All certifications / CySA+ / Cheat sheet
CySA+ CS0-004 cheat sheet
Domain 1: Security operations (34%)
Exam tips
- If a scenario stresses remote users and cloud apps with networking and security delivered from the cloud, choose SASE. If it stresses verifying every request regardless of location, choose zero trust. The customer always owns data and configuration in the cloud.
- OAuth is authorization; SAML and OpenID Connect handle authentication. When a question asks how to remove standing admin rights, choose just-in-time access rather than simply adding MFA or PAM.
- Know the most tested IDs: 4624 success, 4625 failure, 4688 process creation, 4720 account created, 4732 group membership change, 1102 log cleared, 7045 service installed, and Sysmon 1 process creation and 3 network connection. Syslog level 0 is the most severe.
- Regular intervals to one rare destination point to beaconing; one source touching many internal hosts on the same port points to a sweep or lateral movement; large outbound volume at odd hours points to exfiltration. A port number alone never proves the protocol.
- A correct system name in the wrong folder or under the wrong parent is masquerading. Event 7045 means a new service was installed, and always look for more than one persistence mechanism before declaring a host clean.
- A payload in a log proves an attempt, not success. Look at the response code, response size and what the same source did next. Decode first, then match the pattern: quote plus SQL keyword for SQLi, script tags for XSS, ../ for traversal.
- SIEM aggregates and correlates; SOAR automates response across tools; EDR sees and acts on a single host. A clean sandbox result does not prove a file is safe, because some malware detects virtual environments.
- SPF checks the sending server, DKIM checks integrity and the signing domain, DMARC checks alignment with the visible From and sets policy. Received headers are read from the bottom up, and passing all three does not prove a message is safe.
- STIX is the data format and TAXII is the transport; mixing them up is a common exam trap. TTPs sit at the top of the pyramid of pain because they are hardest for attackers to change.
- Hunting is proactive and starts with a hypothesis; incident response is reactive and starts with an alert. Any access to a honeypot or honeytoken is suspicious because it has no legitimate use, and active defense never means hacking back.
- Automation is a single task; orchestration ties many tasks and tools together. Standardize before you automate, tune with narrow exceptions rather than disabling rules, and for AI questions choose protecting sensitive data and validating output.
Key terms
- Shared responsibility model
- The division of security duties between a cloud provider, which secures the underlying infrastructure, and the customer, which secures its data, identities and configuration.
- Serverless
- A cloud model where code runs only when triggered and the provider manages all servers, so security focuses on permissions, inputs and dependencies.
- Container
- A lightweight package of an application and its libraries that shares the host operating system kernel.
- Microsegmentation
- Applying security policy between individual workloads rather than only between large network zones.
- Zero trust
- A model that verifies every access request in context and grants least privilege, regardless of network location.
- Policy enforcement point
- The zero trust component in the data plane that allows or blocks a connection based on the policy engine's decision.
- SASE
- Secure Access Service Edge, a cloud-delivered combination of SD-WAN and security services such as secure web gateway, CASB, firewall as a service and ZTNA.
- MFA
- Multifactor authentication, which requires factors from at least two different categories: know, have and are.
- MFA fatigue
- An attack in which repeated push prompts are sent until a tired or confused user approves one.
- Federation
- A trust relationship in which a service provider accepts identity assertions from an external identity provider.
- OpenID Connect
- An authentication layer built on OAuth 2.0 that tells an application who the user is.
- PAM
- Privileged access management, which vaults, rotates, controls and records use of high-privilege accounts.
- Just-in-time access
- Granting elevated rights only for a specific task and time window, then removing them automatically.
- CASB
- Cloud access security broker, a control point that gives visibility and policy enforcement over cloud service use.
- Log ingestion
- Collecting logs from many sources into a central platform, then parsing and normalizing them.
- Normalization
- Mapping fields from different vendors' logs into a common format so they can be searched and correlated together.
- NTP
- Network Time Protocol, which synchronizes system clocks so timestamps from different devices can be correlated.
- Syslog severity
- A 0 to 7 scale where 0 is emergency and 7 is debug, with lower numbers being more severe.
- Event ID 4625
- The Windows Security log event for a failed logon attempt.
- Sysmon
- A Microsoft Sysinternals tool that logs detailed process, network, file and registry activity to the Windows event log.
- auth.log / secure
- The Linux files that record authentication events on Debian-family and Red Hat-family systems respectively.
- Beaconing
- Periodic outbound check-ins from a compromised host to a command-and-control server.
- Jitter
- Random variation added to beacon timing to make the pattern harder to detect.
- Baseline
- A record of normal activity used to recognize deviations.
- NetFlow
- Flow records summarizing who talked to whom, on which ports, for how long and how much data was sent, without full packet content.
- Rogue device
- Unauthorized hardware connected to the network, such as an unknown laptop, access point or DHCP server.
- Port scan
- One source probing many ports on a single host to find listening services.
- Network access control (NAC)
- A control that checks a device's identity and health before allowing it onto the network.
- Masquerading
- Disguising malware as a legitimate program through a trusted name, misspelling, double extension or renamed tool.
- Parent-child process
- The relationship between a process and the one that launched it, which often reveals malicious execution chains.
- Persistence
- Any mechanism that lets an attacker's code survive reboots, logoffs or credential changes.
- Run key
- A registry location whose entries launch programs automatically at startup or user logon.
- Event ID 7045
- The Windows System log event recording that a new service was installed.
- Autoruns
- A Sysinternals tool that lists programs configured to start automatically across many Windows locations.
- Application allow listing
- A control that permits only approved software to run, blocking unauthorized programs.
- Anomalous activity
- Application behavior that departs noticeably from its baseline, such as bulk exports or odd-hour logins.
- Unexpected output
- Responses an application should never produce, such as stack traces, database errors or other users' data.
- Directory traversal
- An attack using sequences like ../ to reach files outside the intended web directory.
- URL encoding
- Representing characters as a percent sign and two hex digits, such as %27 for a single quote, which attackers use to hide input.
- Stack trace
- A detailed error listing of the code path that failed, which leaks internal information when shown to users.
- SIEM
- Security information and event management, a platform that collects, normalizes, correlates and alerts on log data.
- SOAR
- Security orchestration, automation and response, a platform that runs playbooks to enrich alerts and automate response actions.
- EDR
- Endpoint detection and response, an agent-based tool that records host activity, detects malicious behavior and supports remote response.
- tcpdump
- A command-line packet capture tool that can save traffic to a pcap file for later analysis.
- Sandbox
- An isolated environment for safely executing a suspicious file or URL to observe its behavior.
- CyberChef
- A browser-based tool that decodes and transforms data through chained operations such as Base64 and XOR.
- WHOIS
- A lookup that returns domain registration details such as registrar, creation date and name servers.
- Received header
- A header added by each mail server that handles a message, read bottom to top to trace its path.
- Return-Path
- The envelope sender address used for bounces and checked by SPF.
- SPF
- Sender Policy Framework, a DNS record listing servers authorized to send mail for a domain.
- DKIM
- DomainKeys Identified Mail, a digital signature proving a message came from the signing domain and was not altered.
- DMARC
- A DNS policy requiring SPF or DKIM to pass with alignment to the From domain, and telling receivers how to handle failures.
- Business email compromise
- Fraud in which an attacker impersonates an executive or supplier by email to obtain payments or data.
- Lookalike domain
- A domain registered to resemble a legitimate one through misspellings or similar characters.
- TTPs
- Tactics, techniques and procedures: the goals, methods and specific implementations an adversary uses.
- Advanced persistent threat
- A well-resourced, usually state-linked actor that maintains long-term covert access to targets.
- Pyramid of pain
- A model showing that indicators such as hashes and IPs are easy for attackers to change, while TTPs are hard to change.
- Confidence
- A judgment of intelligence quality based on timeliness, relevancy and accuracy.
- ISAC
- Information Sharing and Analysis Center, a sector-specific community that shares threat information among members.
- STIX
- Structured Threat Information eXpression, a standard format for describing threat intelligence objects and relationships.
- TAXII
- Trusted Automated eXchange of Intelligence Information, a protocol for transporting STIX data between systems.
- Threat hunting
- A proactive, hypothesis-driven search for threats that existing detections have missed.
- Hypothesis
- A testable statement about possible attacker activity that defines what data to examine and what to expect.
- IoC
- Indicator of compromise, an artifact such as a hash, IP, domain or registry key that suggests intrusion.
- Stacking
- Counting occurrences of an attribute across many systems to find rare, suspicious outliers.
- Active defense
- Engaging adversaries inside your own environment through deception and monitoring, without attacking their systems.
- Honeypot
- A decoy system with no legitimate use, so any interaction with it indicates suspicious activity.
- Honeytoken
- A fake credential, record or file planted to trigger an alert when an intruder uses or opens it.
- Standard operating procedure
- A documented, repeatable set of steps for handling a common task consistently.
- Automation
- Performing a single repetitive task by machine without human involvement.
- Orchestration
- Coordinating multiple tools and automated tasks into one workflow, usually through a SOAR platform.
- Alert fatigue
- Reduced analyst attention caused by a high volume of alerts, especially false positives.
- Alert tuning
- Adjusting detection rules, thresholds and exceptions to reduce noise without missing real threats.
- Single pane of glass
- One interface that presents data and controls from many security tools together.
- Prompt injection
- Hidden instructions inside content given to an AI assistant that try to change its behavior.
Domain 2: Vulnerability management (26%)
Exam tips
- For the most accurate results with fewest false positives, choose a credentialed scan. For fragile systems where probes are risky, choose passive monitoring. For devices that are rarely on the network, choose agents.
- In OT/ICS scenarios availability and safety come first; the best answer is usually passive monitoring, segmentation or testing during scheduled downtime, never an aggressive active scan. For cloud, think agents, image scanning and CSPM.
- SAST is white-box and early (code at rest); DAST is black-box and later (running app); SCA is about third-party components; fuzzing is about malformed input. In nmap, filtered usually means a firewall is in the way, while closed means the host answered but nothing is listening.
- If a Linux server shows an old version banner but is patched through its vendor, think backported patch and false positive. A false negative is the worst outcome because it hides real risk, and a clean report means nothing if authentication failed.
- Decode vectors: AV:N is the worst attack vector, PR:N and UI:N mean no barrier for the attacker, and C:H/I:H/A:H means full impact. CVSS measures severity, EPSS measures likelihood, and KEV confirms active exploitation, which usually outranks raw CVSS.
- Ask who executes the payload: the database or shell (injection), another user's browser (XSS), or the server fetching a URL (SSRF). Changing an ID to see someone else's data is IDOR. SSRF is the server making the request; CSRF is the victim's browser.
- Best-fix pairings: SQL injection with parameterized queries, XSS with output encoding, buffer overflow with bounds checking and memory protections, IDOR with server-side authorization checks. Input validation helps everywhere but is rarely the single best answer for injection.
- When a system cannot be patched, look for segmentation or another compensating control that addresses the same threat, plus a documented, time-limited exception accepted by the business owner. Ignoring the finding or disconnecting a critical system is usually wrong.
- The exam favors testing before deployment, documented change requests with rollback plans, and rescanning to verify. An actively exploited critical flaw can justify an emergency change, and an unauthorized change with no ticket should be treated as a possible security event.
- Insurance is transfer, retiring the service is avoidance, adding controls is mitigation, and a signed decision to proceed is acceptance. Only a risk owner with authority accepts risk, never the analyst alone.
Key terms
- Asset inventory
- A maintained list of hardware, software and cloud resources with owners and criticality.
- Active scanning
- Sending probes to systems and analyzing their responses to find services and vulnerabilities.
- Passive scanning
- Identifying hosts and software by observing existing network traffic without sending probes.
- Credentialed scan
- A scan that logs into targets to inspect installed software, patches and configuration directly.
- Non-credentialed scan
- A scan performed without logging in, showing only what is exposed to an unauthenticated attacker.
- Agent-based scanning
- Assessment by software installed on each host that reports results to a central console.
- External scan
- A scan run from outside the network perimeter to show the internet-facing attack surface.
- Operational technology (OT)
- Systems that monitor and control physical processes, where availability and safety come first.
- SCADA
- Supervisory control and data acquisition, systems that monitor and control geographically distributed industrial processes.
- PLC
- Programmable logic controller, a ruggedized computer that directly controls industrial machinery.
- CSPM
- Cloud security posture management, tools that read cloud configuration through APIs to find misconfigurations.
- MDM
- Mobile device management, which inventories mobile devices and enforces security and compliance policies on them.
- Scan throttling
- Limiting scan speed and parallel connections to reduce the load placed on target systems.
- SPAN port
- A switch port that mirrors traffic to a monitoring device for passive analysis.
- Plugin
- A scanner test that checks for a specific vulnerability or configuration issue and produces a finding.
- Filtered port
- An nmap state meaning probes got no useful response, usually because a firewall is blocking them.
- SAST
- Static application security testing, which analyzes code without running it.
- DAST
- Dynamic application security testing, which tests a running application from the outside.
- SCA
- Software composition analysis, which identifies third-party components and their known vulnerabilities and licenses.
- SBOM
- Software bill of materials, a list of the components and versions that make up a piece of software.
- Fuzzing
- Sending large volumes of malformed or unexpected input to a program to reveal crashes and input handling flaws.
- True positive
- A detection that correctly reports a real issue.
- False positive
- A detection that reports an issue that does not actually exist.
- True negative
- Correctly reporting no issue where none exists.
- False negative
- A real issue that the tool fails to report, the most dangerous outcome.
- Backported patch
- A security fix applied to an older package version without changing its upstream version number.
- Banner grabbing
- Identifying software and versions from the text a service returns when a connection is made.
- Validation
- Confirming a finding with additional evidence before treating it as real.
- CVSS
- Common Vulnerability Scoring System, a 0.0 to 10.0 scale rating the severity of a vulnerability.
- Base metrics
- The CVSS metrics describing a vulnerability's inherent exploitability and impact, independent of any environment.
- Vector string
- A compact text representation of the CVSS metric values used to calculate a score.
- Attack vector
- The CVSS metric for how remote an attacker can be: network, adjacent, local or physical.
- EPSS
- Exploit Prediction Scoring System, which estimates the probability that a vulnerability will be exploited in the wild soon.
- CISA KEV
- The Known Exploited Vulnerabilities catalog, listing vulnerabilities with reliable evidence of active exploitation.
- Asset criticality
- How important a system is to the business, which raises or lowers the priority of its vulnerabilities.
- Injection
- A flaw where untrusted input is interpreted as part of a command or query, changing its meaning.
- Cross-site scripting (XSS)
- Injection of script into a web page that then runs in other users' browsers.
- SSRF
- Server-side request forgery, which makes a server send requests to attacker-chosen destinations, often internal ones.
- IDOR
- Insecure direct object reference, where changing an identifier gives access to another user's data because authorization is not checked.
- Broken access control
- Any failure to enforce what an authenticated user is allowed to see or do.
- Buffer overflow
- Writing more data to a memory buffer than it can hold, overwriting adjacent memory.
- HttpOnly flag
- A cookie attribute that prevents JavaScript from reading the cookie, limiting session theft through XSS.
- Input validation
- Checking that incoming data matches the expected type, length, format and range before it is used.
- Allow listing
- Accepting only input that matches known-good patterns, rather than trying to block known-bad input.
- Output encoding
- Converting special characters into a safe form for the context where data is displayed, preventing XSS.
- Parameterized query
- A database query with placeholders where user input is passed separately, so it is treated as data only.
- ASLR
- Address space layout randomization, which places code and data at unpredictable memory addresses.
- DEP / NX
- Data execution prevention, which marks memory regions such as the stack as non-executable.
- Content Security Policy
- An HTTP response header that restricts which sources of script and other content a browser will load.
- Compensating control
- An alternative safeguard that reduces risk to an acceptable level when the primary control cannot be used.
- Segmentation
- Dividing a network into isolated zones so only necessary connections reach a system.
- Air gap
- Complete physical separation of a system or network from other networks.
- Risk exception
- A documented, approved and time-limited decision to accept a known risk that cannot currently be remediated.
- Residual risk
- The risk that remains after compensating controls are applied.
- Risk owner
- The business person with authority to accept risk for a system, usually the system or data owner.
- End of life
- The point after which a vendor no longer provides patches or support for a product.
- Patch management
- The process of identifying, testing, deploying and verifying software updates.
- Secure baseline
- An approved, hardened configuration standard that systems are built and measured against.
- Configuration drift
- Gradual divergence of a system from its approved baseline configuration.
- Change management
- The process for requesting, reviewing, approving, scheduling and documenting changes to production.
- Change advisory board (CAB)
- The group that reviews and approves significant changes.
- Maintenance window
- A scheduled period of low business activity when changes and reboots are permitted.
- Rollback plan
- Documented steps to return a system to its previous state if a change fails.
- Risk appetite
- The amount and type of risk an organization is willing to pursue or tolerate to meet its goals.
- Risk acceptance
- A documented decision by an authorized risk owner to live with a risk without further action.
- Risk transference
- Shifting the financial impact of a risk to another party, such as an insurer, while accountability remains.
- Risk avoidance
- Eliminating a risk by stopping the activity or retiring the system that creates it.
- Memorandum of understanding (MOU)
- A less formal agreement describing shared intentions and responsibilities between parties.
- Service level agreement (SLA)
- A contract setting measurable service commitments such as uptime or response times.
Domain 3: Incident response & management (24%)
Exam tips
- Linear phases means Kill Chain; four corners and pivoting means Diamond Model; tactics and technique IDs means ATT&CK. OWASP is for web apps, OSSTMM is broad operational security testing.
- Map actions to phases: playbooks and training are preparation, isolating a host is containment, removing malware is eradication, restoring backups is recovery, and lessons learned is post-incident activity.
- Scope before you eradicate. If a question asks what to do after confirming one infected host, search for the same IoCs elsewhere before cleaning anything.
- Memory before disk. Matching hashes prove integrity; chain of custody proves handling. Always analyze a verified copy, never the original.
- Volatility is for memory, FTK Imager is primarily for acquiring and previewing images, and Autopsy is for in-depth disk image analysis with timelines and keyword search.
- Active ransomware or destruction means contain now. Watching before acting fits only stealthy, low-damage intrusions, needs management and legal approval, and ends with containing everything at once.
- Reimaging beats cleaning in place, restores must come from backups taken before the compromise began, and recovery is incomplete until the original entry point is fixed and monitored.
- Tabletop equals discussion, no systems touched. If a scenario says attackers may be reading email or chat, the answer is out-of-band communication.
- Root cause is the fundamental reason, not the first thing that went wrong. Lessons learned only pay off when corrective actions are assigned, tracked and fed into playbooks and controls.
Key terms
- Cyber Kill Chain
- Lockheed Martin's seven-phase linear model of an intrusion, from reconnaissance to actions on objectives.
- Diamond Model
- An intrusion analysis model linking adversary, capability, infrastructure and victim for each event.
- MITRE ATT&CK
- A knowledge base of adversary tactics and techniques used to map detections, hunts and incidents.
- Tactic
- In ATT&CK, the adversary's goal at a point in an attack, such as persistence or lateral movement.
- Technique
- In ATT&CK, a specific way an adversary achieves a tactic, identified by an ID such as T1053.
- OWASP Web Security Testing Guide
- A methodology for testing the security of web applications across areas like authentication and input validation.
- OSSTMM
- A peer-reviewed methodology for measurable testing of operational security across human, physical, wireless and network channels.
- NIST SP 800-61
- NIST's Computer Security Incident Handling Guide, source of the standard incident response lifecycle.
- CSIRT
- Computer security incident response team, the group responsible for handling incidents.
- Precursor
- A sign that an incident may occur in the future, such as a threat announcement.
- Indicator
- A sign that an incident may have occurred or is occurring, such as an alert or anomalous log entry.
- Containment
- Actions that limit damage and stop an incident from spreading.
- Eradication
- Removing the threat and its persistence and fixing the vulnerability that allowed it.
- Recovery
- Restoring affected systems to normal, verified operation while monitoring for recurrence.
- Indicator of compromise (IoC)
- An artifact, such as a hash, domain or registry key, suggesting a system has been compromised.
- Indicator of attack (IoA)
- Behavioral evidence that an attack is in progress, independent of specific artifacts.
- Scoping
- Determining which systems, accounts, data and time frame an incident affects.
- Patient zero
- The first system compromised in an incident, often the initial access point.
- Functional impact
- The effect of an incident on the organization's ability to operate and deliver services.
- Triage
- Rapidly sorting and prioritizing alerts to decide which need investigation first.
- Benign true positive
- An alert that correctly detected real activity which turns out to be authorized.
- Order of volatility
- The practice of collecting evidence from most to least short-lived, such as memory before disk.
- Chain of custody
- A documented record of every person who collected, handled or accessed an item of evidence.
- Legal hold
- A directive to preserve relevant data, overriding normal deletion, when litigation is anticipated.
- Forensic image
- A bit-for-bit copy of storage media, including deleted and unallocated space.
- Write blocker
- A device or software that allows reading media while preventing any writes to it.
- Hash validation
- Comparing cryptographic hashes of original and copy to prove the copy is identical and unchanged.
- Live acquisition
- Collecting data from a running system, accepting small documented changes to capture volatile evidence.
- Volatility
- An open-source framework for analyzing memory captures using plugins such as pslist, netscan and malfind.
- FTK Imager
- A free tool for creating and hashing forensic images and previewing their contents read-only.
- Autopsy
- An open-source graphical forensic platform built on The Sleuth Kit for analyzing disk images.
- Fileless malware
- Malicious code that runs in memory or through legitimate tools without writing a conventional executable to disk.
- File carving
- Recovering files from raw data using their signatures, without relying on file system metadata.
- Timestomping
- An anti-forensic technique of altering file timestamps to mislead investigators.
- Prefetch
- Windows files that record program execution, useful as evidence that a program ran.
- Isolation
- Cutting a compromised system off from the network while keeping it running for evidence.
- Quarantine VLAN
- A restricted network segment where suspect hosts are placed to block their normal traffic.
- Segmentation
- Dividing a network into zones so traffic between them can be restricted to contain spread.
- Sinkholing
- Redirecting a malicious domain to a server the defender controls so infected hosts cannot reach the attacker.
- Delayed containment
- Deliberately monitoring an attacker before acting in order to learn the full scope, then containing all at once.
- Session revocation
- Invalidating active logins and tokens so stolen sessions can no longer be used.
- Reimaging
- Rebuilding a system from a trusted, known-good image instead of cleaning it in place.
- Persistence
- Mechanisms an attacker installs to regain access after reboots or cleanup.
- Gold image
- A hardened, approved baseline image used to build or rebuild systems.
- Immutable backup
- A backup copy that cannot be modified or deleted during its retention period.
- 3-2-1 backup practice
- Keeping three copies of data on two media types with one copy offsite.
- KRBTGT
- The Active Directory account whose key signs Kerberos tickets; resetting it twice invalidates forged tickets.
- Incident response plan
- The document defining the IR program's scope, roles, severity levels, escalation and communication.
- Playbook
- A documented set of steps for handling a specific type of incident.
- Jump bag
- A ready kit of tools, media, forms and contact lists for responders.
- Tabletop exercise
- A discussion-based walkthrough of a scenario without touching production systems.
- Out-of-band communication
- Using channels separate from the potentially compromised environment to coordinate a response.
- SOAR
- Security orchestration, automation and response platforms that automate playbook steps.
- After-action review
- A structured review after an exercise or incident to capture improvements.
- Root cause analysis (RCA)
- A structured process to find the fundamental reason an incident occurred.
- Five whys
- An RCA technique of asking why repeatedly until reaching a fixable underlying cause.
- Fishbone diagram
- A cause-and-effect diagram grouping contributing factors into categories such as people, process and technology.
- Lessons learned
- A review after an incident capturing what worked, what did not and what to change.
- Corrective action
- A specific, assigned and tracked change made to prevent recurrence.
- ISAC
- Information sharing and analysis center, a sector group for sharing threat information among members.
Domain 4: Reporting & communication (16%)
Exam tips
- Prioritize by context, not base score alone: exploited, exposed and critical assets come first. Recurring vulnerabilities usually indicate an image or process problem, not individual host failures.
- An action plan closes a gap over time with owners and dates; an exception accepts a gap temporarily with approval and expiry; a compensating control reduces the risk of that gap. Compliance and security are related but not the same.
- Trends show direction, top 10 lists show where to focus, SLA compliance shows whether deadlines are met, and zero-day reporting focuses on exposure and compensating controls because no patch exists yet.
- Match detail to audience: technical teams get specifics, system owners get business impact and options, executives get a brief summary of risk and decisions. The system owner, not the analyst, accepts risk.
- Analysts do not talk to the media or notify regulators on their own; those go through PR and legal. Insider cases require HR and legal. Law enforcement involvement is a management decision with legal advice.
- Know event versus incident, and functional (to expertise) versus hierarchical (to management) escalation. Regulated data or privileged accounts usually raise severity and trigger escalation. When in doubt, escalate.
- The executive summary is for non-technical leaders and is written last. Timelines use one consistent time zone, scope includes what was ruled out, and recommendations must be specific with owners.
- Lessons learned only count when actions are assigned, tracked and reflected in later reports and metrics. Choose answers that close the loop over answers that only document.
- MTTD measures detection speed from the attacker's first activity; MTTR measures response or remediation speed and must be defined because the acronym is ambiguous. High alert volume with a low true positive rate signals tuning is needed.
Key terms
- CVSS
- Common Vulnerability Scoring System, a standard for rating the technical severity of vulnerabilities.
- KEV catalog
- CISA's list of vulnerabilities known to be exploited in the wild.
- EPSS
- Exploit Prediction Scoring System, which estimates the probability that a vulnerability will be exploited.
- Recurrence
- A vulnerability that reappears after being fixed or repeatedly across scans.
- Aging
- How long a finding has been open, often compared against its remediation deadline.
- Remediation SLA
- A policy-defined time frame for fixing vulnerabilities of each severity.
- Compliance report
- A report showing status against each requirement of a regulation or framework, with supporting evidence.
- POA&M
- Plan of action and milestones, a tracked plan listing weaknesses, remediation steps, owners and dates.
- Compliance exception
- A documented, approved and time-limited acceptance that a requirement will not be met.
- Compensating control
- An alternative safeguard that meets the intent of a requirement that cannot be met as written.
- PCI DSS
- Payment Card Industry Data Security Standard, the security standard for organizations handling payment card data.
- Evidence
- Artifacts such as scan results, configuration exports and policies that prove a control's status.
- Metric
- Any measured value describing some aspect of security, such as open findings.
- Key performance indicator (KPI)
- A metric tied to an important goal, usually with a target, used to judge progress.
- Trend
- The direction of a metric over time, which shows improvement or decline.
- Top 10 list
- A ranked list, such as most common vulnerabilities or riskiest hosts, used to focus remediation.
- Zero-day vulnerability
- A flaw unknown to the vendor or without an available patch, possibly already exploited.
- SLA compliance
- The percentage of findings remediated within the policy-defined time frame for their severity.
- Scan coverage
- The percentage of known assets that are actually being scanned.
- Stakeholder
- Anyone with an interest in, affected by or able to influence a security issue.
- System owner
- The business person accountable for a system and its risk, who approves changes and risk acceptance.
- RACI chart
- A matrix showing who is responsible, accountable, consulted and informed for each activity.
- CMDB
- Configuration management database, which records assets, their configurations and owners.
- Executive summary
- A brief, non-technical overview of risk, impact, actions and decisions needed.
- Need to know
- The principle of sharing sensitive information only with those who require it for their role.
- Legal counsel
- Lawyers who assess notification duties, preserve evidence, review statements and manage liability during incidents.
- Legal privilege
- Protection that can keep certain communications and work done at counsel's direction from disclosure.
- Public relations (PR)
- The function that manages external messaging to the media and public.
- Breach notification
- Legally or contractually required notice to regulators or individuals after certain data is exposed.
- Regulator
- A government or industry body that oversees compliance and may require incident notification.
- Holding statement
- A brief, pre-approved public statement used while facts are still being established.
- Event
- Any observable occurrence in a system or network.
- Adverse event
- An event with negative consequences, such as a crash or unauthorized access attempt.
- Security incident
- A violation or imminent threat of violation of security policies or standard practices.
- Incident declaration
- The formal decision that an incident exists, activating the IR plan.
- Functional escalation
- Moving an issue to someone with greater expertise or different skills.
- Hierarchical escalation
- Moving an issue up the management chain for decisions and authority.
- Escalation path
- A predefined sequence of contacts, conditions and time frames for raising an incident's handling level.
- Incident report
- The official record of an incident, its handling, impact and recommendations.
- Timeline
- A chronological list of attacker and responder actions with timestamps and sources.
- Impact
- The effect of an incident on operations, data, finances, compliance and reputation.
- Scope
- The extent of an incident, including what was affected and what was confirmed unaffected.
- Recommendation
- A specific, prioritized action with an owner to prevent recurrence or improve response.
- UTC
- Coordinated Universal Time, a common reference time zone for normalizing timelines.
- Root cause
- The fundamental, fixable reason an incident or recurring problem occurred.
- Five whys
- An RCA technique of repeatedly asking why until reaching the underlying cause.
- Ishikawa diagram
- Another name for a fishbone cause-and-effect diagram that groups contributing factors.
- Corrective action
- A change that fixes the specific problem identified by analysis.
- Preventive action
- A change that stops similar problems from arising elsewhere.
- Feedback loop
- The cycle in which findings drive changes that are then measured and reported.
- Mean time to detect (MTTD)
- The average time from the start of malicious activity to its detection.
- Mean time to respond (MTTR)
- The average time from detection to the start of response or to containment.
- Mean time to remediate
- The average time from detection or discovery to full, verified resolution.
- Alert volume
- The number of alerts generated in a period, often split by source, rule and severity.
- True positive rate
- The share of alerts that turn out to reflect real malicious activity.
- Dwell time
- How long an attacker remains in an environment before being detected.
- Alert fatigue
- Reduced analyst effectiveness caused by overwhelming numbers of low-value alerts.
Study CySA+ for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the CySA+ study planLessons, quizzes, exam simulations and hands-on labs.