Free CS0-002: CompTIA CySA Certification Exam (CS0-002) Exam Questions and Answers
This exam retired on 5 December 2023. It was replaced by CS0-003: CompTIA CySA (CS0-003). The questions here still cover most of the same ground, and the new exam’s own page has the current bank.
Replaces CS0-001: CompTIA CySA Certification Exam. Questions from the earlier version are also in this bank.
CompTIA CySA Certification Exam (CS0-002) is exam CS0-002, part of the CompTIA certification programme. CompTIA exam codes carry a family prefix and a version number — SY0- for Security+, N10- for Network+, CS0- for CySA+, 220- for A+ — and most Plus-series exams allow 90 minutes for up to 90 questions, mixing multiple choice with performance-based items in a simulated environment.
Candidates comparing CS0-002 exam dumps, ExamTopics and other CS0-002 practice tests use this page for the answers and explanations behind each question. Download the free CS0-002 PDF, then sit the timed CS0-002 exam simulation before booking with CompTIA.
Last updated: September 29, 2026
- Exam code
- CS0-002
- Provider
- CompTIA
- Questions in our bank
- 1000+
- Free to read
- First 10, with answers
- Official page
- Official Exam website
- Our test mode duration & pass mark
- 130 mins · 70%
Recommended: Switch to Test Mode to start a practice test that simulates the real exam experience.
Question #1
Due to a rise m cyberattackers seeking PHI, a healthcare company that collects highly sensitive data from millions of customers is deploying a solution that will ensure the customers' data is protected by the organization internally and externally Which of the following countermeasures can BEST prevent the loss of customers' sensitive data?
Correct answer: A
Explanation
Implementing privileged access management (PAM) would be the best countermeasure to prevent the loss of customers’ sensitive data due to a rise in cyberattackers seeking PHI (Protected Health Information). PAM is a solution that helps to control and monitor the access and use of privileged accounts, such as administrator or root accounts, that have elevated permissions or access to sensitive data. PAM can help prevent unauthorized or accidental use of privileged accounts by enforcing strict access policies, such as requiring approval, authentication, or auditing for each access request. PAM can also help rotate or expire the passwords of privileged accounts to reduce the risk of compromise2. PAM can help protect PHI from cyberattackers who may try to exploit privileged accounts to access or exfiltrate sensitive data.
Continue with CS0-002: CompTIA CySA Certification Exam (CS0-002)
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in CS0-002: CompTIA CySA Certification Exam (CS0-002), the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #2
Which of the following is a vulnerability associated with the Modbus protocol?
Correct answer: D
Explanation
Modbus is a communication protocol that is widely used in industrial control systems (ICS) and supervisory control and data acquisition (SCADA) systems. However, Modbus was not designed to provide security and it is vulnerable to various cyberattacks. One of the main vulnerabilities of Modbus is the lack of authentication, which means that any device on the network can send or receive commands without verifying its identity or authority. This can lead to unauthorized access, data manipulation, or denial of service attacks on the ICS or SCADA system. Some examples of attacks that exploit the lack of authentication in Modbus are: Detection attack: An attacker can scan the network and discover the devices and their addresses, functions, and registers by sending Modbus requests and observing the responses. This can reveal sensitive information about the system configuration and operation1. Command injection attack: An attacker can send malicious commands to the devices and modify their settings, values, or outputs. For example, an attacker can change the speed of a motor, open or close a valve, or turn off a switch23. Response injection attack: An attacker can intercept and alter the responses from the devices and deceive the master or other devices about the true state of the system. For example, an attacker can fake a normal response when there is an error or an alarm23. Denial of service attack: An attacker can flood the network with Modbus requests or commands and overload the devices or the communication channel. This can prevent legitimate requests or commands from being processed and disrupt the normal operation of the system14. To mitigate these attacks, some security measures that can be applied to Modbus are: Encryption: Encrypting the Modbus messages can prevent eavesdropping and tampering by unauthorized parties. However, encryption can also introduce additional overhead and latency to the communication56. Authentication: Adding authentication mechanisms to Modbus can ensure that only authorized devices can send or receive commands. Authentication can be based on passwords, certificates, tokens, or other methods56. Firewall: Installing a firewall between the Modbus network and other networks can filter out unwanted traffic and block unauthorized access. A firewall can also enforce rules and policies for Modbus communication24. Intrusion detection system: Deploying an intrusion detection system (IDS) on the Modbus network can monitor the traffic and detect anomalous or malicious activities. An IDS can also alert the operators or trigger countermeasures when an attack is detected24.
Continue with CS0-002: CompTIA CySA Certification Exam (CS0-002)
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in CS0-002: CompTIA CySA Certification Exam (CS0-002), the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #3
A security technician configured a NIDS to monitor network traffic. Which of the following is a condition in which harmless traffic is classified as a potential network attack?
Correct answer: C
Explanation
A false positive is a condition in which harmless traffic is classified as a potential network attack by a NIDS. A NIDS is a network intrusion detection system that monitors network traffic for any signs of malicious or anomalous activity. A false positive can result in unnecessary alerts or actions by the NIDS, such as blocking legitimate traffic or generating false alarms. False positives can be caused by various factors, such as misconfigured rules, outdated signatures, noisy network traffic or benign anomalies3 .
Continue with CS0-002: CompTIA CySA Certification Exam (CS0-002)
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in CS0-002: CompTIA CySA Certification Exam (CS0-002), the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #4
An analyst reviews the most recent vulnerability management report and notices a firewall with 99.98% required uptime is reporting different firmware versions on scans than were reported in previous scans. The vendor released new firewall firmware a few months ago. Which of the following will the analyst most likely do next given the requirements?
Correct answer: B
Explanation
The analyst should check for change tickets as the next step, given that the firewall is reporting different firmware versions on scans than were reported in previous scans. Change tickets are records of any authorized changes made to a system or a network, such as updating firmware, installing patches, or modifying configurations. Checking for change tickets can help verify if the firmware change was intentional and approved, or if it was unauthorized or malicious.
Continue with CS0-002: CompTIA CySA Certification Exam (CS0-002)
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in CS0-002: CompTIA CySA Certification Exam (CS0-002), the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #5
While reviewing a vulnerability assessment, an analyst notices the following issue is identified in the report: this finding, which of the following would be most appropriate for the analyst to recommend to the network engineer?

Correct answer: D
Explanation
The vulnerability assessment report shows that the device is using SSLv3, which is an outdated and insecure protocol for secure communication over a network. SSLv3 has several known vulnerabilities, such as POODLE, that allow attackers to decrypt or modify the encrypted data. To remediate this issue, the analyst should recommend reconfiguring the device to support only connections leveraging TLSv1.2, which is a newer and more secure protocol that provides stronger encryption, authentication, and integrity protection for the data transmitted over the network.
Continue with CS0-002: CompTIA CySA Certification Exam (CS0-002)
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in CS0-002: CompTIA CySA Certification Exam (CS0-002), the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #6
An internally developed file-monitoring system identified the following except as causing a program to crash often: Which of the following should a security analyst recommend to fix the issue?

Correct answer: B
Explanation
The security analyst should recommend replacing the strcpy function with a safer alternative. The strcpy function is a C library function that copies a string from one buffer to another. However, this function does not check the size of the destination buffer, which can lead to buffer overflow vulnerabilities if the source string is longer than the destination buffer. Buffer overflow vulnerabilities can allow attackers to execute arbitrary code or crash the program. A safer alternative to strcpy is strncpy, which limits the number of characters copied to the size of the destination buffer.
Continue with CS0-002: CompTIA CySA Certification Exam (CS0-002)
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in CS0-002: CompTIA CySA Certification Exam (CS0-002), the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #7
An organization has the following risk mitigation policies • Risks without compensating controls will be mitigated first it the nsk value is greater than $50,000 • Other nsk mitigation will be pnontized based on risk value. The following risks have been identified: Which of the following is the ordei of priority for risk mitigation from highest to lowest?

Correct answer: C
Explanation
The order of priority for risk mitigation from highest to lowest is C, B, A, D. This order is based on applying the risk mitigation policies of the organization. According to the first policy, risks without compensating controls will be mitigated first if the risk value is greater than $50,000. Risk C has no compensating controls and a risk value of $75,000, so it is the highest priority. Risk B also has no compensating controls, but a risk value of $40,000, so it is the second priority. According to the second policy, other risk mitigation will be prioritized based on risk value. Risk A has a risk value of $60,000 and a compensating control of encryption, so it is the third priority. Risk D has a risk value of $50,000 and a compensating control of backup power supply, so it is the lowest priority.
Continue with CS0-002: CompTIA CySA Certification Exam (CS0-002)
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in CS0-002: CompTIA CySA Certification Exam (CS0-002), the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #8
A company’s Chief Information Security Officer (CISO) published an Internet usage policy that prohibits employees from accessing unauthorized websites. The IT department whitelisted websites used for business needs. The CISO wants the security analyst to recommend a solution that would improve security and support employee morale. Which of the following security recommendations would allow employees to browse non-business-related websites?
Correct answer: A
Explanation
A virtual machine alternative is a solution that allows employees to access non-business-related websites on a separate virtual machine that is isolated from the company’s network and data. This way, the employees can browse the internet without compromising the security or performance of the company’s systems3
Continue with CS0-002: CompTIA CySA Certification Exam (CS0-002)
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in CS0-002: CompTIA CySA Certification Exam (CS0-002), the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #9
A SIEM analyst receives an alert containing the following URL: Which of the following BEST describes the attack?
Correct answer: D
Explanation
A directory traversal attack is a type of web application attack that exploits insufficient input validation or filtering to access files or directories that are outside of the web root folder. A directory traversal attack can allow an attacker to read, modify, or execute files on the target server that are not intended to be accessible via web requests. The URL in the alert contains an example of a directory traversal attack, as indicated by the use of “…/” sequences in the query string. These sequences are used to navigate up one level in the directory hierarchy, potentially reaching sensitive files or folders on the server. In this case, the attacker is trying to access /etc/passwd file, which contains user account information on Linux systems.
Continue with CS0-002: CompTIA CySA Certification Exam (CS0-002)
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in CS0-002: CompTIA CySA Certification Exam (CS0-002), the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #10
A help desk technician inadvertently sent the credentials of the company's CRM n clear text to an employee's personal email account. The technician then reset the employee's account using the appropriate process and the employee's corporate email, and notified the security team of the incident According to the incident response procedure, which of the following should the security team do NEXT?
Correct answer: C
Explanation
The security team should perform postmortem data correlation next after receiving notification of the incident from the help desk technician. Postmortem data correlation is an activity that involves analyzing data from various sources (such as logs, alerts, reports, etc.) to identify root causes, impacts, indicators of compromise (IoCs), lessons learned, and recommendations for improvement after an incident3. Postmortem data correlation can help the security team to: Determine how the incident occurred and how it was detected and resolved Identify any gaps or weaknesses in security controls or processes that contributed to the incident Develop action plans or remediation strategies to prevent recurrence or mitigate future incidents
Continue with CS0-002: CompTIA CySA Certification Exam (CS0-002)
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in CS0-002: CompTIA CySA Certification Exam (CS0-002), the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Discussion
Explain your reasoning, not just the letterOther CompTIA certifications
- SK0-004: CompTIA Server (opens in a new tab)
- SY0-701: CompTIA Security 2023 (opens in a new tab)
- N10-008: CompTIA Network (opens in a new tab)
- SY0-601: CompTIA Security 2021 (opens in a new tab)
- N10-009: CompTIA Network+ Exam (opens in a new tab)
- N10-007: CompTIA Network 2018 (opens in a new tab)
- CS0-003: CompTIA CySA (CS0-003) (opens in a new tab)
- 220-1102: CompTIA A Certification Exam: Core 2 (opens in a new tab)
- SK0-005: CompTIA Server Certification Exam (opens in a new tab)
- 220-1101: CompTIA A Certification Exam: Core 1 (opens in a new tab)
- XK0-005: CompTIA Linux (opens in a new tab)
- CS0-001: CompTIA CySA Certification Exam (opens in a new tab)
Reviews
Write a review★★★★★
Exam Practice is worth every penny. The mock exams are realistic, and the feedback helped me focus on key areas.
Amit SharmaVerified buyer
★★★★★
I highly recommend Exam Practice. The feedback after each test helped me improve significantly, and I passed my exams easily.
Oscar NyströmVerified buyer
★★★★★
This platform is a lifesaver. The practice questions and explanations are so detailed. It’s the best study tool I’ve ever used.
Hannah SmithVerified buyer
FAQ
Learn More: https://www.comptia.org/certifications
- Q1: Is the CompTIA CySA+ CS0-002 exam still available?
- A: No. CS0-002 retired on December 5, 2023 and was replaced by CS0-003, which launched on June 6, 2023. CompTIA has announced that CS0-003 will itself retire in English on December 22, 2026, with a new CySA+ version taking over.
- Q2: How many questions were on the CS0-002 exam and how long was it?
- A: CS0-002 had a minimum of 85 multiple-choice and performance-based questions and a 165-minute time limit. The current CS0-003 exam has a maximum of 85 questions in the same 165 minutes.
- Q3: What was the passing score for CS0-002?
- A: The passing score was 750 on a scale of 100 to 900, which is also the passing score for CS0-003.
- Q4: What domains did the CS0-002 exam cover and how were they weighted?
- A: CS0-002 was weighted Threat and Vulnerability Management 22%, Software and Systems Security 18%, Security Operations and Monitoring 25%, Incident Response 22% and Compliance and Assessment 13%. CS0-003 uses four domains: Security Operations 33%, Vulnerability Management 30%, Incident Response Management 20% and Reporting and Communication 17%.
- Q5: What experience did CompTIA recommend for CS0-002?
- A: CompTIA recommended four years of hands-on experience in a technical cybersecurity job role plus Security+ and Network+ or equivalent knowledge and experience.
- Q6: In what languages is the current CySA+ exam offered?
- A: As of October 2026, CS0-003 is offered in English, Japanese, Portuguese and Spanish. The English version retires on December 22, 2026 and the translated versions on March 23, 2027.
- Q7: What is the CS0-002: CompTIA CySA Certification Exam (CS0-002) exam?
- A: CS0-002: CompTIA CySA Certification Exam (CS0-002) is a CompTIA certification exam. Judging by the questions in our bank, it concentrates on analyst, ciso, chief, vulnerability and officer.
- Q8: What topics does the CS0-002: CompTIA CySA Certification Exam (CS0-002) exam cover?
- A: Questions in our CS0-002: CompTIA CySA Certification Exam (CS0-002) bank cluster around analyst, ciso, chief, vulnerability, officer, reviewing, hard and compromised. Working through the full set is the quickest way to find which of these you are weakest on.
- Q9: How should I prepare for CS0-002: CompTIA CySA Certification Exam (CS0-002)?
- A: Work through the CS0-002: CompTIA CySA Certification Exam (CS0-002) practice questions here, checking your answer on each one, then sit the practice test to rehearse the exam under timed conditions before the real thing.
- Q10: Are these real CS0-002: CompTIA CySA Certification Exam (CS0-002) exam questions?
- A: They are drawn from officially released past questions and from community members who have sat CS0-002: CompTIA CySA Certification Exam (CS0-002). Answers are verified and updated weekly.
- Q11: Where do I register for the CS0-002: CompTIA CySA Certification Exam (CS0-002) exam?
- A: Register through CompTIA directly at https://www.comptia.org/certifications. Exampractice is not affiliated with CompTIA and does not administer the exam.
- Q12: Is there a free CS0-002: CompTIA CySA Certification Exam (CS0-002) sample?
- A: Yes. Every CS0-002: CompTIA CySA Certification Exam (CS0-002) page shows a free sample of real questions. Upgrading opens the full bank and the practice test.
- Q13: What are CompTIA Certification Exams?
- A: CompTIA Certification Exams validate your expertise in various IT disciplines, including networking, security, cloud computing, and IT support. These certifications demonstrate your proficiency in applying best practices and industry standards to manage and troubleshoot IT environments.
- Q14: Why should I pursue CompTIA Certification?
- A: CompTIA Certification enhances your professional credibility, showcasing your skills and knowledge in essential IT areas. This can lead to better job opportunities, higher salaries, and career advancement in IT support, networking, cybersecurity, and cloud computing fields.
- Q15: What are the benefits of CompTIA Certification?
- A: Benefits include recognition as a certified IT professional, improved job performance, access to exclusive resources, continuing education opportunities, and staying current with the latest IT industry trends and best practices.
- Q16: Who should take CompTIA Certification Exams?
- A: IT professionals, network administrators, cybersecurity experts, cloud engineers, and anyone involved in managing and supporting IT infrastructure should consider these certifications to validate their expertise and advance their careers.
- Q17: What types of CompTIA Certification Exams are available?
- A: CompTIA offers various certification paths, including:
- Q18: How do I prepare for CompTIA Certification Exams?
- A: Preparation can include official CompTIA training courses, study guides, practice exams, online tutorials, and hands-on experience in relevant IT disciplines.
- Q19: Where can I take CompTIA Certification Exams?
- A: CompTIA Certification Exams can be taken at authorized Pearson VUE testing centers worldwide or online, providing flexibility to fit your schedule and location.
- Q20: How do CompTIA Certifications impact my career?
- A: CompTIA Certifications significantly boost your career by demonstrating your expertise to employers, making you a more competitive candidate for advanced roles and promotions in IT support, networking, cybersecurity, and cloud computing.
- Q21: Are there any prerequisites for CompTIA Certification Exams?
- A: Some exams may have prerequisites, such as foundational knowledge or prior certifications. Check the specific requirements for each certification path on the CompTIA website.
- Q22: How often do I need to recertify for CompTIA Certifications?
- A: CompTIA Certifications typically require recertification every three years to ensure that certified professionals stay updated with the latest IT technologies and industry practices.



