TechNuggets Academy
CS0-003

Free CompTIA Cybersecurity Analyst (CySA+) Practice Test

12 exam-style questions with full explanations — no sign-up. Score yourself, then close your gaps with the full course.

Exam fee ~$4044 exam domainsLevel Intermediate2 timed practice tests in the course
✅ Free practice — no sign-up📝 Real exam-style questions💡 Detailed explanations💸 30-day money-back via Udemy
Question 1 of 12 · Security Operations
During threat hunting, a SOC analyst discovers a workstation generating hundreds of DNS queries per minute to seemingly random, algorithmically generated domain names, with most queries returning NXDOMAIN. Which conclusion BEST explains this observation?
Malware families that use command-and-control resilience techniques often generate hundreds of pseudo-random domain names per day; most fail to resolve (NXDOMAIN) because only the attacker-controlled ones are registered. High-volume NXDOMAIN patterns in DNS logs are the classic indicator analysts use to confirm DGA-based C2 activity.
Question 2 of 12 · Vulnerability Management
A security analyst wants to reduce false positives and gain accurate visibility into missing patches and misconfigurations on internal Windows servers, but is concerned about scan performance impact during business hours. Which approach BEST meets these requirements?
Credentialed scans authenticate to the host, providing accurate patch and configuration data with far fewer false positives than unauthenticated methods. Scheduling during a maintenance window addresses the performance concern.
Question 3 of 12 · Incident Response and Management
During a post-incident review, analysts want to map an adversary's observed techniques to a single, granular reference of tactics and procedures to identify detection gaps in their SIEM rules. Which framework should they use for this specific purpose?
MITRE ATT&CK provides a granular, continuously updated matrix of specific tactics, techniques, and sub-techniques mapped to real-world adversary behavior, making it the best tool for identifying detection coverage gaps at a technique level.
Question 4 of 12 · Reporting and Communication
A vulnerability scan identifies a critical unpatched vulnerability on a legacy manufacturing control system. The system owner states that patching would require a six-month maintenance window and could void the vendor's support contract. Which of the following BEST describes this situation in a vulnerability management report?
Business and technical constraints (long maintenance windows, vendor support contract restrictions) that prevent timely patching are classic documented 'inhibitors to remediation,' which should be reported along with recommended compensating controls (e.g., network segmentation, enhanced monitoring) until the patch can be applied.
Question 5 of 12 · Security Operations
An analyst needs to capture full packet payloads on a network segment and reconstruct an entire TCP conversation for offline protocol-level review of a suspected data exfiltration attempt. Which tool is BEST suited for this task?
Wireshark provides full packet capture with a GUI, deep protocol dissectors, and a 'Follow TCP Stream' feature that reconstructs an entire conversation payload-by-payload, making it the standard tool for detailed offline packet analysis on the exam.
Question 6 of 12 · Vulnerability Management
An organization has a large remote workforce with laptops that connect intermittently to the corporate VPN, sometimes only once every few weeks. The security team needs continuous vulnerability visibility on these devices regardless of network connectivity. Which scanning approach BEST satisfies this requirement?
An installed agent scans locally regardless of network reachability and uploads results whenever connectivity to the management server is available, giving continuous visibility on intermittently connected endpoints.
Question 7 of 12 · Incident Response and Management
An incident responder documents the adversary, the capability used, the infrastructure involved, and the victim for a single confirmed intrusion event. Which analytic model is being applied?
The Diamond Model's four core features are exactly adversary, capability, infrastructure, and victim, connected to form an event vertex used for pivoting between related intrusions.
Question 8 of 12 · Reporting and Communication
During an incident response investigation, an analyst confirms that an attacker exfiltrated a database containing customer Social Security numbers. In addition to the incident response team and IT management, which stakeholder MUST be notified immediately based on this finding?
Confirmed exposure of PII such as Social Security numbers typically triggers regulatory and contractual breach notification obligations, so legal counsel and the compliance/privacy officer must be looped in immediately to assess notification timelines and legal exposure.
Question 9 of 12 · Security Operations
A SOC configures a SIEM rule that only triggers an alert when it observes five failed login attempts from the same source IP within two minutes, immediately followed by one successful login. Which detection technique does this rule represent?
This rule correlates a sequence of related events (multiple failures followed by success) rather than matching a static signature or a known-bad IP/domain. Correlating a behavioral pattern across multiple log events over a time window is the definition of behavior-based correlation used to flag brute-force/credential-stuffing.
Question 10 of 12 · Vulnerability Management
A vulnerability report lists a finding with the CVSS v3.1 vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Based on this vector, which statement is accurate?
AV:N (network), AC:L (low complexity), PR:N (no privileges required), UI:N (no user interaction), combined with C:H/I:H/A:H, describes a remotely exploitable flaw with high impact across all three CIA properties.
Question 11 of 12 · Incident Response and Management
A ransomware infection is spreading rapidly across a hospital's clinical network. Patient care systems on the same VLAN are not yet infected but are at imminent risk. Analysts cannot immediately identify patient zero. Which containment action is MOST appropriate?
Network segmentation/isolation at the switch or firewall is a standard short-term containment strategy that halts lateral movement while preserving volatile evidence and system state for later forensic analysis, and it avoids the operational disruption of shutting down critical clinical systems.
Question 12 of 12 · Reporting and Communication
An organization's incident response report shows the average time between an intrusion occurring and the security team identifying it. Which metric does this describe?
Mean time to detect (MTTD) specifically measures the elapsed time from when an intrusion first occurs to when the security team identifies/detects it, making it a key metric in incident response reporting.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →

CS0-003 exam — quick answers

How much does the CS0-003 exam cost?

The exam fee is approximately $404 and varies by region — confirm current pricing with the certification vendor before you book.

What topics are on the exam?

It covers 4 domains: Security Operations (33%), Vulnerability Management (30%), Incident Response and Management (20%), Reporting and Communication (17%). The full course has a dedicated chapter, lab and practice-test coverage for each.

Is this practice test really free?

Yes — all questions on this page are free with explanations and no sign-up. The paid Udemy course adds two full-length timed exams, video lessons and hands-on labs.

Will this prepare me for the real exam?

The questions mirror the real exam's style and are mapped to the official domains. This is exam-focused preparation — combine the free test with the full course's timed simulations to gauge your readiness.

More free practice by exam domain:
Security Operations →Vulnerability Management →Incident Response and Management →Reporting and Communication →