udy Guide Exam CS0-002 (2
nload/comptia-cysa-study-gui
ook is Available on YakiBoo
CompTIA®
CompTIA CySA+ Study Guide Exam CS0-002 (2nd Edition) Chapple
Cybersecurity Analyst
(CySA+™) Practice Tests
ttps://[Link]/download/comptia-cysa-study-guide-exam-cs0-002-2nd-edition
Exam CS0-002
Second Edition
Mike Chapple
David Seidl
This Book is Available on [Link]
CompTIA CySA+ Study Guide Exam CS0-002 (2nd Edition) Chapple
Copyright © 2020 by John Wiley & Sons, Inc., Indianapolis, Indiana
Published simultaneously in Canada
ISBN: 978-1-119-68379-7
ISBN: 978-1-119-68392-6 (ebk.)
ISBN: 978-1-119-68404-6 (ebk.)
ttps://[Link]/download/comptia-cysa-study-guide-exam-cs0-002-2nd-edition
No part of this publication may be reproduced, stored in a retrieval system or transmitted in any form or by any
means, electronic, mechanical, photocopying, recording, scanning or otherwise, except as permitted under Sections
107 or 108 of the 1976 United States Copyright Act, without either the prior written permission of the Publisher, or
authorization through payment of the appropriate per-copy fee to the Copyright Clearance Center, 222 Rosewood
Drive, Danvers, MA 01923, (978) 750-8400, fax (978) 646-8600. Requests to the Publisher for permission should
be addressed to the Permissions Department, John Wiley & Sons, Inc., 111 River Street, Hoboken, NJ 07030, (201)
748-6011, fax (201) 748-6008, or online at [Link]
Limit of Liability/Disclaimer of Warranty: The publisher and the author make no representations or warranties
with respect to the accuracy or completeness of the contents of this work and specifically disclaim all warranties,
including without limitation warranties of fitness for a particular purpose. No warranty may be created or extended
by sales or promotional materials. The advice and strategies contained herein may not be suitable for every situation.
This work is sold with the understanding that the publisher is not engaged in rendering legal, accounting, or other
professional services. If professional assistance is required, the services of a competent professional person should
be sought. Neither the publisher nor the author shall be liable for damages arising herefrom. The fact that an
organization or Web site is referred to in this work as a citation and/or a potential source of further information
does not mean that the author or the publisher endorses the information the organization or Web site may provide
or recommendations it may make. Further, readers should be aware that Internet Web sites listed in this work may
have changed or disappeared between when this work was written and when it is read.
For general information on our other products and services or to obtain technical support, please contact our
Customer Care Department within the U.S. at (877) 762-2974, outside the U.S. at (317) 572-3993 or fax (317)
572-4002.
Wiley publishes in a variety of print and electronic formats and by print-on-demand. Some material included with
standard print versions of this book may not be included in e-books or in print-on-demand. If this book refers to
media such as a CD or DVD that is not included in the version you purchased, you may download this material at
[Link] For more information about Wiley products, visit [Link].
Library of Congress Control Number: 2020938566
TRADEMARKS: Wiley, the Wiley logo, and the Sybex logo are trademarks or registered trademarks of John Wiley &
Sons, Inc. and/or its affiliates, in the United States and other countries, and may not be used without written
permission. CompTIA and CySA+ are trademarks or registered trademarks of Computing Technology Industry
Association, Inc. All other trademarks are the property of their respective owners. John Wiley & Sons, Inc. is not
associated with any product or vendor mentioned in this book.
This Book is Available on [Link]
CompTIA CySA+ Study Guide Exam CS0-002 (2nd Edition) Chapple
ttps://[Link]/download/comptia-cysa-study-guide-exam-cs0-002-2nd-edition
For Renee, the most patient and caring person I know. Thank you for being
the heart of our family.
—MJC
This book is dedicated to my longtime friend Amanda Hanover, who always
combined unlimited curiosity with equally infinite numbers of questions
about security topics. Amanda lost her fight with mental health struggles
in 2019, but you, our reader, should know that there is support out there.
Mental health challenges are a struggle that many in the security community
face, and community support exists for those who need it. Visit www
.[Link] to find mental health activities at security
conferences in your area, as well as resources and links to other resources.
You are not alone.
And Amanda—here are a thousand more security questions for you. Your
friend, David
—DAS
This Book is Available on [Link]
CompTIA CySA+ Study Guide Exam CS0-002 (2nd Edition) Chapple
Acknowledgments
The authors would like to thank the many people who made this book possible. Kenyon
Brown at Wiley has been a wonderful partner through many books over the years. Carole
ttps://[Link]/download/comptia-cysa-study-guide-exam-cs0-002-2nd-edition
Jelen, our agent, worked on a myriad of logistic details and handled the business side of
the book with her usual grace and commitment to excellence. Chris Crayton, our technical
editor, pointed out many opportunities to improve our work and deliver a high-quality final
product. Kezia Endsley served as developmental editor and managed the project smoothly.
Thank you to Runzhi “Tom” Song, Mike’s research assistant at Notre Dame, who spent
hours proofreading our final copy. Many other people we’ll never meet worked behind the
scenes to make this book a success.
This Book is Available on [Link]
CompTIA CySA+ Study Guide Exam CS0-002 (2nd Edition) Chapple
About the Authors
Mike Chapple, PhD, CISSP, is an author of the best-selling CySA+ Study Guide and CISSP
(ISC)2 Certified Information Systems Security Professional Official Study Guide, now in
ttps://[Link]/download/comptia-cysa-study-guide-exam-cs0-002-2nd-edition
its eighth edition. He is an information security professional with two decades of experi-
ence in higher education, the private sector, and government.
Mike currently serves as teaching professor of IT, analytics, and operations at the Uni-
versity of Notre Dame, where he teaches courses focused on cybersecurity and business
analytics.
Before returning to Notre Dame, Mike served as executive vice president and chief
information officer of the Brand Institute, a Miami-based marketing consultancy. Mike
also spent four years in the information security research group at the National Security
Agency and served as an active duty intelligence officer in the U.S. Air Force.
Mike earned both his BS and PhD degrees from Notre Dame in computer science and
engineering. He also holds an MS in computer science from the University of Idaho and an
MBA from Auburn University.
David Seidl is the Vice President for Information Technology and CIO at Miami University.
During his IT career, he has served in a variety of technical and information security roles,
including serving at the Senior Director for Campus Technology Services at the University
of Notre Dame, where he co-led Notre Dame’s move to the cloud and oversaw cloud oper-
ations, ERP, databases, identity management, and a broad range of other technologies and
service. He also served as Notre Dame’s Director of Information Security and led Notre
Dame’s information security program. He has taught information security and networking
undergraduate courses as an instructor for Notre Dame’s Mendoza College of Business
and has written books on security certification and cyberwarfare, including co-authoring
CISSP (ISC)2 Official Practice Tests (Sybex 2018) as well as the previous editions of both
this book and the companion CompTIA CySA+ Practice Tests: Exam CS0-001.
David holds a bachelor’s degree in communication technology and a master’s degree in
information security from Eastern Michigan University, as well as CISSP, CySA+, Pentest+,
GPEN, and GCIH certifications.
This Book is Available on [Link]
CompTIA CySA+ Study Guide Exam CS0-002 (2nd Edition) Chapple
About the Technical Editor
Chris Crayton, MCSE, CISSP, CASP, CySA+, A+, N+, S+, is a technical consultant, trainer,
author and industry leading technical editor. He has worked as a computer technology
ttps://[Link]/download/comptia-cysa-study-guide-exam-cs0-002-2nd-edition
and networking instructor, information security director, network administrator, network
engineer, and PC specialist. Chris has served as technical editor and content contributor on
numerous technical titles for several of the leading publishing companies. He has also been
recognized with many professional and teaching awards.
This Book is Available on [Link]
CompTIA CySA+ Study Guide Exam CS0-002 (2nd Edition) Chapple
Contents at a Glance
Introduction xvii
ttps://[Link]/download/comptia-cysa-study-guide-exam-cs0-002-2nd-edition
Chapter 1 Domain 1.0: Threat and Vulnerability Management 1
Chapter 2 Domain 2.0: Software and Systems Security 105
Chapter 3 Domain 3.0: Security Operations and Monitoring 151
Chapter 4 Domain 4.0: Incident Response 207
Chapter 5 Domain 5.0: Compliance and Assessment 265
Chapter 6 Practice Exam 1 289
Chapter 7 Practice Exam 2 315
Appendix Answers to Review Questions 347
Index 481
This Book is Available on [Link]
CompTIA CySA+ Study Guide Exam CS0-002 (2nd Edition) Chapple
Contents
Introduction xvii
ttps://[Link]/download/comptia-cysa-study-guide-exam-cs0-002-2nd-edition
Chapter 1 Domain 1.0: Threat and Vulnerability Management 1
Chapter 2 Domain 2.0: Software and Systems Security 105
Chapter 3 Domain 3.0: Security Operations and Monitoring 151
Chapter 4 Domain 4.0: Incident Response 207
Chapter 5 Domain 5.0: Compliance and Assessment 265
Chapter 6 Practice Exam 1 289
Chapter 7 Practice Exam 2 315
Appendix Answers to Review Questions 347
Answers to Chapter 1: Domain 1.0: Threat and
Vulnerability Management 348
Answers to Chapter 2: Domain 2.0: Software and
Systems Security 381
Answers to Chapter 3: Domain 3.0: Security Operations
and Monitoring 403
Answers to Chapter 4: Domain 4.0: Incident
Response 425
Answers to Chapter 5: Domain 5.0: Compliance
and Assessment 450
Answers to Chapter 6: Practice Exam 1 461
Answers to Chapter 7: Practice Exam 2 470
Index 481
This Book is Available on [Link]
CompTIA CySA+ Study Guide Exam CS0-002 (2nd Edition) Chapple
Introduction
CompTIA CySA+ (Cybersecurity Analyst) Practice Tests, Second Edition is a companion
volume to the CompTIA CySA+ Study Guide, Second Edition (Sybex, 2020, Chapple/
ttps://[Link]/download/comptia-cysa-study-guide-exam-cs0-002-2nd-edition
Seidl). If you’re looking to test your knowledge before you take the CySA+ exam, this book
will help you by providing a combination of 1,000 questions that cover the CySA+ domains
and easy-to-understand explanations of both right and wrong answers.
If you’re just starting to prepare for the CySA+ exam, we highly recommend that you
use the Cybersecurity Analyst+ (CySA+) Study Guide, Second Edition to help you learn
about each of the domains covered by the CySA+ exam. Once you’re ready to test your
knowledge, use this book to help find places where you may need to study more or to prac-
tice for the exam itself.
Since this is a companion to the CySA+ Study Guide, this book is designed to be
similar to taking the CySA+ exam. It contains multipart scenarios as well as standard
multiple-choice questions similar to those you may encounter in the certification exam
itself. The book itself is broken up into seven chapters: five domain-centric chapters with
questions about each domain, and two chapters that contain 85-question practice tests
to simulate taking the CySA+ exam itself.
CompTIA
CompTIA is a nonprofit trade organization that offers certification in a variety of IT areas,
ranging from the skills that a PC support technician needs, which are covered in the A+
exam, to advanced certifications like the CompTIA Advanced Security Practitioner, or
CASP certification. CompTIA recommends that practitioners follow a cybersecurity career
path as shown here:
CompTIA
CompTIA CompTIA CompTIA CompTIA CompTIA
IT
A+ Network+ Security+ CSA+ CASP
Fundamentals
This Book is Available on [Link]