CompTIA CySA+ Exam Free Practice Test — 30 Questions
This practice set exercises knowledge of vulnerability management prioritization, regulatory compliance, incident response, and professional ethics. Decisions involve balancing technical severity with business impact, adhering to data privacy laws like GDPR and HIPAA, preserving forensic evidence, and conducting ethical intelligence gathering. It reinforces the importance of risk-based prioritization, compensating controls, and thorough documentation. The scenarios test the ability to apply frameworks such as CVSS, NIST CSF, and STRIDE in realistic organizational contexts.
What this CompTIA CySA+ Exam practice set measures
This is an analysis of the practice bank, not a claim about the vendor's live exam blueprint. Use it to identify the knowledge, judgment, and recall patterns exercised here, then verify your coverage against the current official exam guide.
Vulnerability Management and Prioritization
Effective vulnerability management requires prioritizing remediation based on both technical exploitability and business impact. The practice bank emphasizes using CVSS scores alongside asset criticality to focus resources on high-risk vulnerabilities. Scenarios illustrate the need for risk assessments, phased remediation plans, and compensating controls when permanent fixes are delayed. Realistic constraints like limited resources and legacy systems challenge analysts to make defensible trade-offs. The correct approach consistently involves structured prioritization aligned with organizational risk tolerance and regulatory expectations.
- Prioritize vulnerabilities using CVSS base score and asset business criticality.
- Implement compensating controls for immediate risk reduction when permanent fixes take time.
- Conduct comprehensive risk assessments to identify and prioritize vulnerabilities based on impact and likelihood.
Regulatory Compliance and Data Privacy
Compliance with regulations like GDPR, HIPAA, and PCI-DSS is a recurring theme. The practice bank stresses conducting Data Protection Impact Assessments (DPIAs) before deploying systems that process personal data. When multiple regulations apply, the best practice is to meet the most stringent requirements. Organizations must integrate security into the development lifecycle, not rely solely on perimeter controls like WAFs. Incident response must include immediate legal consultation and adherence to breach notification timelines.
- Conduct a DPIA for new systems handling personal data to identify and mitigate privacy risks.
- Apply the most stringent requirements when multiple regulations (e.g., GDPR, HIPAA, PCI-DSS) apply.
- Integrate security into design and development, using secure coding and regular testing, not just post-deployment firewalls.
Incident Response and Digital Forensics
Incident response scenarios require balancing rapid recovery with forensic integrity and regulatory compliance. The correct actions include immediately isolating affected systems, creating forensic images before analysis, and documenting all steps to maintain chain of custody. Recovery should follow the disaster recovery plan while preserving evidence. Notification obligations must be assessed with legal counsel early. The practice bank consistently emphasizes a structured, phased approach that prioritizes containment, evidence preservation, and regulatory reporting.
- Create forensically sound images of affected systems and analyze copies, never originals.
- Implement tiered response: isolate high-confidence IOCs, escalate medium-confidence for human review, log low-confidence.
- Engage legal and privacy officers immediately to determine notification requirements under applicable laws.
Ethical and Professional Conduct
Ethical dilemmas arise in penetration testing and threat intelligence. Testers must adhere to scope but report critical vulnerabilities outside scope discretely. OSINT gathering must use only publicly accessible sources, avoiding any unauthorized access. When gathering threat intelligence, rely on vetted, public feeds and IOCs. The practice bank reinforces that ethical behavior includes respecting boundaries, maintaining client trust, and avoiding actions that could harm or violate laws. Professional judgment is key when balancing contractual obligations with broader security obligations.
- Report critical vulnerabilities discovered outside scope discreetly to the client point of contact.
- Use only publicly accessible sources for OSINT; avoid any unauthorized probing or data access.
- Rely on reputable threat intelligence feeds and IOCs from vetted sources for TTP understanding.
Practice CompTIA CySA+ Exam with real flashcards
Read the prompt, commit to an answer, then flip the card. Move through the deck at your own pace and repeat any topic that does not come back quickly.
Card 1 of 20
1 reviewed this session
Static practice bank
Start the 30-question diagnostic
The complete question bank is embedded in this pre-rendered page. There is no database request or second content download when you begin.
What factors determine the optimal scope and delivery methods for a security awareness training program within a US-based financial institution?
Study workflow
Turn one CompTIA CySA+ Exam attempt into a study plan
- 1
Prioritize Vulnerabilities Using CVSS and Asset Criticality
Review the vulnerability scan report and assign each finding a priority based on its CVSS base score and the business criticality of the affected asset. Focus remediation on vulnerabilities with the highest combined risk, ensuring alignment with regulatory requirements and organizational risk tolerance.
- 2
Conduct a Data Protection Impact Assessment (DPIA)
Before deploying any system that processes personal data, perform a DPIA to identify privacy risks and required safeguards. Document data flows, assess necessity and proportionality, and implement measures to minimize data collection and ensure compliance with GDPR or other relevant regulations.
- 3
Implement Compensating Controls During Remediation
When a permanent vulnerability fix is delayed, deploy a temporary compensating control (e.g., configuration change, network segmentation) within 24 hours to reduce exploitability. Simultaneously initiate the formal change process for the permanent fix, and monitor the control's effectiveness continuously.
- 4
Preserve Forensic Evidence with Proper Chain of Custody
Upon suspecting a data breach, immediately create forensically sound images of affected systems and storage media using write-blockers. Document every action, including the image creation, analysis, and any transfers. Keep a detailed chain of custody log to ensure evidence admissibility in legal proceedings.
- 5
Use Hybrid Threat Modeling (STRIDE + Data Flow Diagrams)
For a new application like an online banking platform, combine STRIDE (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege) with detailed data flow diagrams and asset mapping. This identifies threats comprehensively and aligns with regulatory expectations for protecting financial data.
FAQ
Questions about this exam practice page
Clear boundaries on what the bank covers, how to use it, and where official vendor information still matters.
How does CVSS factor into vulnerability prioritization for CySA+?+
CVSS provides a standardized severity score, but CySA+ emphasizes combining it with business impact. High CVSS on a critical asset warrants immediate action, while a lower score on a non-critical system may be deferred. The exam expects risk-based prioritization that considers both factors.
What is the role of a Data Protection Impact Assessment (DPIA) in compliance?+
A DPIA identifies and mitigates privacy risks before processing personal data, especially under GDPR. It is mandatory for high-risk processing. The CySA+ practice bank shows that skipping a DPIA leads to non-compliance, while conducting it early ensures legal and ethical data handling.
When should compensating controls be used instead of a permanent fix?+
Compensating controls are appropriate when a permanent patch is not immediately available. They reduce risk temporarily while the permanent fix is developed. CySA+ scenarios stress implementing such controls within 24 hours and documenting them for audit and compliance.
What is the correct forensic procedure for a suspected data breach?+
Create forensically sound images of all affected systems and media using write-blockers. Analyze copies, not originals, and maintain a detailed chain of custody. This preserves evidence integrity for legal proceedings and aligns with best practices emphasized in the practice bank.
How does STRIDE threat modeling apply to financial applications?+
STRIDE systematically identifies threats: Spoofing, Tampering, Repudiation, Info Disclosure, DoS, Elevation of Privilege. Combined with data flow diagrams, it ensures comprehensive coverage. For online banking, this meets regulatory expectations by addressing all attack vectors that could compromise client data.
Build the next review session
Browse another free bank or use the study strategy guide to turn your misses into spaced review.
