Start free →
Study guide · CompTIA CySA+

CompTIA CySA+ Practice Exam (CS0-003)

270 practice questions for the CySA+ CS0-003 exam — threat detection, vulnerability management, incident response, and reporting. The intermediate cybersecurity analyst certification.

Start practicing now — free

20 free questions · No credit card

Try CySA+ questions →

About the CySA+ CS0-003 exam

CompTIA CySA+ is the intermediate cybersecurity certification between Security+ and CASP+. The CS0-003 version emphasizes behavioral analytics, threat intelligence, and SOC operations. Ideal for security analysts with 3–4 years of experience. The exam has up to 85 questions, 165-minute time limit, and a passing score of 750/900.

CS0-003 exam domains

22%
Security Operations
35%
Vulnerability Management
22%
Incident Response & Management
21%
Reporting & Communication

Sample CySA+ practice questions

A security analyst reviewing SIEM alerts notices a large number of failed SSH login attempts from a single IP, followed by a single successful login. What type of attack most likely occurred?
A. Spear phishing
B. Brute force attack ✓
C. SQL injection
D. Man-in-the-middle attack
Multiple failed logins followed by a success is the classic signature of a brute force or password spray attack. The follow-up action would be to investigate the successful session for lateral movement indicators.
A vulnerability scan shows a critical vulnerability on a production server requiring a 4-hour maintenance window, but the server handles 24/7 customer transactions. What is the BEST immediate risk mitigation?
A. Ignore the vulnerability until the next scheduled maintenance
B. Patch immediately regardless of impact
C. Apply compensating controls such as WAF rules or network isolation while scheduling patching ✓
D. Decommission the server
Compensating controls are the industry-standard approach when immediate patching isn't feasible. A WAF rule or firewall restriction reduces attack surface while business continuity is maintained.
Which threat intelligence sharing format is specifically designed for structured communication of cyber threat information between organizations?
A. CVE
B. CVSS
C. STIX/TAXII ✓
D. MITRE ATT&CK
STIX defines the format for threat intelligence data. TAXII is the transport protocol that delivers STIX data between organizations. CVE identifies vulnerabilities. CVSS scores severity. MITRE ATT&CK is a framework, not a sharing format.

How to prepare for CySA+

Vulnerability Management is the largest domain

At 35%, understand the full vulnerability lifecycle: scanning, analysis, prioritization (CVSS, EPSS), remediation, and exception handling. Know how to read Nessus/Qualys output and interpret CVSS base scores.

Log analysis is essential

CySA+ PBQs present real log data — Windows Event Logs, Syslog, NetFlow, firewall logs, SIEM dashboards. Practice reading these and identifying indicators of compromise: failed logins, unusual outbound connections, registry modifications.

Learn the MITRE ATT&CK framework

Know the main tactics: Reconnaissance, Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Lateral Movement, Exfiltration. This framework underpins threat hunting and incident response questions.

270 CySA+ questions with full explanations

Free to start · Pro unlocks all + timed exam mode

Start practicing →

More certifications on aprencert