CySA Plus Exam Prep Free practice test →

Free CySA Plus Practice Questions

10 free, exam-style CySA Plus (CySA Plus) practice questions with answers and explanations. No signup required. Work through them below, then take the full free CySA Plus practice test to study every exam domain.

Question 1

A SOC analyst reviews SIEM alerts and notices a workstation is making HTTPS connections to an external IP address every 60 seconds. Each connection transfers less than 1 KB of data. No user activity is occurring on the workstation at the time. Which type of malicious activity does this pattern MOST likely indicate?

  1. Command and control beaconing when applied properly
  2. Distributed denial-of-service participation
  3. Peer-to-peer lateral movement in the typical case
  4. DNS tunneling for data exfiltration
Show answer & explanation

Correct answer: A - Command and control beaconing when applied properly

Question 2

A security analyst investigates a suspicious email reported by an employee. The email header shows the following results: SPF: PASS DKIM: FAIL DMARC: FAIL (policy: quarantine) What does the DKIM failure indicate about this email?

  1. The sender's domain does not have a DMARC record
  2. The message content was altered after being sent
  3. The email was sent over an unencrypted connection
  4. The sending IP address is not authorized for the domain
Show answer & explanation

Correct answer: B - The message content was altered after being sent

Question 3

A company's threat intelligence team discovers that a recent breach used a zero-day exploit, was conducted over several months with careful operational security, and targeted proprietary defense research data. Which threat actor type is MOST consistent with this activity?

  1. Nation-state in the typical case
  2. Hacktivist under accepted convention
  3. Script kiddie when applied properly
  4. Insider threat under accepted convention
Show answer & explanation

Correct answer: A - Nation-state in the typical case

Question 4

A vulnerability scanner returns the following CVSS v3.1 vector string for a finding on a hypervisor: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H What does the Scope metric value of "Changed" (S:C) indicate about this vulnerability?

  1. The attacker must change networks to exploit the vulnerability
  2. Exploitation impacts resources beyond the vulnerable component
  3. The vulnerability changes the CVSS score from High to Critical
  4. The attack vector changes from Local to Network after exploitation
Show answer & explanation

Correct answer: B - Exploitation impacts resources beyond the vulnerable component

Question 5

An organization is migrating workloads to AWS and needs to assess its cloud environment against CIS benchmark security configurations. Which tool is MOST appropriate for this task?

  1. Recon-ng as ordinarily interpreted
  2. Nessus as ordinarily interpreted
  3. Prowler under standard market practice
  4. Burp Suite under applicable rules
Show answer & explanation

Correct answer: C - Prowler under standard market practice

Question 6

A vulnerability scan reveals two critical findings: Finding A: CVSS 9.8 on an air-gapped SCADA system with no known public exploit. Finding B: CVSS 7.5 on an internet-facing web server with an active Metasploit module. Which finding should be remediated FIRST, and why?

  1. Finding A, because SCADA systems control critical physical processes
  2. Both findings equally, because both exceed a CVSS score of 7.0
  3. Finding A, because the CVSS score is higher as commonly understood
  4. Finding B, because it has a known exploit and external exposure
Show answer & explanation

Correct answer: D - Finding B, because it has a known exploit and external exposure

Question 7

During a threat hunt, an analyst identifies a C2 server domain used in an attack. The analyst uses this finding to discover the malware family deployed and the adversary group responsible. Which analytical framework supports this type of pivoting between intrusion components?

  1. OSSTMM under standard market practice
  2. OWASP Testing Guide for Web Applications
  3. Lockheed Martin Cyber Kill Chain
  4. Diamond Model of Intrusion Analysis
Show answer & explanation

Correct answer: D - Diamond Model of Intrusion Analysis

Question 8

A security team arrives on-site to respond to a confirmed endpoint compromise. The affected laptop is still powered on and connected to the network. Following the order of volatility, which evidence source should the team capture FIRST?

  1. Firewall and proxy log exports
  2. Offline backup comparison files
  3. Contents of system RAM in the typical case
  4. Full disk image of the hard drive
Show answer & explanation

Correct answer: C - Contents of system RAM in the typical case

Question 9

A vulnerability scan identifies a critical remote code execution flaw on a hospital's patient monitoring system. The device vendor states that applying the patch will void the support contract, and the system cannot be taken offline. Which inhibitor to remediation does this scenario BEST represent?

  1. Proprietary system when applied properly
  2. Organizational governance under standard market practice
  3. Business process interruption under accepted convention
  4. Service level agreement under accepted convention
Show answer & explanation

Correct answer: A - Proprietary system when applied properly

Question 10

After implementing a new EDR solution, a SOC manager reviews quarterly metrics and finds that the average time between an intrusion occurring and the SOC receiving an alert has decreased from 12 days to 36 hours. Which incident response metric reflects this improvement?

  1. Mean time to remediate under applicable rules
  2. Mean time to detect under accepted convention
  3. Alert volume under applicable rules
  4. Mean time to respond in this context
Show answer & explanation

Correct answer: B - Mean time to detect under accepted convention

Ready for the real thing?

Practice hundreds more CySA Plus questions with instant scoring, weak-area drills, and full exam simulations.

Start the free practice test See pricing