CySA+ CS0-004 - Domain 1: Security Operations (34%)

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/75

flashcard set

Earn XP

Description and Tags

Built from CompTIA's official CS0-004 V4 exam objectives (v2.0)

Last updated 6:44 PM on 10/9/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

76 Terms

1
New cards

Logging concept: ingestion

Collecting logs from sources into a central platform such as a SIEM

2
New cards

Why does time synchronization (NTP) matter for logging?

Event timestamps must line up across systems so you can build an accurate timeline and correlate events

3
New cards

Log integrity and security

Protecting logs from tampering (hashing, write-once storage, restricted access) so they stay trustworthy as evidence

4
New cards

Log retention

How long logs are kept, set by policy and regulation (e.g., PCI DSS) and storage cost

5
New cards

System hardening

Reducing attack surface: remove unneeded services/software, apply patches, enforce secure configuration baselines

6
New cards

Zero Trust Network Architecture (ZTNA) core idea

Never trust, always verify: authenticate and authorize every request regardless of network location, with least privilege

7
New cards

SASE (Secure Access Service Edge)

Cloud-delivered combination of network (SD-WAN) and security services (SWG, CASB, ZTNA, firewall) at the edge

8
New cards

Hybrid cloud

A mix of on-premises infrastructure and public/private cloud services working together

9
New cards

Cloud native

Applications built to run in the cloud using services like containers, microservices, and managed APIs

10
New cards

Virtualization vs. containerization

VMs virtualize hardware and run a full guest OS each; containers share the host OS kernel and are lighter weight

11
New cards

Why are APIs a security concern?

They expose application functions and data; weak authentication, excessive data exposure, and missing rate limits are common issues

12
New cards

PAM (Privileged Access Management)

Controls, vaults, and monitors accounts with elevated rights (admin/root), often with just-in-time access and session recording

13
New cards

Secrets management

Securely storing and rotating credentials, API keys, and certificates in a vault instead of hard-coding them

14
New cards

SSO (Single Sign-On)

One authentication grants access to multiple applications

15
New cards

MFA (Multifactor Authentication)

Requires two or more factor types: something you know, have, or are

16
New cards

OT / ICS / SCADA

Operational technology: systems that control physical processes. ICS = industrial control systems; SCADA = supervisory control and data acquisition

17
New cards

Why are OT/ICS networks hard to patch?

They are availability-critical, often legacy, and downtime can affect physical safety, so they are usually segmented and monitored instead

18
New cards

MDM (Mobile Device Management)

Enforces policy on mobile devices: enrollment, encryption, app control, remote wipe

19
New cards

Network-related indicator: rogue device

An unauthorized device on the network, e.g., unknown MAC/IP, rogue access point

20
New cards

Network-related indicator: enumeration

Scanning or probing to list hosts, ports, services, or accounts (a reconnaissance sign)

21
New cards

Network indicator: traffic on unexpected ports

Services or outbound connections on unusual ports can indicate C2, tunneling, or an unauthorized service

22
New cards

Host-related indicators of compromise

Resource spikes (CPU/disk/network), unauthorized software, suspicious/rogue processes, file system changes, data exfiltration

23
New cards

LOLBins

Living Off the Land Binaries: legitimate built-in tools (powershell.exe, certutil, mshta, rundll32) abused by attackers to avoid detection

24
New cards

Application-related indicators

Service disruption and anomalous activity such as unexpected errors, new accounts, or unusual requests

25
New cards

Cloud-related indicators

Anomalous activity and resource compromise, e.g., unexpected instances (cryptomining), odd API calls, new access keys

26
New cards

Typosquatting

Registering a lookalike domain with a common misspelling to trick users

27
New cards

URL shorteners as an indicator

They hide the real destination, so they are commonly used in phishing links

28
New cards

Impossible travel

Logins from locations too far apart for the time elapsed, suggesting account compromise

29
New cards

Identity-based indicators

IAM account compromise, unauthorized access, impossible travel

30
New cards

BEC (Business Email Compromise)

Fraud via impersonating or compromising a business email account to trick staff into payments or data disclosure

31
New cards

CyberChef

Browser tool for decoding, parsing, and transforming data (Base64, hex, XOR, etc.) - the "Swiss Army knife" for analysts

32
New cards

Wireshark vs. tcpdump

Wireshark: GUI packet analyzer. tcpdump: command-line packet capture

33
New cards

Snort and Suricata

Open-source network IDS/IPS engines that match traffic against rules

34
New cards

Zeek

Network security monitor that turns traffic into rich logs (conn, dns, http, etc.) rather than only signature alerts

35
New cards

SIEM

Aggregates and correlates logs from many sources for alerting, search, and investigation

36
New cards

OTX, MISP, OpenCTI

Threat intelligence platforms. OTX = Open Threat Exchange; MISP = Malware Information Sharing Platform; OpenCTI = Open Cyber Threat Intelligence

37
New cards

EDR vs. XDR

EDR monitors and responds on endpoints. XDR extends detection/response across endpoint, network, email, and cloud

38
New cards

WHOIS

Lookup of domain registration data (registrar, dates, contacts)

39
New cards

AbuseIPDB

Community database for checking an IP address's abuse reputation

40
New cards

GeoIP

Maps an IP address to an approximate geographic location

41
New cards

strings (file analysis)

Extracts printable text from a binary; may reveal URLs, commands, or file names

42
New cards

VirusTotal

Service that scans files, hashes, URLs, or IPs against many AV engines and reputation sources

43
New cards

YARA

Rule-based tool for identifying and classifying malware by patterns in files or memory

44
New cards

Joe Sandbox and Cuckoo Sandbox

Sandboxes that run suspicious files in an isolated environment to observe behavior

45
New cards

MXToolbox

Email/DNS analysis: check MX, SPF, DKIM, DMARC records and blacklists

46
New cards

UEBA

User and entity behavior analytics: baselines normal behavior and flags anomalies. OpenUBA is an open-source example

47
New cards

Common structured data formats in security tools

JSON, XML, YAML, and EVTX (Windows event log format)

48
New cards

EVTX

Windows Event Log file format

49
New cards

Scripting languages to be able to read on the exam

Python, PowerShell, and shell scripts

50
New cards

Pattern recognition tools

Regular expressions and interpreting suspicious commands (e.g., encoded PowerShell, certutil downloads)

51
New cards

APT (Advanced Persistent Threat)

Well-resourced, usually state-linked actor that maintains long-term stealthy access to a target

52
New cards

Insider threat

Risk from someone with legitimate access (malicious or negligent) misusing it

53
New cards

MITRE ATT&CK

Knowledge base of adversary tactics, techniques, and procedures (TTPs) used to map and hunt behavior

54
New cards

Pyramid of Pain

Ranks IoCs by how painful they are for an attacker to change: hashes (trivial) up to TTPs (tough)

55
New cards

Pyramid of Pain order, easiest to hardest for attacker to change

Hash values, IP addresses, domain names, network/host artifacts, tools, TTPs

56
New cards

Heat map (threat intel)

Visual of which ATT&CK techniques or areas are most observed or most covered by detections

57
New cards

Attribution

Identifying who is behind an attack; often low confidence and not required to respond

58
New cards

Confidence level factors for intel

Timeliness, relevance, accuracy

59
New cards

OSINT vs. closed-source intelligence

OSINT = publicly available. Closed-source = restricted/paid/proprietary sources. Intel sharing = trusted exchange like ISACs

60
New cards

Atomic vs. behavioral IoC

Atomic: single data point (IP, hash, domain). Behavioral: pattern of actions (e.g., Office spawning PowerShell)

61
New cards

IoC lifecycle steps

Collection, analysis, application/usage

62
New cards

STRIDE

Threat model: Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege

63
New cards

Cyber deception

Honeypots, honeytokens, and decoys that lure and detect attackers

64
New cards

Playbook vs. runbook

Playbook: response process for a scenario type. Runbook: step-by-step operational procedure for a task, often automatable

65
New cards

SOAR

Security Orchestration, Automation, and Response: automates repetitive tasks and workflows across tools

66
New cards

IaC (Infrastructure as Code)

Defining infrastructure in version-controlled code for repeatable, auditable deployments

67
New cards

Data enrichment

Adding context (reputation, geolocation, asset owner) to alerts to speed triage

68
New cards

Rule/alert tuning

Adjusting detection rules to reduce false positives while keeping true detections

69
New cards

API vs. webhook vs. plug-in

API: request/response interface. Webhook: sends an event to a URL when something happens. Plug-in: add-on extending a tool

70
New cards

AI risk: hallucination

The model produces confident but false output; verify before acting

71
New cards

AI risk: model poisoning

Corrupting training data or the model to alter its behavior

72
New cards

AI risk: malicious prompts

Prompt injection or crafted inputs that manipulate the model's output or actions

73
New cards

AI risk: data exposure

Sensitive data entered into AI tools may be leaked or retained

74
New cards

AI governance

Legal/regulatory compliance and AI usage policies

75
New cards

AI use cases in security operations

Comparing artifacts, analyzing logs, document creation, incident investigation, event correlation, automation and orchestration

76
New cards