization wants to move its infrastructure to the cloud but must ensure that data from different
customers is logically separated. Which concept describes this?

A. Multi-tenancy
B. Serverless computing
C. Infrastructure as Code
D. Resource pooling

, 🟢 A. Multi-tenancy
🔴 RATIONALE: Multi-tenancy involves serving multiple customers from the same infrastructure while ensuring
data isolation and privacy.
7. While reviewing logs, an analyst sees a series of failed login attempts for several different accounts from a
single IP address within a short timeframe. What is this an example of?

A. Brute-force attack
B. Password spraying
C. Credential stuffing
D. Rainbow table attack
🟢 B. Password spraying
🔴 RATIONALE: Password spraying involves trying a few common passwords against many different accounts
to avoid account lockout.
8. Which of the following is the most effective way to prevent Cross-Site Request Forgery (CSRF) attacks?

A. Input validation
B. Anti-CSRF tokens
C. Web Application Firewall (WAF)
D. HTTPS encryption
🟢 B. Anti-CSRF tokens
🔴 RATIONALE: Unique, unpredictable tokens for each session ensure that requests are intentional and come
from the authenticated user.
9. A company discovers that an employee has been exfiltrating sensitive data via an encrypted USB drive.
Which type of threat does this represent?

Geschreven voor

Instelling
COMPTIA CYSA+
Vak
COMPTIA CYSA+

Documentinformatie

Geüpload op
10 mei 2026
Aantal pagina's
39
Geschreven in
2025/2026
Type
Tentamen (uitwerkingen)
Bevat
Vragen en antwoorden

Onderwerpen

€23,34
Krijg toegang tot het volledige document:

Verkeerd document? Gratis ruilen Binnen 14 dagen na aankoop en voor het downloaden kun je een ander document kiezen. Je kunt het bedrag gewoon opnieuw besteden.
Geschreven door studenten die geslaagd zijn
Direct beschikbaar na je betaling
Online lezen of als PDF

Maak kennis met de verkoper
Seller avatar
certificationpag
1,0
(1)

Maak kennis met de verkoper

Seller avatar
certificationpag For state PCS, UPSC, UGC NET
Volgen Je moet ingelogd zijn om studenten of vakken te kunnen volgen
Verkocht
1
Lid sinds
1 maand
Aantal volgers
0
Documenten
620
Laatst verkocht
3 weken geleden

1,0

1 beoordelingen

5
0
4
0
3
0
2
0
1
1

Recent door jou bekeken

Waarom studenten kiezen voor Stuvia

Gemaakt door medestudenten, geverifieerd door reviews

Kwaliteit die je kunt vertrouwen: geschreven door studenten die slaagden en beoordeeld door anderen die dit document gebruikten.

Niet tevreden? Kies een ander document

Geen zorgen! Je kunt voor hetzelfde geld direct een ander document kiezen dat beter past bij wat je zoekt.

Betaal zoals je wilt, start meteen met leren

Geen abonnement, geen verplichtingen. Betaal zoals je gewend bent via iDeal of creditcard en download je PDF-document meteen.

Student with book image

“Gekocht, gedownload en geslaagd. Zo makkelijk kan het dus zijn.”

Alisha Student

Bezig met je bronvermelding?

Maak nauwkeurige citaten in APA, MLA en Harvard met onze gratis bronnengenerator.

Bezig met je bronvermelding?

Veelgestelde vragen