Free daily set, then full-bank Pro when you want more
Question 1 of 10
Objective 1.15Security Operations
Which of the following is a primary goal of the 'Identify' function in the NIST Cybersecurity Framework?
Correct Answer: B. To understand the organization's risks and assets
Concept tested: Use the NIST Cybersecurity Framework to organize security operations outcomes
A. × Incorrect: The 'Identify' function focuses on understanding an organization's risk profile, not just incident response policies.
B. ✓ Correct: This because the Identify function aims to understand and manage risks by identifying assets, threats, and vulnerabilities.
C. × Incorrect: Preventing cyber attacks falls under the Protect function, not Identify.
D. × Incorrect: Data recovery procedures are part of the Recover function, not Identify.
Why this matters:This matters because understanding an organization's risks and assets is crucial for effective cybersecurity planning and resource allocation.
Question 2 of 10
Objective 4.4Reporting and Communication
What should an action-oriented vulnerability report include so remediation blockers are visible?
Correct Answer: D. Action plans, inhibitors to remediation, metrics, key performance indicators, and stakeholder communication
Concept tested: Reporting and Communication
A. × Incorrect: It only includes raw packet bytes without any context that would help in understanding or addressing vulnerabilities.
B. × Incorrect: A screenshot of a scanner color scale does not provide actionable information for remediation.
C. × Incorrect: Unrelated exploit code snippets do not contribute to creating an effective vulnerability report.
D. ✓ Correct: It includes action plans, inhibitors to remediation, metrics, key performance indicators, and stakeholder communication, which are essential for addressing vulnerabilities effectively.
Why this matters:This matters because a comprehensive vulnerability report ensures that all necessary information is available for timely and effective remediation.
Question 3 of 10
Objective 2.4Vulnerability Management
What is the purpose of the OWASP Web Security Testing Guide (WSTG) project?
Correct Answer: C. To produce a guide for web application security testing
Concept tested: Vulnerability Management
A. × Incorrect: It focuses on tool creation rather than guidance.
B. × Incorrect: Its primary goal is not secure coding practices but testing.
C. ✓ Correct: It produces a guide for web application security testing.
D. × Incorrect: It pertains to training, not the project's main output.
Why this matters:This matters because understanding the WSTG's purpose helps in effectively using its resources for secure testing.
Keep the momentum
You're 3 questions in. Want the full bank?
Unlock the full question set, timed exam mode, practice mode, saved progress, previous tests, and readiness scoring.
164 more questions, timed exam mode, and saved history are waiting in the full unlock.
Pro is active. Use the full bank, Exam mode, and saved box scores when you want deeper review.
Question 4 of 10
Objective 3.7Incident Response Management
What does NIST SP 800-34 Rev. 1 recommend for maintaining the resilience of an information system?
Correct Answer: C. Contingency planning
Concept tested: Incident Response Management
A. × Incorrect: Helps with security but does not directly address resilience.
B. × Incorrect: Enhances data protection, not necessarily the overall system resilience.
C. ✓ Correct: Contingency planning involves creating recovery strategies and procedures to maintain system operations during disruptions.
D. × Incorrect: Improve compliance and oversight but do not specifically focus on maintaining system resilience.
Why this matters:This matters because understanding resilience strategies ensures that systems can recover quickly from incidents, minimizing downtime and preserving critical functions.
Question 5 of 10
Objective 1.8Security Operations
An adversary has modified lifecycle policies in a cloud storage environment to automatically delete all objects stored within after a certain period of time. What is the primary impact of this action on the organization's data integrity and availability?
Correct Answer: A. Data destruction leading to loss of critical business information
Concept tested: Analyze host and service interruption indicators
A. ✓ Correct: Data destruction leading to loss of critical business information directly matches the Analyze host and service interruption indicators concept tested in the question.
B. × Incorrect: Increased network traffic due to unauthorized access attempts is related, but it does not answer what this question asks about Analyze host and service interruption indicators.
C. × Incorrect: Enhanced security through regular data purging practices is related, but it does not answer what this question asks about Analyze host and service interruption indicators.
D. × Incorrect: Improved system performance by freeing up storage space is related, but it does not answer what this question asks about Analyze host and service interruption indicators.
Why this matters:This matters because understanding the impact of lifecycle policy modifications on cloud storage helps organizations protect against data loss and maintain operational continuity.
Question 6 of 10
Objective 4.2Reporting and Communication
Which vulnerability management reporting content helps stakeholders track remediation work?
Correct Answer: C. Compliance reports, action plans, inhibitors to remediation, metrics, key performance indicators, and stakeholder communication
Concept tested: Reporting and Communication
A. × Incorrect: Packet capture decoding and TCP stream reassembly are forensic techniques, not reporting content.
B. × Incorrect: Forensic disk imaging and volatile memory capture are investigative methods, not part of vulnerability management reporting.
C. ✓ Correct: Compliance reports, action plans, inhibitors to remediation, metrics, KPIs, and stakeholder communication provide essential information for tracking remediation work.
D. × Incorrect: Reconnaissance tactic numbering from an attack matrix does not help stakeholders track remediation efforts.
Why this matters:Projects run smoother when the right information reaches the right stakeholder in a usable format.
Question 7 of 10
Objective 2.6Vulnerability Management
Which of the following metrics is used in CVSS to assess the severity of a vulnerability?
Correct Answer: B. Base Metrics
Concept tested: Vulnerability Management
A. × Incorrect: It refers to metrics that consider temporal factors like exploitability and remediation.
B. ✓ Correct: Base Metrics assess the inherent characteristics of a vulnerability without considering environmental factors.
C. × Incorrect: It involves customizing the base metrics based on specific organizational needs, not assessing severity directly.
D. × Incorrect: While impact metrics are part of CVSS, they specifically measure the consequences rather than the overall severity.
Why this matters:This matters because understanding base metrics helps in accurately evaluating a vulnerability's inherent risk before considering external factors.
Question 8 of 10
Objective 3.3Incident Response Management
Which version of the OWASP Web Security Testing Guide should you reference if you need to ensure compatibility with a report written in April 2020?
Correct Answer: B. v4.1
Concept tested: Use OWASP testing guidance for web incident context
A. × Incorrect: The v4.3 version is not applicable as it was unreleased at the time of April 2020.
B. ✓ Correct: The v4.1 version because it serves as a post-migration stable version under the new GitHub repository workflow and was released in April 2020.
C. × Incorrect: The v4.2 version because although it introduces updates, it was released after April 2020.
D. × Incorrect: Version v3 because it predates the changes made to the project's workflow and does not align with reports written post-April 2020.
Why this matters:This matters because referencing the correct version ensures consistency in security testing methodologies and findings.
Question 9 of 10
Objective 1.12Security Operations
An organization is reviewing MITRE ATT&CK tactics to understand how threat actors gather information about their target's network security appliances. Which tactic would best help the organization identify this type of reconnaissance activity?
Correct Answer: A. Reconnaissance
Concept tested: Compare threat actor tactics, techniques, and procedures
A. ✓ Correct: Reconnaissance because it includes techniques such as 'Gather Victim Network Information' which covers network security appliances.
B. × Incorrect: Persistence because it deals with maintaining access to a system over time, not gathering initial information about the target's environment.
C. × Incorrect: Credential Access because this tactic focuses on stealing or accessing existing credentials rather than discovering network security details.
D. × Incorrect: Impact because it involves actions that cause disruption or damage, unrelated to reconnaissance activities.
Why this matters:This matters because understanding Reconnaissance tactics helps organizations identify and mitigate early-stage attacks by recognizing how adversaries gather critical information about their targets.
Question 10 of 10
Objective 4.3Reporting and Communication
When prioritizing vulnerabilities for a company's risk management team, which CVSS v4 metric group should you adjust to reflect the unique characteristics of your organization’s environment?
Correct Answer: C. Environmental
Concept tested: Communicate vulnerability priorities using severity, exploitability, and asset context
A. × Incorrect: The Base metric group because it represents intrinsic qualities that are constant over time and across user environments, not tailored to a specific organization.
B. × Incorrect: The Threat metric group because it reflects characteristics of a vulnerability that change over time but does not tailor severity to an individual environment's unique conditions.
C. ✓ Correct: Environmental because this metric group represents the characteristics of a vulnerability that are unique to a user's environment and allows for tailoring severity based on specific organizational factors.
D. × Incorrect: Supplemental metrics do not modify the final score, so they cannot be used to adjust severity in relation to an organization’s unique context.
Why this matters:This matters because accurately reflecting an organization's unique characteristics is crucial for effective risk management and prioritization of vulnerabilities.
Free preview complete
You've reached the free preview.
Go beyond sample questions with the full source-backed bank, objective practice, exam mode, saved progress, and readiness scoring.
174 verified questions are ready behind the full unlock.
Pro is active. Use the full bank, readiness score, and saved exams when you want deeper reps.
Ready to finish?Answer the questions, then submit your test for review.
Go Pro
Unlock the full CS0-003 bank.
Get the full source-backed bank, timed exam mode, practice mode, saved progress, previous tests, and readiness scoring for this exam.
174 full-bank questionsEvery choice explainedExam Mode and Practice ModeQuestion sets and random testsReadiness score and trendsPrevious test box scores
You've answered 0/10 free questions today.
Locked: 164 more questions in the full bank.
Locked: exam simulation mode and end-of-exam review.
Today's free set refreshes soon. Upgrade to continue with the full bank.
Box scores, domain breakdowns, and full answer explanations for Pro exam attempts on this browser.
Today’s Set
10 questions
Daily set rotates at 10:00 AM local time
Progress
0/10
Answered on this page session
Accuracy
0%
Loading countdown…
7-day score keeper
Answer questions today and this will become a rolling 7-day scorecard.
Local history
Optional progress sync
Keep today’s practice moving
Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily CS0-003 practice in sync across browsers.
Guest progress saves on this device automatically
174 verified questions are currently in the live bank. Questions updated at May 13, 2026, 1:57 PM CDT. The daily set rotates at 10:00 AM local time, and each explanation links back to the source used to write it. Use the web set for quick practice, then switch to the app when available for larger banks and deeper review.
Careers and fields this exam supports
CySA+ fits analyst-style security roles where detection, triage, vulnerability management, and response judgment matter more than pure fundamentals.
Role examples: SOC analyst, threat detection analyst, blue-team practitioner, and security operations engineer.
Where it shows up: security monitoring, incident response, vulnerability management, and defensive operations.
On-the-job payoff: you already know the basics and want more analyst-style scenario judgment.
Typical next step: It usually builds on Security+ and pairs with network or cloud-security depth.
dotCreds builds CySA+ practice questions from CompTIA documentation, standards, and source-backed references, with official or primary sources preferred first. The questions are written for realistic study practice, not copied from exam dumps.
How are explanations sourced?
Each question includes a source-backed explanation and a link to the documentation or reference used to validate the answer. If an official page is too broad, dotCreds uses a reputable answer-level reference instead of pretending a generic page proves the answer.
What score do I get?
The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.
Why use this site?
The site is the fastest way to start CySA+ practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.
Why use the app when available?
The web page is the quick free sampler. If a dotCreds app is available for CySA+, the app is better for larger banks, focused weak-domain drills, longer review sessions, and mobile study routines.
Related practice tests
If you want another cert after CySA+, these pages keep the same daily-question format with source-backed explanations.