26 Attack Frameworks & the Response Process Practice Questions & Answers
Every Attack Frameworks & the Response Process practice question from the CompTIA CySA+ Practice Test, with the correct answer and a short explanation.
Start practice test →1. A security operations centre maintains about 300 detection rules. Leadership asks which adversary behaviours the team would miss entirely. Analysts map every rule to the tactics and techniques of a public behaviour catalogue and shade the matrix by how many rules cover each entry. What does this exercise actually produce?
- A.A ranked list of the vulnerabilities most likely to be exploited on the monitored hosts, so that patching work can be sequenced
- B.A view of which adversary behaviours no current rule would detect, so engineering effort can be aimed at those gaps✓ Answer
- C.A count of how many alerts each rule raises per shift, so that the noisiest rules can be tuned or retired before the rest
- D.An attribution judgement naming the adversary group most likely to target this organisation during the coming year
Mapping existing rules onto a tactic-and-technique catalogue turns a rule inventory into a coverage picture: entries with no rule behind them are behaviours that would pass unnoticed. The catalogue describes adversary behaviour, so it cannot rank host vulnerabilities, measure alert volume, or attribute activity to a group.
Source: CompTIA CySA+ CS0-004 Objective 3.1 (attack methodology frameworks); MITRE ATT&CK stated use for detection coverage assessmentReport a problem with this question
2. Analysts confirm that an intruder read credentials out of process memory on one server and then queried the directory for members of privileged groups. The team asks what a catalogue of adversary tactics and techniques can contribute at this point in the investigation.
- A.It shows which behaviours commonly follow credential access and discovery, so hunting can be aimed at the likely next moves✓ Answer
- B.It names the group responsible for the intrusion, because each technique entry is used by only one tracked adversary
- C.It shows how long the intruder has been present, because every technique entry records a typical dwell time in days
- D.It gives the order the intruder must follow next, because catalogue entries are numbered in the sequence they occur
A behaviour catalogue groups techniques under the goals they serve, so observed credential access and discovery point to the behaviours adversaries commonly use next, such as lateral movement or persistence. The catalogue records no dwell time, assigns no unique owner to a technique, and imposes no mandatory order on an intrusion.
Source: CompTIA CySA+ CS0-004 Objective 3.1; MITRE ATT&CK tactic/technique structure (tactic = goal, technique = method)Report a problem with this question
3. After a joint exercise, the offensive team's report says it "used a signed system binary to run the payload" while the defensive team's report says it "saw suspicious child processes". Both describe the same activity, and management cannot tell that they match. What is the BEST fix for the next exercise?
- A.Have both teams label activity with named techniques from one shared catalogue, so the two accounts line up item by item✓ Answer
- B.Have the defensive team rewrite its account in the offensive team's wording, since the attacker's own description is authoritative
- C.Have both teams file their findings under a single incident number in the ticketing system, so that the two reports at least appear together
- D.Have management read the offensive report only, since the exercise was designed and executed by the team that ran the simulated attack
A shared technique catalogue exists precisely to give attack and defence a common vocabulary: when both sides record the same named behaviour, coverage and gaps become comparable. Filing under one ticket number, rewriting one report in the other's words, or reading only one side leaves the two descriptions unmapped.
Source: CompTIA CySA+ CS0-004 Objective 3.1; MITRE ATT&CK as common language for purple-team and detection workReport a problem with this question
4. A mail gateway quarantines a message whose attached document carries a macro. The macro has not run, no mailbox has opened it, and no host shows related activity. Using the seven-stage intrusion model, which stage does the observed evidence represent?
- A.Weaponization, because the macro and the document were paired together to produce a usable payload
- B.Exploitation, because a macro-bearing document inside the environment already amounts to code execution
- C.Delivery, because the tooling reached the target environment while execution is still pending✓ Answer
- D.Installation, because an attachment that reaches a mailbox has established a foothold in the environment
Delivery is the transmission of the weaponised payload to the target; the payload is present but nothing has executed. Weaponization happened earlier on the adversary's own systems, exploitation requires the macro to run against a weakness, and installation requires a foothold to be established.
Source: CompTIA CySA+ CS0-004 Objective 3.1; Lockheed Martin Cyber Kill Chain stage definitions (Delivery)Report a problem with this question
5. An analyst is asked to build a detection for every stage of the seven-stage intrusion model using only telemetry collected inside the defended environment. One stage cannot be covered that way. Which stage is it, and why?
- A.Reconnaissance, because scanning and public-source research never appear in the defender's own log data
- B.Weaponization, because it is carried out on the adversary's own systems and leaves no artefact on the defended network✓ Answer
- C.Command and control, because an encrypted channel cannot be recorded by any sensor on the internal network
- D.Actions on objectives, because theft of data looks identical to ordinary business file access in the logs
Weaponization takes place entirely in the adversary's own build environment, so the defender has no victim-side artefact to detect. Reconnaissance often does touch defender logs, command-and-control channels leave flow and DNS evidence even when encrypted, and actions on objectives can be distinguished with the right telemetry.
Source: CompTIA CySA+ CS0-004 Objective 3.1; Lockheed Martin Cyber Kill Chain — Weaponization occurs on adversary infrastructureReport a problem with this question
6. Macro-bearing attachments repeatedly execute on finance workstations; a scheduled task then relaunches the payload at every boot and the host begins contacting an external controller. Management will fund exactly one control. Which choice breaks the chain earliest, described correctly?
- A.Blocking the controller domains at the egress point, which stops delivery; a control at exploitation acts only once data is already leaving
- B.Blocking macro execution in mail-sourced documents, which stops exploitation; a control at command and control acts later✓ Answer
- C.Filtering inbound attachments by file type, which stops weaponization; a control there acts before the adversary has built the payload
- D.Removing the scheduled tasks nightly, which stops installation; a control at delivery acts only once the payload is already persistent
The staged model is useful because it shows where an intervention removes everything downstream. Stopping the macro from running defeats exploitation, so installation and command and control never happen. The other options mislabel their stages: egress blocking acts at command and control, task removal acts after installation, and attachment filtering acts at delivery, not weaponization.
Source: CompTIA CySA+ CS0-004 Objective 3.1; Cyber Kill Chain used for control placement (earliest effective intervention)Report a problem with this question
7. A review finds that an intruder entered with valid credentials bought from a broker, ran no malware, moved between cloud services using stolen tokens, and returned to reconnaissance repeatedly over six weeks. A manager wants the report laid out as the seven ordered stages. What is the BEST response?
- A.Report it as a full pass through all seven stages, because any successful intrusion must traverse each stage in turn
- B.Report only the stages with matching evidence and mark the intrusion incomplete, since missing stages mean the objective failed
- C.Recast the whole campaign as one exploitation stage, because credential misuse and token reuse are both forms of exploitation
- D.Explain that the activity loops and skips stages, so the ordered model imposes a sequence alien to this intrusion✓ Answer
A linear staging model is a planning aid, not a description of how real intrusions behave: identity-driven intrusions can skip weaponization, installation and malware entirely and revisit earlier activity many times. Forcing the evidence into a fixed order manufactures a narrative the data does not support, which is the classic misuse of the model.
Source: CompTIA CySA+ CS0-004 Objective 3.1; documented limitation of linear kill-chain models for non-malware, identity-based intrusionsReport a problem with this question
8. An investigation has exactly one confirmed detail: the hosting address the intruder's controller ran on. The team applies a four-vertex relationship model of intrusion analysis. What does that single detail let them do?
- A.Fix the intrusion at one point of an ordered stage model, since infrastructure appears at only a single stage there
- B.Establish the adversary's identity directly, since controller addresses are registered to the operator who uses them
- C.Pivot from that infrastructure to the capability it served and to other victims that contacted it, filling in the adversary picture✓ Answer
- D.Confirm that data was stolen, since a controller address in use proves that exfiltration happened over that channel
The core axiom of the four-vertex model is that any known vertex can be pivoted on to reveal the others, so a single infrastructure detail leads to the capability delivered through it and to other victims that touched it. Ownership records do not establish identity, infrastructure recurs across stages, and a controller address alone proves no data loss.
Source: CompTIA CySA+ CS0-004 Objective 3.1; Diamond Model of Intrusion Analysis — pivoting axiom across adversary, capability, infrastructure, victimReport a problem with this question
9. Three requests reach the analysis team in one week: (1) decide whether two intrusions share an operator, (2) find which adversary behaviours current detections miss, (3) show executives where one control would have stopped a campaign earliest. Which assignment of models fits?
- A.Staged intrusion model for (1), relationship model for (2), behaviour catalogue for (3), chosen by campaign order
- B.Behaviour catalogue for (1), staged intrusion model for (2), relationship model for (3), chosen by shared tooling
- C.Relationship model for (1), behaviour catalogue for (2), staged intrusion model for (3), chosen by analytic purpose✓ Answer
- D.Relationship model for (1), staged intrusion model for (2), behaviour catalogue for (3), chosen by stage coverage
Each framework answers a different question: the four-vertex relationship model links adversary, capability, infrastructure and victim for attribution and pivoting; the tactic-and-technique catalogue expresses behaviours and therefore detection coverage; the ordered stage model shows where an intervention breaks a campaign earliest. Swapping them produces analysis the chosen model cannot support.
Source: CompTIA CySA+ CS0-004 Objective 3.1; stated analytic purpose of Diamond Model, MITRE ATT&CK and Cyber Kill ChainReport a problem with this question
10. A team has always tagged behaviours with technique identifiers after an incident closes, purely as a reporting step. The new lead wants the catalogue used prospectively instead. Which use BEST reflects that intent?
- A.Add the technique identifier to every closed ticket, so that the quarterly report can count the techniques each team has observed
- B.Require a technique name before any alert may be escalated, so that every escalation carries a catalogue reference in it
- C.Choose techniques plausible for the organisation's threats and hunt for their traces in existing telemetry before any alert✓ Answer
- D.Replace the alert queue with the catalogue, so that analysts work through the techniques in numerical order each shift
Used prospectively, a behaviour catalogue supplies hunt hypotheses: pick behaviours a relevant adversary would plausibly use, then look for their traces in telemetry that already exists, with no alert required. Tagging closed tickets, gating escalation on a label, or working the matrix in numerical order are all retrospective or clerical uses.
Source: CompTIA CySA+ CS0-004 Objective 3.1; hypothesis-driven use of ATT&CK for hunting and exercise designReport a problem with this question
11. A draft report states that an intruder used a specific named credential-theft technique. The only supporting evidence is a spike of failed logins and a process that could not be identified before the host was rebuilt. What is the correct handling?
- A.Keep the named technique, since it is the commonest explanation for a login spike and gives the report something concrete
- B.Swap the technique for its parent tactic and treat the mapping as confirmed, since a tactic needs no supporting artefact
- C.Strip every framework reference out of the report, because a mapping counts only when a detection product produced it
- D.Record the behaviour as unconfirmed with the evidence behind it, because a named technique claims more than was seen✓ Answer
A framework mapping is a claim about evidence, so naming a technique asserts that the specific method was observed. With only a failed-login spike and an unidentified process, the honest record is the behaviour plus its evidence, marked unconfirmed. Forcing evidence to fit a label, or treating a tactic as evidence-free, corrupts later analysis built on the report.
Source: CompTIA CySA+ CS0-004 Objective 3.1; ATT&CK mapping guidance — confidence must reflect available evidenceReport a problem with this question
12. An analyst writes: "the goal was to obtain passwords; the method was reading them out of process memory; the specific implementation was a renamed copy of a signed dumping utility run from a temporary folder." How do those three descriptions map onto framework terms?
- A.The goal is the tactic, the method is the technique, and the renamed tool run from that folder is the procedure✓ Answer
- B.The goal is the technique, the method is the tactic, and the renamed tool is a sub-technique of that tactic
- C.The goal is the procedure, the method is the technique, and the tactic is the temporary folder the tool ran from
- D.All three are techniques at different levels, since tactics describe network activity rather than host activity
In a behaviour catalogue the tactic is the adversary's goal, the technique is how the goal is achieved, and the procedure is the concrete implementation a particular actor used. Tactics apply to host activity as much as to network activity, and a file path is never a tactic.
Source: CompTIA CySA+ CS0-004 Objective 3.1; MITRE ATT&CK definitions of tactic, technique and procedureReport a problem with this question
13. Midway through an investigation the team finds that the hosts of interest never forwarded process-creation events, and that proxy records roll off well before the suspected date of entry. Which statement BEST describes the failure?
- A.Detection failed, because the alert itself should have carried the process history the analyst needed
- B.Analysis failed, because the analyst should have rebuilt the sequence from surviving artefacts on disk
- C.Recovery failed, because restoring those hosts from backup would have returned the missing log data
- D.Preparation failed, because logging coverage and retention are set in advance and cannot be created mid-case✓ Answer
Deciding what is logged, from which hosts, and for how long is preparation work that must be done before an incident, because telemetry that was never collected cannot be recovered afterwards by any tool or technique. Backups restore system state, not audit records that were never generated or already aged out.
Source: CompTIA CySA+ CS0-004 Objective 3.2 (preparation phase); NIST SP 800-61r3 preparedness — logging and data collection decided in advanceReport a problem with this question
14. A correlation rule raises an alert for anomalous authentication. An analyst then confirms the sign-in was genuine attacker activity, identifies four other accounts the same source touched, and declares an incident. Which phases are represented, in order?
- A.The rule firing is analysis, and confirming and scoping are detection, since detection ends only once scope is known
- B.Both the rule firing and the confirmation are detection, and analysis begins only once containment is in place
- C.The rule firing is detection, and confirming the activity, scoping the accounts and declaring the case are analysis✓ Answer
- D.The rule firing is preparation, and confirming, scoping and declaring the case together form the detection phase
Detection is the surfacing of a possible incident, whether by a rule, a sensor or a report. Analysis is the separate phase in which the analyst validates true versus false positive, scopes what else is affected, classifies severity and declares the incident; that judgement work does not wait for containment.
Source: CompTIA CySA+ CS0-004 Objective 3.2 — detection and analysis listed as separate lifecycle phasesReport a problem with this question
15. An endpoint alert confirms a web shell on one internet-facing server. The duty manager wants the host isolated at once and the case closed. Before containment can be relied on, what must be true?
- A.The exploited vulnerability is patched first, because containment cannot hold while the flaw used for entry remains open
- B.The server is restored from the latest backup first, so the business service keeps running while the case is investigated
- C.The root cause is written up and signed off first, because no case may be contained before its cause has been agreed
- D.The scope is established first, since other hosts, accounts and cloud resources with the same foothold stay open✓ Answer
Containment only works against the whole intrusion, so scoping in the analysis phase must identify every affected host, account and cloud resource first; isolating one server while a second foothold survives simply lets the intruder return. Patching and restoring belong to eradication and recovery, and containment never waits for a signed root-cause statement.
Source: CompTIA CySA+ CS0-004 Objective 3.2 — scoping during analysis precedes containmentReport a problem with this question
16. Powering off a compromised application server would stop an active intrusion immediately, but it would also end the only running instance of a customer-facing service and destroy the running state the team needs to understand what happened. What does sound practice expect here?
- A.The analyst powers the host off at once, because stopping the damage outranks investigative value in any incident
- B.The analyst passes the decision to the platform team, because service availability is purely an operations matter
- C.The analyst leaves the host untouched until analysis ends, since containment must never alter a system under study
- D.The analyst escalates the trade-off to the incident lead and the business owner, to be weighed against the declared severity✓ Answer
Containment trades speed against business impact and investigative value, and that balance is set by the declared severity and by the people accountable for both sides: the incident lead and the business owner. An analyst acting alone either destroys understanding of the intrusion or leaves it running, and handing the call to operations removes the security judgement entirely.
Source: CompTIA CySA+ CS0-004 Objective 3.2 — containment decisions driven by severity classification and defined IR rolesReport a problem with this question
17. Malware is removed from eleven hosts within hours and service is restored the same evening. Nobody has yet established how the intruder first got in. Two days later the same malware appears on nine hosts. Which statement BEST explains the outcome?
- A.Eradication removed the symptom while the entry path stayed open, so the intrusion returned through the same cause✓ Answer
- B.Containment was never lifted, so malware held on the isolated segment re-entered the hosts when monitoring resumed
- C.Recovery moved too fast, so surviving copies of the malware came back from the backups restored onto the rebuilt hosts
- D.Detection was mistuned, so the second wave is the first infection being reported again rather than a real reinfection
Eradication must remove the threat and the condition that enabled it; deleting malware while the exploited service, exposed credential or missing control stays in place addresses the symptom only, and reinfection through the same path is the predictable result. That is why root cause must be understood before eradication is called complete.
Source: CompTIA CySA+ CS0-004 Objective 3.2 — eradication removes threat and root enabler before recoveryReport a problem with this question
18. The intruder's persistence mechanisms have been removed, the exploited service has been patched, and the affected credentials have been rotated. The team now wants the systems back in production. What must the recovery phase establish?
- A.That the restored systems work correctly and are watched for recurrence, from restore points predating the compromise✓ Answer
- B.That the case ticket is closed and a lessons-learned meeting is booked, since recovery ends the formal response process
- C.That every affected system was rebuilt from the vendor's original media, since a hardened image cannot be trusted again
- D.That the business owner accepts the residual risk in writing, since recovery hands over ownership of what exposure remains
Recovery returns systems to normal operation and then proves they deserve trust: functionality is validated, the restore point is confirmed to predate the compromise so the threat is not reintroduced, and heightened monitoring watches for recurrence. Closing the ticket and holding the review belong to post-incident activity, after recovery.
Source: CompTIA CySA+ CS0-004 Objective 3.2 — recovery validates restored systems and monitors for recurrenceReport a problem with this question
19. While the investigation continues, the team disables the intruder's two accounts, blocks the controller addresses at the egress firewall, and moves an affected cloud instance into a restricted network group. Into which phase does this work fall?
- A.Eradication, since disabling accounts and blocking addresses removes the intruder's tooling from the environment
- B.Containment in its immediate form, since the reach of the intrusion is being limited while the threat itself is still present✓ Answer
- C.Recovery, since the environment is returned to a safe operating state once those connections have been blocked
- D.Detection, since blocking addresses already known to be bad is how further malicious activity gets surfaced
Immediate or short-term containment limits the damage an active intrusion can still do without claiming to remove it: disabled accounts, blocked indicators and a quarantined cloud instance all cut reach while the threat and its enablers remain. Eradication removes the threat and its root enabler; recovery restores and validates service afterwards.
Source: CompTIA CySA+ CS0-004 Objective 3.2 — short-term (immediate) containment versus eradicationReport a problem with this question
20. A confirmed intrusion involves a legacy manufacturing application that cannot be patched for several months and cannot be taken offline without halting production. Immediate isolation of the affected segment is already in place. What does long-term containment mean in this case?
- A.A permanent acceptance of the risk, since an unpatchable application closes the response with a documented exception
- B.Compensating controls and network restriction that hold the risk down until remediation becomes possible✓ Answer
- C.Repeating the immediate isolation on a schedule until the vendor patch arrives and the application can be updated
- D.Rebuilding the application server weekly from an image, so that anything reintroduced is removed on a regular cycle
Long-term containment keeps the business operating while full remediation is still impossible: segmentation, tightened access paths, passive monitoring and other compensating controls hold the residual risk down until the application can be patched or replaced. It is a bridge to eradication, not a risk acceptance and not a schedule of repeated rebuilds.
Source: CompTIA CySA+ CS0-004 Objective 3.2 — long-term containment with compensating controls; OT availability constraintsReport a problem with this question
21. To restore service before the weekend, a team restores twenty servers from backup on Friday and plans to patch the exploited internet-facing flaw the following week. What is the MOST likely outcome?
- A.The restored servers are safe while the containment firewall rule stands, so the patching order does not matter here
- B.The restored servers are protected, because restoring from backup replaces the vulnerable component with a clean one
- C.The restored servers are exposed through the same flaw and are recompromised before the patch window arrives✓ Answer
- D.The restored servers cannot be reinfected, because the intruder's tooling was removed from every host before restore
Recovery may not run ahead of eradication: a backup carries the same unpatched software, so restoring first puts the identical exploitable surface back on the internet. A temporary containment rule is not a substitute for closing the flaw, and removing tooling does nothing about the way in.
Source: CompTIA CySA+ CS0-004 Objective 3.2 — eradication (patching the exploited weakness) precedes recoveryReport a problem with this question
22. A night-shift analyst believes one anomalous authentication warrants declaring a major incident and paging executives at 02:00. What governs whether that declaration is made?
- A.The analyst's own reading of severity, since the person closest to the evidence is best placed to declare
- B.The documented declaration criteria applied to the evidence, which set what qualifies and who may declare at each level✓ Answer
- C.The number of alerts the rule produced overnight, since volume is the agreed measure of significance
- D.The seniority of the affected user, since the importance of the account decides the level of the case
Declaration is a defined decision, not a matter of taste: the plan states the criteria an event must meet and the role authorised to declare at each level, which is what keeps night-shift escalation consistent and defensible. Alert volume and the affected user's rank may feed severity inputs, but neither is the criterion by itself.
Source: CompTIA CySA+ CS0-004 Objective 3.2 — incident declaration criteria and defined escalation authorityReport a problem with this question
23. Two cases are open: a file server that is unavailable but holds only public marketing files, and a quiet database that is still serving users while an intruder reads regulated customer records. The team's tiering scheme weighs functional impact, information impact and recoverability. How should the cases be ranked?
- A.The file server case ranks higher, because an outage is a measured impact while access to the data is only potential
- B.The database case ranks higher, because information impact and recoverability weigh alongside loss of function✓ Answer
- C.Both rank the same, because each case affects one system and severity follows the count of affected systems
- D.Ranking waits for root cause on both cases, because severity cannot be set before the cause is understood
Severity tiering combines functional impact, information impact and recoverability, so ongoing access to regulated records outranks the loss of a service whose data is public: the information impact and the difficulty of undoing disclosure dominate. Severity is assigned from observed impact during analysis, long before root cause is known.
Source: CompTIA CySA+ CS0-004 Objective 3.2 — severity and prioritisation by functional impact, information impact, recoverabilityReport a problem with this question
24. Analysis shows that an intruder read a directory containing personal customer records. The analyst drafts a notification email to the affected customers and asks the shift manager to send it. Why is that the wrong route?
- A.Notification runs through the communication plan and is issued by named owners, with legal and leadership involved✓ Answer
- B.Notification is unnecessary while systems remain contained, because no loss is confirmed until recovery has ended
- C.Notification goes through the service desk, which already owns every outbound contact with customers in the company
- D.Notification is the analyst's own duty, but it must wait until the case is closed and the final report is signed off
Who is told, by whom, how fast and in what detail is set by the communication plan and carried out by the named owners, because external notification carries legal, regulatory and reputational consequences an analyst is not positioned to weigh. The analyst's role is to supply verified facts into that process, not to originate the message.
Source: CompTIA CySA+ CS0-004 Objective 3.2 and Domain 4 — stakeholder identification and communication plan ownershipReport a problem with this question
25. Service has been restored and the case is formally closed. The incident lead schedules a review with everyone who took part. Beyond producing a written record of what happened, what should this phase deliver?
- A.A decision on who was at fault, so that individual accountability is recorded while the case is still fresh
- B.A closed ticket and disposal of the case material, so that the next case starts without legacy assumptions
- C.A restatement of the containment steps taken, so that exactly the same steps can be repeated in the next case
- D.Changes carried back into preparation: updated playbooks, revised detection rules, and control gaps with owners and dates✓ Answer
Post-incident activity exists to close the loop into preparation: the review turns what was learned into updated playbooks, better detections, and assigned corrective actions with dates, so the next response starts stronger. Fault-finding suppresses the candour the review depends on, and copying containment steps ignores that the next incident will differ.
Source: CompTIA CySA+ CS0-004 Objective 3.2 — post-incident activity feeds lessons learned back into preparationReport a problem with this question
26. Between incidents, a team tunes three noisy correlation rules, writes a playbook for business email compromise, and arranges standing read access to cloud audit logs for on-call analysts. Which phase is this work, and why does the timing matter?
- A.Preparation, since this capability has to exist beforehand and cannot be built while a live case is being worked✓ Answer
- B.Post-incident activity, since tuning and playbook writing only ever follow a case and close out the previous one
- C.Detection, since the work exists to make alerts fire and so belongs with the phase that surfaces malicious activity
- D.Analysis, since tuned rules and provisioned access are what let an analyst judge an alert once it has arrived
Preparation is the phase that builds capability before it is needed: tuned rules, written playbooks, pre-provisioned access, logging coverage and trained roles. None of it can be created mid-incident, when time pressure and changed systems make new instrumentation and new approvals impossible to obtain cleanly.
Source: CompTIA CySA+ CS0-004 Objective 3.2 — preparation phase scope (tooling, playbooks, access, alert tuning)Report a problem with this question
Practice questions based on the CompTIA CySA+ exam objectives. This site is not affiliated with or endorsed by CompTIA, and these are not real exam questions. CompTIA refreshes this exam periodically, runs two versions side by side during a transition, and sets the exam length, passing standard and eligibility terms — confirm the current objectives and the live exam code with CompTIA before you register. The real exam also includes performance-based items that a multiple-choice bank cannot reproduce, so pair this with hands-on practice. Official CySA+ exam objectives →