Security Architecture, Logs and Threat Intelligence
CySA+ security operations starts with architecture context, log ingestion, time synchronization, IAM, encryption, data protection, threat intelligence, and hunting.
How to study for CompTIA CySA+
Treat each CySA+ item as an analyst decision: identify telemetry, scope risk, validate findings, contain impact, communicate clearly, and improve controls.
Core concepts
Concept 1
Analysts need architecture context to interpret telemetry and identify what normal or abnormal behavior means.
Exam cue: Correlate logs with architecture, identity, time, and data sensitivity.
Concept 2
Log ingestion and time synchronization enable accurate correlation across systems, networks, identities, and applications.
Exam cue: Use threat intelligence to prioritize and contextualize alerts.
Concept 3
Threat intelligence and hunting help analysts move from alert handling to proactive detection.
Exam cue: Separate threat hunting hypotheses from routine alert response.
Risk pitfalls and guardrails
Correlating events from systems with unsynchronized clocks.
Guardrail: Avoid answers that destroy evidence, trust scanner output blindly, over-automate containment, omit stakeholders, or report raw tool noise as strategy.
Treating every threat feed item as equally urgent.
Guardrail: Avoid answers that destroy evidence, trust scanner output blindly, over-automate containment, omit stakeholders, or report raw tool noise as strategy.
Ignoring architecture context when interpreting a single alert.
Guardrail: Avoid answers that destroy evidence, trust scanner output blindly, over-automate containment, omit stakeholders, or report raw tool noise as strategy.
Memory anchors
Log Ingestion
Log ingestion collects events from systems, networks, identities, applications, and security tools for analysis.
Time Synchronization
Time synchronization enables accurate event correlation across many sources.
Logging Level
Logging level controls event detail and can affect visibility, cost, and noise.
IAM Context
Identity and access context helps explain whether an action is expected or suspicious.
Encryption Context
Encryption context helps analysts understand data exposure and protection boundaries.
Sensitive Data
Sensitive data requires special monitoring, access controls, and response handling.
Threat Intelligence
Threat intelligence provides context about actors, tactics, indicators, and relevance.
IOC
An indicator of compromise is observable evidence that may suggest malicious activity.
TTP
Tactics, techniques, and procedures describe adversary behavior and tradecraft.
Threat Hunt
A threat hunt uses a hypothesis to proactively search for suspicious activity.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
Aster Bank placed its public customer-portal and database on the same flat subnet. A compromised web account is now reaching the database directly. Which action is the BEST next step? No response action has been taken yet.
At 02:14 UTC, Canyon Transit records a successful admin login to vpn-gateway. The same user is on approved leave, and the source 192.0.2.48 has never been used by that identity. Which recommendation is MOST appropriate? No response action has been taken yet.
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 317 U.S. exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
