← Back

26 Incident Response Techniques Practice Questions & Answers

Every Incident Response Techniques practice question from the CompTIA CySA+ Practice Test, with the correct answer and a short explanation.

Start practice test →
  1. 1. At 08:05 four alerts open at once: an endpoint agent reports a credential-dumping tool writing to disk on a domain controller; a kiosk reports adware; the mail gateway reports one quarantined spam message; and an intrusion sensor matches a 2009 Linux exploit signature against a host that runs only Windows. Which alert should the analyst work first, and why?

    • A.The credential-dumping detection, because it is live behaviour on the identity tier and would widen access.✓ Answer
    • B.The exploit signature, because network sensors observe an attack earlier in its progress than endpoint agents do.
    • C.The kiosk adware detection, because a confirmed malware identification outranks behaviour that has not been proven yet.
    • D.The quarantined spam message, because email is the most common entry route and stopping it prevents later stages.

    Triage ranks alerts by how likely they are to be real and by what they would cost. Credential dumping on a domain controller is behavioural, hard to fake, and would let the intruder authenticate anywhere, while the adware, the quarantined message and a Linux signature fired against a Windows-only host are either low impact or plainly false positives.

    Source: CompTIA CySA+ CS0-004 Objective 3.3 (incident response techniques: triage and prioritization); NIST SP 800-61 detection and analysis, prioritization by functional and information impactReport a problem with this question

  2. 2. An analyst confirms a suspicious process on a finance workstation holding an established outbound connection. The service desk suggests rebooting the machine to clear it before the analyst continues. What should happen first, and why?

    • A.Capture the memory image, the process list and the open connections first, because a reboot destroys that live state for good.✓ Answer
    • B.Reboot the workstation so the process stops spreading, and image the disk once the machine is quiet again.
    • C.Run the endpoint agent cleanup routine to quarantine the file, then collect memory from the cleaned running host.
    • D.Disconnect the power to freeze the disk as it stands, then recover the process data from the pagefile afterwards.

    The process table, its parent relationship, injected code and the open socket exist only in volatile state. A reboot, a power cut or a cleanup routine removes the link between the process and the remote address, so volatile capture comes before any containment or cleanup step.

    Source: CompTIA CySA+ CS0-004 Objective 3.3 (evidence acquisition, order of volatility); RFC 3227 Guidelines for Evidence Collection and ArchivingReport a problem with this question

  3. 3. A responder has ten minutes on a live compromised host before a maintenance window forces a restart. Available items are the ARP cache and active connection table, a full disk image, the archived authentication logs on the log server, and last night's backup tape. Which does the responder collect first, and why?

    • A.The archived authentication logs, because rotation may remove them and they anchor the incident timeline.
    • B.The full disk image, because it is by far the largest artefact and a restart mid-acquisition would invalidate it.
    • C.The ARP cache and connection table, because that state exists only while the host is still running.✓ Answer
    • D.Last night's backup tape, because it preserves the host as it stood before the attacker made further changes.

    Order of volatility puts the most perishable data first. The ARP cache and connection table are gone the moment the host restarts, whereas the disk, the shipped logs and the tape all survive the restart and can be acquired afterwards.

    Source: RFC 3227 order of volatility; CompTIA CySA+ CS0-004 Objective 3.3 (evidence acquisition and preservation)Report a problem with this question

  4. 4. An analyst needs to examine a workstation suspected of hosting an active intruder. A colleague offers the domain administrator credentials so that every protected location on the host can be read. What should the analyst do?

    • A.Use the domain administrator credentials, because full rights are needed to read the protected areas of this host.
    • B.Use the local administrator password instead, because local credentials cannot be replayed against any other system.
    • C.Use an account with no rights elsewhere, or collect remotely, because an interactive logon exposes the credential.✓ Answer
    • D.Sign in as the affected user and elevate when prompted, so the activity blends into the normal session history.

    An interactive logon places the privileged credential in the memory of a machine the intruder may still control, so a domain administrator logon can hand over the whole directory. Collection is done with a scoped account that has no rights elsewhere, or remotely through an agent, and local administrator passwords are frequently reused across builds.

    Source: CompTIA CySA+ CS0-004 Objective 3.3 (incident response techniques: safe handling of compromised hosts); NIST SP 800-61 containment and analysis practicesReport a problem with this question

  5. 5. A user reports a phishing email. The analyst confirms an attacker holds an active session in the user's cloud mailbox and has created a hidden forwarding rule. What should the analyst do about the account first?

    • A.Revoke the active sessions and reset the credential out of band, then phone the user, because the attacker reads that mailbox.✓ Answer
    • B.Send instructions to the affected mailbox asking the user to change the password as soon as they read the message.
    • C.Leave the account untouched until the forensic timeline is finished so that the attacker's activity is not disturbed.
    • D.Publish a notice naming the affected mailbox so that colleagues stop replying to messages arriving from that account.

    An intruder inside the mailbox reads any warning sent to it, and a password reset on its own leaves live tokens and the forwarding rule working. The credential is reset and the sessions revoked first, the rule removed, and the user contacted on a channel the attacker cannot observe.

    Source: CompTIA CySA+ CS0-004 Objective 3.3 (containment: account and session containment, out-of-band notification)Report a problem with this question

  6. 6. A laptop may become evidence in a dismissal case that the company expects to be challenged. The analyst is about to acquire its drive. Which set of practices keeps the work defensible?

    • A.Boot the laptop from its own installation, export the folders of interest, and hash each exported file as the evidence.
    • B.Mount the original drive read-only in the analysis system, examine it in place, and hash the relevant files afterwards.
    • C.Attach the drive through a write blocker, take a bit-for-bit image, hash it, and examine only the verified copy.✓ Answer
    • D.Copy the user profile to a protected share, hash every file that was copied, and keep the laptop running for later work.

    A write blocker stops the acquisition from altering the source, a bit-for-bit image with a recorded hash proves the copy is faithful, and analysing only the copy leaves the original in the state in which it was seized for anyone who re-examines it. Booting the machine or exporting selected folders changes timestamps and loses unallocated space.

    Source: CompTIA CySA+ CS0-004 Objective 3.3 (evidence acquisition: write blockers, bit-for-bit imaging, hashing and validation)Report a problem with this question

  7. 7. Halfway through an examination the analyst must hand the evidence drive to a colleague on the next shift, and explains verbally what has been done so far. What is required for that handoff to survive later scrutiny?

    • A.An email to the case file sent after the shift, because a timestamped message shows when the handoff took place.
    • B.A custody log entry giving the date, the time, both names and the reason, signed by the two parties at handoff.✓ Answer
    • C.A fresh hash of the image stored after the handoff, which shows the drive stayed in authorised hands throughout.
    • D.A note added to the incident ticket at the end of the shift, because the ticket is the authoritative case record.

    Chain of custody is an unbroken written record of who held the evidence, when and why, and a transfer is documented and signed at the moment it happens. A later email, ticket note or re-hash cannot show who possessed the drive during the interval, which is exactly what an opposing party attacks.

    Source: CompTIA CySA+ CS0-004 Objective 3.3 (evidence handling: chain of custody); NIST SP 800-86 guidance on documenting evidence transfersReport a problem with this question

  8. 8. Three responders ran commands on an affected server during a response. Two weeks later the report asks why a service was stopped and when, and nobody can say. Why does a contemporaneous log of responder actions matter?

    • A.It demonstrates that the responders held the qualifications required for the work performed on the affected server.
    • B.It lowers the mean time to respond, because a later shift can repeat exactly the same commands without reading again.
    • C.It removes the need for a separate custody record, because one log then covers evidence handling and analysis alike.
    • D.It lets the investigation tell changes made by responders apart from changes made by the intruder, so the findings hold up.✓ Answer

    Responders change the system they are investigating. A log of who ran what, at what time and for what reason lets each change be attributed correctly, which stops responder activity being written up as attacker activity and keeps the conclusions defensible.

    Source: CompTIA CySA+ CS0-004 Objective 3.3 (documentation of response actions); NIST SP 800-61 incident documentationReport a problem with this question

  9. 9. A programmable controller on a production line is beaconing to an external address every five minutes. Plant management states the controller cannot be powered off or unplugged during the run, which has eleven hours left. What containment should the analyst apply?

    • A.Shut the controller down at the next scheduled break, accepting the delay because output has to be protected.
    • B.Apply rules permitting only the required control traffic, block the beacon destination, and monitor the host closely.✓ Answer
    • C.Leave the controller alone and compensate with extra detection rules on the neighbouring hosts and at the network perimeter.
    • D.Reimage the controller while it continues to run, so the malware is removed without breaking the control loop.

    When a system cannot be taken out of service, containment becomes a compensating control: restrict its traffic to what the process genuinely needs, cut the command channel, and raise monitoring. That stops the bleeding without halting production, whereas doing nothing leaves the channel open and reimaging a live controller is not a containment action.

    Source: CompTIA CySA+ CS0-004 Objective 3.3 (containment options and segmentation); compensating controls for systems that cannot be taken out of serviceReport a problem with this question

  10. 10. Endpoint telemetry shows an interactive intruder session on a server: commands are being typed in real time. The analyst must contain the host while keeping the evidence and without announcing the response. Which action fits best?

    • A.Power the host off immediately, so the intruder loses the session before noticing the response.
    • B.Disable the network interface or move the host to a quarantine segment and leave it running.✓ Answer
    • C.Block the command-and-control address at the perimeter firewall and leave the host connected.
    • D.Change the local administrator password on the host, cutting the access without any downtime.

    Cutting the network at the interface or by quarantine VLAN ends lateral movement and exfiltration while memory, running processes and the session state survive for capture. Powering off destroys that volatile evidence, a single firewall block leaves the host free to move internally, and a password change does not end an established session.

    Source: CompTIA CySA+ CS0-004 Objective 3.3 (containment: isolation and quarantine versus destructive actions)Report a problem with this question

  11. 11. After a cloud account compromise the team reset the user's password six hours ago, yet the attacker is still sending mail and reading files from the same account. Which explanation and fix is correct?

    • A.Directory replication delays a password change, so the attacker is going to lose the access within a day anyway.
    • B.Session and refresh tokens already issued outlive a password change, so they must be revoked and the device re-enrolled.✓ Answer
    • C.The attacker must be using a second account, so the reset worked and the hunt should move to that other account.
    • D.Multi-factor authentication was probably not enforced, so enabling it now ends the attacker's current session.

    Session and refresh tokens are issued independently of the password and stay valid until they are explicitly revoked, so a reset alone leaves the intruder signed in. Containment of a cloud identity means revoking tokens, removing added authentication methods and re-enrolling the device as well as resetting the credential.

    Source: CompTIA CySA+ CS0-004 Objective 3.3 (containment in cloud and hybrid environments: session and token revocation)Report a problem with this question

  12. 12. Attacker tooling recovered from one server contains the plaintext password of a service account used by several automated jobs. The manager asks how far the incident scope now reaches. Which statement is correct?

    • A.The server where the tooling was recovered is in scope, because that is the place where the password was exposed.
    • B.Systems documented as using the account are in scope, since undocumented use of a service account is unlikely.
    • C.Hosts that logged a successful logon by the account inside the incident window are in scope, and no others are.
    • D.Every system, application and job where that credential was valid is in scope until each one has been cleared.✓ Answer

    A credential is not bound to the host where it was found. Scoping follows the credential, so every system, service and scheduled job that would accept it has to be examined and cleared, and the absence of a logged success proves only that logging was incomplete.

    Source: CompTIA CySA+ CS0-004 Objective 3.3 (scoping the incident and impact analysis before declaring containment)Report a problem with this question

  13. 13. A workstation was cleaned after malware was quarantined, and it ran normally all day. At 03:00 the same malware reappears, and it has now done so at 03:00 on each of the last three nights. What does this indicate?

    • A.The detection signature is incomplete, so a full scan with an updated engine will put an end to the reinfections.
    • B.The user reopens the original attachment every morning, so awareness training is what will resolve the problem.
    • C.The sample was quarantined instead of deleted, so clearing out the quarantine store stops it from coming back.
    • D.A scheduled task, service or autorun entry is fetching the payload again and has to be found and removed.✓ Answer

    Reinfection on a fixed schedule is the signature of a persistence mechanism, not of a weak signature. Eradication has to remove the scheduled task, service or autorun entry that re-downloads the payload, and close the exploited root cause, or the host keeps reinfecting itself.

    Source: CompTIA CySA+ CS0-004 Objective 3.3 (eradication: removal of persistence mechanisms and root cause)Report a problem with this question

  14. 14. The earliest confirmed attacker activity on a file server is 14 March, established from authentication and process evidence. Nightly backups exist for the last thirty days, and the business asks for the 2 April set because it is the newest. What should the team do?

    • A.Restore a set predating 14 March and reapply validated data changes, because later sets may carry the intrusion.✓ Answer
    • B.Restore the newest set from 2 April, because it returns the most current data to the business at once.
    • C.Restore the 2 April set and scan it with an updated engine, which removes whatever the attacker left behind.
    • D.Restore and reconnect the 2 April set in the same segment, watching it for a week before it is trusted again.

    Any backup taken after the first confirmed attacker activity can contain the implant, the attacker's accounts or their changes, so restoring it reintroduces the compromise. Recovery starts from a known-good point that predates the intrusion, and needed data changes are reapplied after validation.

    Source: CompTIA CySA+ CS0-004 Objective 3.3 (recovery: restoration from a known-good state); NIST SP 800-61 recovery guidanceReport a problem with this question

  15. 15. Eradication is finished on a compromised application server: it was rebuilt from a golden image, patched and hardened. The manager wants it back in the load balancer pool immediately. What should the analyst insist on?

    • A.Verify the remediation, confirm the indicators are absent, and then release the host with heightened monitoring.✓ Answer
    • B.Reconnect it now and rely on the endpoint agent to raise an alert if any of the earlier activity returns.
    • C.Reconnect it now, because a rebuild from a golden image removes the attacker's artefacts by definition.
    • D.Keep it isolated until the post-incident report has been signed off, then reconnect it in the next change window.

    Recovery includes an explicit verification step before release from isolation: confirm the remediation worked and the indicators are gone, then restore service under closer monitoring than normal. A rebuild can faithfully restore the same vulnerable configuration, and waiting for a signed report needlessly extends the outage.

    Source: CompTIA CySA+ CS0-004 Objective 3.3 (recovery: validation of remediation and release from isolation)Report a problem with this question

  16. 16. A post-incident review establishes this chain: a contractor clicked a phishing link and entered credentials; the attacker signed in to the remote access service, which required no second factor; an unpatched server then allowed lateral movement. Which finding is the root cause of the unauthorized access?

    • A.The contractor entering credentials on the phishing page, which is the first event on the incident timeline.
    • B.The missing patch on the server, which is what allowed the attacker to reach other systems from there.
    • C.The attacker's use of a valid account, which made the malicious sign-in look like ordinary contractor work.
    • D.The lack of a second authentication factor on remote access, which let a stolen password work on its own.✓ Answer

    Root cause is the condition that made the compromise possible, not the first event in the sequence. The stolen password only worked because remote access accepted a single factor, so the corrective action is enforcing multi-factor there; the missing patch explains later movement rather than the initial access.

    Source: CompTIA CySA+ CS0-004 Objective 3.3 (post-incident activity: root cause analysis and corrective action)Report a problem with this question

  17. 17. Counsel notifies the security team that litigation involving a departing employee is reasonably anticipated and names that employee's laptop. Operations has the laptop scheduled to be reimaged today for reissue. What must happen?

    • A.Rebuild the laptop today and retain the antivirus logs, which document everything the investigation will need.
    • B.Preserve the laptop and its forensic image under the hold, and postpone the rebuild until counsel releases it.✓ Answer
    • C.Record the drive hash and then reimage, which allows the original contents to be reconstructed at a later stage.
    • D.Export the user's documents and then reimage, since the exported copies satisfy the duty to preserve the material.

    A legal hold suspends normal retention and disposal and overrides the operational wish to wipe and reissue the device, so the analyst's authority to remediate stops there. Exported documents, antivirus logs and a recorded hash preserve none of the unallocated space, artefacts or device state the litigation may require.

    Source: CompTIA CySA+ CS0-004 Objective 3.3 (evidence preservation: legal hold and its effect on remediation)Report a problem with this question

  18. 18. At 14:00 an analyst concludes that the only containment that fully stops an active intrusion is taking the customer-facing payment service offline. The analyst has no authority over that service. What is the correct next step?

    • A.Take the service offline at once, because containment authority rests with the analyst who declared the incident.
    • B.Escalate the shutdown decision to the incident commander and the business owner, while applying the limited containment available.✓ Answer
    • C.Wait for the payment vendor's written guidance before any containment step, because a third-party system is involved.
    • D.Record the recommendation in the incident channel and keep investigating until somebody else decides to act on it.

    Stopping a revenue-generating service is a business decision that sits above the analyst's authority, so the analyst escalates with the recommendation, the impact and the alternatives and lets the incident commander and business owner decide. Meanwhile the containment the analyst is authorised to apply goes in, because doing nothing while waiting lets the intrusion continue.

    Source: CompTIA CySA+ CS0-004 Objective 3.3 (escalation criteria and authority boundaries during response)Report a problem with this question

  19. 19. A cloud virtual machine is confirmed compromised. It has an attached identity role that grants access to storage, and the team needs containment that keeps the evidence available. Which set of actions is best?

    • A.Detach the volume for imaging and stop the instance, preserving the disk and ending the intruder's access to it.
    • B.Terminate the instance and let the scaling group replace it, which removes the intruder from the environment entirely.
    • C.Snapshot the volume, move the instance into an isolating security group, and revoke the role's active sessions.✓ Answer
    • D.Rotate the administrative credentials and leave the instance running so that the traffic can be observed longer.

    The snapshot preserves the disk state, an isolating security group cuts traffic without destroying the instance or its memory, and revoking the role's sessions removes the credential the intruder was actually using. Terminating the instance destroys the evidence, and stopping it discards volatile state that has not been captured.

    Source: CompTIA CySA+ CS0-004 Objective 3.3 (containment and evidence acquisition in cloud environments: snapshots, isolation, role session revocation)Report a problem with this question

  20. 20. An alert fires on a container that the orchestrator has already destroyed and replaced; it ran for four minutes. Nothing of the container's filesystem or memory remains on the cluster. What is the best source of evidence now?

    • A.Re-run the same image in the cluster to reproduce the behaviour and capture memory from the new container.
    • B.Image the worker node's disk, because the destroyed container's filesystem stays there until the node reboots.
    • C.Ask the provider for a hypervisor memory capture of the deleted container, which they retain for their customers.
    • D.Collect the control-plane audit records and the shipped container logs, and pull the image with its provenance.✓ Answer

    Ephemeral workloads leave their evidence outside the container: control-plane audit records show what was scheduled and by whom, forwarded logs hold the runtime output, and the image and its registry provenance show what actually ran. Re-running the image creates new data instead of preserving what happened, and providers do not keep memory of deleted workloads for customers.

    Source: CompTIA CySA+ CS0-004 Objective 3.3 (evidence acquisition limits for containerized and ephemeral cloud workloads; shared responsibility)Report a problem with this question

  21. 21. A playbook automatically isolates any host with a medium-confidence detection. Last week it isolated a domain controller and a payment gateway on detections that both turned out to be false. What change is best?

    • A.Keep the automated enrichment and ticketing, but require analyst approval before isolating a critical host.✓ Answer
    • B.Disable the playbook and return host isolation to a manual queue worked by the on-call analyst each shift.
    • C.Exempt the two systems that were isolated last week and keep the automatic isolation everywhere else.
    • D.Raise the trigger so that only high-confidence detections isolate a host, and keep the step fully automatic.

    Automation should run freely on enrichment, ticketing and notification, but a destructive or business-impacting action needs a human decision point, especially on a low-confidence detection or a critical system. Raising the threshold alone still lets automation take a payment gateway offline, and switching everything back to manual throws away the speed the playbook was built for.

    Source: CompTIA CySA+ CS0-004 Objective 3.3 with the V4 automation and orchestration content (human approval gates for destructive or high-impact actions)Report a problem with this question

  22. 22. An artificial intelligence assistant summarises an intrusion, names one host as the origin, and recommends isolating forty hosts it says are affected. The analyst has not yet read the underlying telemetry. What should the analyst do?

    • A.Isolate the forty hosts now, since the assistant read more telemetry than an analyst could read in the time.
    • B.Check the assistant's conclusions against the source telemetry before acting, because generated findings can be unsupported.✓ Answer
    • C.Discard the summary and restart the triage by hand, because generated output cannot enter an investigation record.
    • D.Send the summary to leadership as the incident assessment and begin isolating the hosts that it has identified.

    Generated summaries can assert conclusions the telemetry does not support, so their output is investigative input rather than authority. The analyst validates the named host and the affected list against the source data before an action with real business impact, and the assistant's work is still usable once it has been checked.

    Source: CompTIA CySA+ CS0-004 (V4 artificial intelligence content applied to Objective 3.3: analyst verification of generated findings before response action)Report a problem with this question

  23. 23. Before any image was taken, a junior analyst ran a temporary-file and browser cleanup utility on a suspect workstation, believing it would help. What is the consequence, and what should be done now?

    • A.Only unallocated space was touched; the timeline holds and the image will still show all of the user activity.
    • B.The workstation is now clean; imaging can proceed and the analysis continues from the data that remains.
    • C.Timeline artefacts have been destroyed; record the action and its time, and note the gap in the report.✓ Answer
    • D.The utility's own log replaces what it removed; the timeline can be rebuilt from that record instead of the disk.

    Cleanup utilities delete and overwrite exactly the artefacts a timeline is built from, including temporary files, browser history and access timestamps, and nothing recovers them. The correct response is to document the action, its author and its time, then state the evidentiary gap in the findings so the report is not built on an unexplained hole.

    Source: CompTIA CySA+ CS0-004 Objective 3.3 (evidence preservation; documenting responder actions and evidentiary gaps)Report a problem with this question

  24. 24. One host has been isolated and its malware removed. Proxy logs show the same beacon domain contacted from four hosts in three other subnets during the same period. The manager wants the incident declared contained. What is the correct position?

    • A.Containment is incomplete until every host contacting that domain has been identified and isolated or cleared.✓ Answer
    • B.Containment can be declared as soon as the beacon domain is blocked at the proxy for the whole company.
    • C.Containment holds for the confirmed host, and the other subnets should be opened as a separate new incident.
    • D.Containment can be declared once the isolated host is rebuilt, because it was the source of the beacon traffic.

    Containment is declared against the scope of the incident, not against one host, so the four hosts showing the same indicator have to be identified and either isolated or cleared first. Blocking the domain at the proxy suppresses one channel while leaving the intruder's foothold and any second channel in place.

    Source: CompTIA CySA+ CS0-004 Objective 3.3 (scoping and impact analysis before declaring containment)Report a problem with this question

  25. 25. An internet-facing application is being exploited through a flaw for which the vendor patch is two weeks away, and the service cannot be taken down. Which pair of containment steps is correct?

    • A.Increase the monitoring and leave the application unchanged until the vendor patch arrives and has been tested.
    • B.Take the application offline for the two weeks, because only removing the service really stops the exploitation.
    • C.Block the exploit path at the reverse proxy now as short-term containment, and plan the patch and a design fix as long-term.✓ Answer
    • D.Rebuild the server from a golden image each night until the patch arrives, clearing whatever was left behind.

    Short-term containment stops the exploitation immediately with a compensating control such as filtering the exploit path, while long-term containment is the permanent fix applied under change control once the patch exists. Watching without acting leaves the flaw exploitable, and nightly rebuilds neither block the exploit nor address its cause.

    Source: CompTIA CySA+ CS0-004 Objective 3.3 (short-term versus long-term containment and compensating controls)Report a problem with this question

  26. 26. An analyst records the SHA-256 value of a disk image at acquisition, copies the image to an analysis workstation, and hashes it again. The two values differ. What should the analyst do?

    • A.Continue the analysis and record the new value, which from now on identifies the working copy that is in use.
    • B.Hash the copy with a second algorithm and continue if that value matches the originally recorded value.
    • C.Treat compression during transfer as the cause and verify only the individual files that matter to the case.
    • D.Stop, document the mismatch and re-acquire or re-copy, because the working copy is not a faithful duplicate.✓ Answer

    The hash is the integrity control on the copy, so a mismatch means the working copy is not identical to what was acquired and it must not be analysed or reported on. The mismatch is documented and the copy is made again, because hashing a bad copy with another algorithm only produces a second value for the wrong data.

    Source: CompTIA CySA+ CS0-004 Objective 3.3 (data integrity validation: hashing at acquisition and re-verification after transfer)Report a problem with this question

Practice questions based on the CompTIA CySA+ exam objectives. This site is not affiliated with or endorsed by CompTIA, and these are not real exam questions. CompTIA refreshes this exam periodically, runs two versions side by side during a transition, and sets the exam length, passing standard and eligibility terms — confirm the current objectives and the live exam code with CompTIA before you register. The real exam also includes performance-based items that a multiple-choice bank cannot reproduce, so pair this with hands-on practice. Official CySA+ exam objectives →