StudyToCert

All certifications / CySA+ / Cheat sheet

CySA+ CS0-004 cheat sheet

Every exam tip and key term from the free CySA+ lessons, by domain. Use your browser's Print to save it as a PDF.

Domain 1: Security operations (34%)

Exam tips

Key terms

Shared responsibility model
The division of security duties between a cloud provider, which secures the underlying infrastructure, and the customer, which secures its data, identities and configuration.
Serverless
A cloud model where code runs only when triggered and the provider manages all servers, so security focuses on permissions, inputs and dependencies.
Container
A lightweight package of an application and its libraries that shares the host operating system kernel.
Microsegmentation
Applying security policy between individual workloads rather than only between large network zones.
Zero trust
A model that verifies every access request in context and grants least privilege, regardless of network location.
Policy enforcement point
The zero trust component in the data plane that allows or blocks a connection based on the policy engine's decision.
SASE
Secure Access Service Edge, a cloud-delivered combination of SD-WAN and security services such as secure web gateway, CASB, firewall as a service and ZTNA.
MFA
Multifactor authentication, which requires factors from at least two different categories: know, have and are.
MFA fatigue
An attack in which repeated push prompts are sent until a tired or confused user approves one.
Federation
A trust relationship in which a service provider accepts identity assertions from an external identity provider.
OpenID Connect
An authentication layer built on OAuth 2.0 that tells an application who the user is.
PAM
Privileged access management, which vaults, rotates, controls and records use of high-privilege accounts.
Just-in-time access
Granting elevated rights only for a specific task and time window, then removing them automatically.
CASB
Cloud access security broker, a control point that gives visibility and policy enforcement over cloud service use.
Log ingestion
Collecting logs from many sources into a central platform, then parsing and normalizing them.
Normalization
Mapping fields from different vendors' logs into a common format so they can be searched and correlated together.
NTP
Network Time Protocol, which synchronizes system clocks so timestamps from different devices can be correlated.
Syslog severity
A 0 to 7 scale where 0 is emergency and 7 is debug, with lower numbers being more severe.
Event ID 4625
The Windows Security log event for a failed logon attempt.
Sysmon
A Microsoft Sysinternals tool that logs detailed process, network, file and registry activity to the Windows event log.
auth.log / secure
The Linux files that record authentication events on Debian-family and Red Hat-family systems respectively.
Beaconing
Periodic outbound check-ins from a compromised host to a command-and-control server.
Jitter
Random variation added to beacon timing to make the pattern harder to detect.
Baseline
A record of normal activity used to recognize deviations.
NetFlow
Flow records summarizing who talked to whom, on which ports, for how long and how much data was sent, without full packet content.
Rogue device
Unauthorized hardware connected to the network, such as an unknown laptop, access point or DHCP server.
Port scan
One source probing many ports on a single host to find listening services.
Network access control (NAC)
A control that checks a device's identity and health before allowing it onto the network.
Masquerading
Disguising malware as a legitimate program through a trusted name, misspelling, double extension or renamed tool.
Parent-child process
The relationship between a process and the one that launched it, which often reveals malicious execution chains.
Persistence
Any mechanism that lets an attacker's code survive reboots, logoffs or credential changes.
Run key
A registry location whose entries launch programs automatically at startup or user logon.
Event ID 7045
The Windows System log event recording that a new service was installed.
Autoruns
A Sysinternals tool that lists programs configured to start automatically across many Windows locations.
Application allow listing
A control that permits only approved software to run, blocking unauthorized programs.
Anomalous activity
Application behavior that departs noticeably from its baseline, such as bulk exports or odd-hour logins.
Unexpected output
Responses an application should never produce, such as stack traces, database errors or other users' data.
Directory traversal
An attack using sequences like ../ to reach files outside the intended web directory.
URL encoding
Representing characters as a percent sign and two hex digits, such as %27 for a single quote, which attackers use to hide input.
Stack trace
A detailed error listing of the code path that failed, which leaks internal information when shown to users.
SIEM
Security information and event management, a platform that collects, normalizes, correlates and alerts on log data.
SOAR
Security orchestration, automation and response, a platform that runs playbooks to enrich alerts and automate response actions.
EDR
Endpoint detection and response, an agent-based tool that records host activity, detects malicious behavior and supports remote response.
tcpdump
A command-line packet capture tool that can save traffic to a pcap file for later analysis.
Sandbox
An isolated environment for safely executing a suspicious file or URL to observe its behavior.
CyberChef
A browser-based tool that decodes and transforms data through chained operations such as Base64 and XOR.
WHOIS
A lookup that returns domain registration details such as registrar, creation date and name servers.
Received header
A header added by each mail server that handles a message, read bottom to top to trace its path.
Return-Path
The envelope sender address used for bounces and checked by SPF.
SPF
Sender Policy Framework, a DNS record listing servers authorized to send mail for a domain.
DKIM
DomainKeys Identified Mail, a digital signature proving a message came from the signing domain and was not altered.
DMARC
A DNS policy requiring SPF or DKIM to pass with alignment to the From domain, and telling receivers how to handle failures.
Business email compromise
Fraud in which an attacker impersonates an executive or supplier by email to obtain payments or data.
Lookalike domain
A domain registered to resemble a legitimate one through misspellings or similar characters.
TTPs
Tactics, techniques and procedures: the goals, methods and specific implementations an adversary uses.
Advanced persistent threat
A well-resourced, usually state-linked actor that maintains long-term covert access to targets.
Pyramid of pain
A model showing that indicators such as hashes and IPs are easy for attackers to change, while TTPs are hard to change.
Confidence
A judgment of intelligence quality based on timeliness, relevancy and accuracy.
ISAC
Information Sharing and Analysis Center, a sector-specific community that shares threat information among members.
STIX
Structured Threat Information eXpression, a standard format for describing threat intelligence objects and relationships.
TAXII
Trusted Automated eXchange of Intelligence Information, a protocol for transporting STIX data between systems.
Threat hunting
A proactive, hypothesis-driven search for threats that existing detections have missed.
Hypothesis
A testable statement about possible attacker activity that defines what data to examine and what to expect.
IoC
Indicator of compromise, an artifact such as a hash, IP, domain or registry key that suggests intrusion.
Stacking
Counting occurrences of an attribute across many systems to find rare, suspicious outliers.
Active defense
Engaging adversaries inside your own environment through deception and monitoring, without attacking their systems.
Honeypot
A decoy system with no legitimate use, so any interaction with it indicates suspicious activity.
Honeytoken
A fake credential, record or file planted to trigger an alert when an intruder uses or opens it.
Standard operating procedure
A documented, repeatable set of steps for handling a common task consistently.
Automation
Performing a single repetitive task by machine without human involvement.
Orchestration
Coordinating multiple tools and automated tasks into one workflow, usually through a SOAR platform.
Alert fatigue
Reduced analyst attention caused by a high volume of alerts, especially false positives.
Alert tuning
Adjusting detection rules, thresholds and exceptions to reduce noise without missing real threats.
Single pane of glass
One interface that presents data and controls from many security tools together.
Prompt injection
Hidden instructions inside content given to an AI assistant that try to change its behavior.

Domain 2: Vulnerability management (26%)

Exam tips

Key terms

Asset inventory
A maintained list of hardware, software and cloud resources with owners and criticality.
Active scanning
Sending probes to systems and analyzing their responses to find services and vulnerabilities.
Passive scanning
Identifying hosts and software by observing existing network traffic without sending probes.
Credentialed scan
A scan that logs into targets to inspect installed software, patches and configuration directly.
Non-credentialed scan
A scan performed without logging in, showing only what is exposed to an unauthenticated attacker.
Agent-based scanning
Assessment by software installed on each host that reports results to a central console.
External scan
A scan run from outside the network perimeter to show the internet-facing attack surface.
Operational technology (OT)
Systems that monitor and control physical processes, where availability and safety come first.
SCADA
Supervisory control and data acquisition, systems that monitor and control geographically distributed industrial processes.
PLC
Programmable logic controller, a ruggedized computer that directly controls industrial machinery.
CSPM
Cloud security posture management, tools that read cloud configuration through APIs to find misconfigurations.
MDM
Mobile device management, which inventories mobile devices and enforces security and compliance policies on them.
Scan throttling
Limiting scan speed and parallel connections to reduce the load placed on target systems.
SPAN port
A switch port that mirrors traffic to a monitoring device for passive analysis.
Plugin
A scanner test that checks for a specific vulnerability or configuration issue and produces a finding.
Filtered port
An nmap state meaning probes got no useful response, usually because a firewall is blocking them.
SAST
Static application security testing, which analyzes code without running it.
DAST
Dynamic application security testing, which tests a running application from the outside.
SCA
Software composition analysis, which identifies third-party components and their known vulnerabilities and licenses.
SBOM
Software bill of materials, a list of the components and versions that make up a piece of software.
Fuzzing
Sending large volumes of malformed or unexpected input to a program to reveal crashes and input handling flaws.
True positive
A detection that correctly reports a real issue.
False positive
A detection that reports an issue that does not actually exist.
True negative
Correctly reporting no issue where none exists.
False negative
A real issue that the tool fails to report, the most dangerous outcome.
Backported patch
A security fix applied to an older package version without changing its upstream version number.
Banner grabbing
Identifying software and versions from the text a service returns when a connection is made.
Validation
Confirming a finding with additional evidence before treating it as real.
CVSS
Common Vulnerability Scoring System, a 0.0 to 10.0 scale rating the severity of a vulnerability.
Base metrics
The CVSS metrics describing a vulnerability's inherent exploitability and impact, independent of any environment.
Vector string
A compact text representation of the CVSS metric values used to calculate a score.
Attack vector
The CVSS metric for how remote an attacker can be: network, adjacent, local or physical.
EPSS
Exploit Prediction Scoring System, which estimates the probability that a vulnerability will be exploited in the wild soon.
CISA KEV
The Known Exploited Vulnerabilities catalog, listing vulnerabilities with reliable evidence of active exploitation.
Asset criticality
How important a system is to the business, which raises or lowers the priority of its vulnerabilities.
Injection
A flaw where untrusted input is interpreted as part of a command or query, changing its meaning.
Cross-site scripting (XSS)
Injection of script into a web page that then runs in other users' browsers.
SSRF
Server-side request forgery, which makes a server send requests to attacker-chosen destinations, often internal ones.
IDOR
Insecure direct object reference, where changing an identifier gives access to another user's data because authorization is not checked.
Broken access control
Any failure to enforce what an authenticated user is allowed to see or do.
Buffer overflow
Writing more data to a memory buffer than it can hold, overwriting adjacent memory.
HttpOnly flag
A cookie attribute that prevents JavaScript from reading the cookie, limiting session theft through XSS.
Input validation
Checking that incoming data matches the expected type, length, format and range before it is used.
Allow listing
Accepting only input that matches known-good patterns, rather than trying to block known-bad input.
Output encoding
Converting special characters into a safe form for the context where data is displayed, preventing XSS.
Parameterized query
A database query with placeholders where user input is passed separately, so it is treated as data only.
ASLR
Address space layout randomization, which places code and data at unpredictable memory addresses.
DEP / NX
Data execution prevention, which marks memory regions such as the stack as non-executable.
Content Security Policy
An HTTP response header that restricts which sources of script and other content a browser will load.
Compensating control
An alternative safeguard that reduces risk to an acceptable level when the primary control cannot be used.
Segmentation
Dividing a network into isolated zones so only necessary connections reach a system.
Air gap
Complete physical separation of a system or network from other networks.
Risk exception
A documented, approved and time-limited decision to accept a known risk that cannot currently be remediated.
Residual risk
The risk that remains after compensating controls are applied.
Risk owner
The business person with authority to accept risk for a system, usually the system or data owner.
End of life
The point after which a vendor no longer provides patches or support for a product.
Patch management
The process of identifying, testing, deploying and verifying software updates.
Secure baseline
An approved, hardened configuration standard that systems are built and measured against.
Configuration drift
Gradual divergence of a system from its approved baseline configuration.
Change management
The process for requesting, reviewing, approving, scheduling and documenting changes to production.
Change advisory board (CAB)
The group that reviews and approves significant changes.
Maintenance window
A scheduled period of low business activity when changes and reboots are permitted.
Rollback plan
Documented steps to return a system to its previous state if a change fails.
Risk appetite
The amount and type of risk an organization is willing to pursue or tolerate to meet its goals.
Risk acceptance
A documented decision by an authorized risk owner to live with a risk without further action.
Risk transference
Shifting the financial impact of a risk to another party, such as an insurer, while accountability remains.
Risk avoidance
Eliminating a risk by stopping the activity or retiring the system that creates it.
Memorandum of understanding (MOU)
A less formal agreement describing shared intentions and responsibilities between parties.
Service level agreement (SLA)
A contract setting measurable service commitments such as uptime or response times.

Domain 3: Incident response & management (24%)

Exam tips

Key terms

Cyber Kill Chain
Lockheed Martin's seven-phase linear model of an intrusion, from reconnaissance to actions on objectives.
Diamond Model
An intrusion analysis model linking adversary, capability, infrastructure and victim for each event.
MITRE ATT&CK
A knowledge base of adversary tactics and techniques used to map detections, hunts and incidents.
Tactic
In ATT&CK, the adversary's goal at a point in an attack, such as persistence or lateral movement.
Technique
In ATT&CK, a specific way an adversary achieves a tactic, identified by an ID such as T1053.
OWASP Web Security Testing Guide
A methodology for testing the security of web applications across areas like authentication and input validation.
OSSTMM
A peer-reviewed methodology for measurable testing of operational security across human, physical, wireless and network channels.
NIST SP 800-61
NIST's Computer Security Incident Handling Guide, source of the standard incident response lifecycle.
CSIRT
Computer security incident response team, the group responsible for handling incidents.
Precursor
A sign that an incident may occur in the future, such as a threat announcement.
Indicator
A sign that an incident may have occurred or is occurring, such as an alert or anomalous log entry.
Containment
Actions that limit damage and stop an incident from spreading.
Eradication
Removing the threat and its persistence and fixing the vulnerability that allowed it.
Recovery
Restoring affected systems to normal, verified operation while monitoring for recurrence.
Indicator of compromise (IoC)
An artifact, such as a hash, domain or registry key, suggesting a system has been compromised.
Indicator of attack (IoA)
Behavioral evidence that an attack is in progress, independent of specific artifacts.
Scoping
Determining which systems, accounts, data and time frame an incident affects.
Patient zero
The first system compromised in an incident, often the initial access point.
Functional impact
The effect of an incident on the organization's ability to operate and deliver services.
Triage
Rapidly sorting and prioritizing alerts to decide which need investigation first.
Benign true positive
An alert that correctly detected real activity which turns out to be authorized.
Order of volatility
The practice of collecting evidence from most to least short-lived, such as memory before disk.
Chain of custody
A documented record of every person who collected, handled or accessed an item of evidence.
Legal hold
A directive to preserve relevant data, overriding normal deletion, when litigation is anticipated.
Forensic image
A bit-for-bit copy of storage media, including deleted and unallocated space.
Write blocker
A device or software that allows reading media while preventing any writes to it.
Hash validation
Comparing cryptographic hashes of original and copy to prove the copy is identical and unchanged.
Live acquisition
Collecting data from a running system, accepting small documented changes to capture volatile evidence.
Volatility
An open-source framework for analyzing memory captures using plugins such as pslist, netscan and malfind.
FTK Imager
A free tool for creating and hashing forensic images and previewing their contents read-only.
Autopsy
An open-source graphical forensic platform built on The Sleuth Kit for analyzing disk images.
Fileless malware
Malicious code that runs in memory or through legitimate tools without writing a conventional executable to disk.
File carving
Recovering files from raw data using their signatures, without relying on file system metadata.
Timestomping
An anti-forensic technique of altering file timestamps to mislead investigators.
Prefetch
Windows files that record program execution, useful as evidence that a program ran.
Isolation
Cutting a compromised system off from the network while keeping it running for evidence.
Quarantine VLAN
A restricted network segment where suspect hosts are placed to block their normal traffic.
Segmentation
Dividing a network into zones so traffic between them can be restricted to contain spread.
Sinkholing
Redirecting a malicious domain to a server the defender controls so infected hosts cannot reach the attacker.
Delayed containment
Deliberately monitoring an attacker before acting in order to learn the full scope, then containing all at once.
Session revocation
Invalidating active logins and tokens so stolen sessions can no longer be used.
Reimaging
Rebuilding a system from a trusted, known-good image instead of cleaning it in place.
Persistence
Mechanisms an attacker installs to regain access after reboots or cleanup.
Gold image
A hardened, approved baseline image used to build or rebuild systems.
Immutable backup
A backup copy that cannot be modified or deleted during its retention period.
3-2-1 backup practice
Keeping three copies of data on two media types with one copy offsite.
KRBTGT
The Active Directory account whose key signs Kerberos tickets; resetting it twice invalidates forged tickets.
Incident response plan
The document defining the IR program's scope, roles, severity levels, escalation and communication.
Playbook
A documented set of steps for handling a specific type of incident.
Jump bag
A ready kit of tools, media, forms and contact lists for responders.
Tabletop exercise
A discussion-based walkthrough of a scenario without touching production systems.
Out-of-band communication
Using channels separate from the potentially compromised environment to coordinate a response.
SOAR
Security orchestration, automation and response platforms that automate playbook steps.
After-action review
A structured review after an exercise or incident to capture improvements.
Root cause analysis (RCA)
A structured process to find the fundamental reason an incident occurred.
Five whys
An RCA technique of asking why repeatedly until reaching a fixable underlying cause.
Fishbone diagram
A cause-and-effect diagram grouping contributing factors into categories such as people, process and technology.
Lessons learned
A review after an incident capturing what worked, what did not and what to change.
Corrective action
A specific, assigned and tracked change made to prevent recurrence.
ISAC
Information sharing and analysis center, a sector group for sharing threat information among members.

Domain 4: Reporting & communication (16%)

Exam tips

Key terms

CVSS
Common Vulnerability Scoring System, a standard for rating the technical severity of vulnerabilities.
KEV catalog
CISA's list of vulnerabilities known to be exploited in the wild.
EPSS
Exploit Prediction Scoring System, which estimates the probability that a vulnerability will be exploited.
Recurrence
A vulnerability that reappears after being fixed or repeatedly across scans.
Aging
How long a finding has been open, often compared against its remediation deadline.
Remediation SLA
A policy-defined time frame for fixing vulnerabilities of each severity.
Compliance report
A report showing status against each requirement of a regulation or framework, with supporting evidence.
POA&M
Plan of action and milestones, a tracked plan listing weaknesses, remediation steps, owners and dates.
Compliance exception
A documented, approved and time-limited acceptance that a requirement will not be met.
Compensating control
An alternative safeguard that meets the intent of a requirement that cannot be met as written.
PCI DSS
Payment Card Industry Data Security Standard, the security standard for organizations handling payment card data.
Evidence
Artifacts such as scan results, configuration exports and policies that prove a control's status.
Metric
Any measured value describing some aspect of security, such as open findings.
Key performance indicator (KPI)
A metric tied to an important goal, usually with a target, used to judge progress.
Trend
The direction of a metric over time, which shows improvement or decline.
Top 10 list
A ranked list, such as most common vulnerabilities or riskiest hosts, used to focus remediation.
Zero-day vulnerability
A flaw unknown to the vendor or without an available patch, possibly already exploited.
SLA compliance
The percentage of findings remediated within the policy-defined time frame for their severity.
Scan coverage
The percentage of known assets that are actually being scanned.
Stakeholder
Anyone with an interest in, affected by or able to influence a security issue.
System owner
The business person accountable for a system and its risk, who approves changes and risk acceptance.
RACI chart
A matrix showing who is responsible, accountable, consulted and informed for each activity.
CMDB
Configuration management database, which records assets, their configurations and owners.
Executive summary
A brief, non-technical overview of risk, impact, actions and decisions needed.
Need to know
The principle of sharing sensitive information only with those who require it for their role.
Legal counsel
Lawyers who assess notification duties, preserve evidence, review statements and manage liability during incidents.
Legal privilege
Protection that can keep certain communications and work done at counsel's direction from disclosure.
Public relations (PR)
The function that manages external messaging to the media and public.
Breach notification
Legally or contractually required notice to regulators or individuals after certain data is exposed.
Regulator
A government or industry body that oversees compliance and may require incident notification.
Holding statement
A brief, pre-approved public statement used while facts are still being established.
Event
Any observable occurrence in a system or network.
Adverse event
An event with negative consequences, such as a crash or unauthorized access attempt.
Security incident
A violation or imminent threat of violation of security policies or standard practices.
Incident declaration
The formal decision that an incident exists, activating the IR plan.
Functional escalation
Moving an issue to someone with greater expertise or different skills.
Hierarchical escalation
Moving an issue up the management chain for decisions and authority.
Escalation path
A predefined sequence of contacts, conditions and time frames for raising an incident's handling level.
Incident report
The official record of an incident, its handling, impact and recommendations.
Timeline
A chronological list of attacker and responder actions with timestamps and sources.
Impact
The effect of an incident on operations, data, finances, compliance and reputation.
Scope
The extent of an incident, including what was affected and what was confirmed unaffected.
Recommendation
A specific, prioritized action with an owner to prevent recurrence or improve response.
UTC
Coordinated Universal Time, a common reference time zone for normalizing timelines.
Root cause
The fundamental, fixable reason an incident or recurring problem occurred.
Five whys
An RCA technique of repeatedly asking why until reaching the underlying cause.
Ishikawa diagram
Another name for a fishbone cause-and-effect diagram that groups contributing factors.
Corrective action
A change that fixes the specific problem identified by analysis.
Preventive action
A change that stops similar problems from arising elsewhere.
Feedback loop
The cycle in which findings drive changes that are then measured and reported.
Mean time to detect (MTTD)
The average time from the start of malicious activity to its detection.
Mean time to respond (MTTR)
The average time from detection to the start of response or to containment.
Mean time to remediate
The average time from detection or discovery to full, verified resolution.
Alert volume
The number of alerts generated in a period, often split by source, rule and severity.
True positive rate
The share of alerts that turn out to reflect real malicious activity.
Dwell time
How long an attacker remains in an environment before being detected.
Alert fatigue
Reduced analyst effectiveness caused by overwhelming numbers of low-value alerts.
Study CySA+ for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the CySA+ study plan