Security Operations
88 practice questions with explanations — 15 free to try
PassNova has 88 CompTIA CySA+ practice questions on Security Operations, each with a clear explanation. A 15-question taster is free with no sign-up; the full bank is part of PassNova Premium. Updated for 2026.
Security Operations: example questions & answers
3 worked examples with answers and explanations below. Try 15 CompTIA CySA+ questions free in the browser; the full 88-question Security Operations bank is part of PassNova Premium.
During log analysis an analyst observes hundreds of failed logins for many usernames from one source IP, each username tried only once or twice. Which attack does this pattern most likely indicate?
- ASQL injection against a database-backed web form
- BPassword spraying✓
- CPass-the-hash reuse of a stolen NTLM hash
- DKerberoasting of service account ticket hashes
Answer: Password spraying tries a small number of common passwords across many accounts to avoid lockouts, producing few attempts per user but many users from one source.
An analyst wants to understand the tactics, techniques, and procedures (TTPs) used by adversaries and map observed behaviour to known attacker methods. Which framework is purpose-built for this?
- APCI DSS, the payment card industry data security standard
- BThe ISO 9001 standard for quality management systems
- CCOBIT, an IT governance and control framework
- DMITRE ATT&CK✓
Answer: MITRE ATT&CK is a curated knowledge base of adversary tactics and techniques used to classify and map observed attacker behaviour.
A threat intelligence feed provides IP addresses, file hashes, and domains associated with active campaigns. What are these data points collectively known as?
- AIndicators of compromise (IoCs)✓
- BService level objectives that define expected uptime
- CAcceptable use policies governing staff behaviour online
- DRecovery point objectives that cap tolerable data loss
Answer: Atomic artifacts such as malicious IPs, hashes, and domains that signal a possible intrusion are called indicators of compromise (IoCs).