Topic module

Attack Frameworks, Detection and Analysis

Incident response questions cover attack methodology frameworks, MITRE ATT&CK, kill chain thinking, detection, triage, scoping, evidence, and analysis.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for CompTIA CySA+

Treat each CySA+ item as an analyst decision: identify telemetry, scope risk, validate findings, contain impact, communicate clearly, and improve controls.

Core concepts

Concept 1

Attack frameworks help analysts organize adversary behavior, detection gaps, and response priorities.

Exam cue: Map observed behavior to tactics, techniques, scope, and timeline.

Concept 2

Detection and analysis should establish what happened, when, where, affected assets, data exposure, and confidence.

Exam cue: Preserve evidence while triaging and scoping.

Concept 3

Triage should separate likely incidents from noise while preserving evidence and escalation paths.

Exam cue: Use confidence and impact to escalate appropriately.

Risk pitfalls and guardrails

Erasing evidence before scoping the incident.

Guardrail: Avoid answers that destroy evidence, trust scanner output blindly, over-automate containment, omit stakeholders, or report raw tool noise as strategy.

Declaring containment before understanding affected assets.

Guardrail: Avoid answers that destroy evidence, trust scanner output blindly, over-automate containment, omit stakeholders, or report raw tool noise as strategy.

Using a framework label without tying it to observed behavior.

Guardrail: Avoid answers that destroy evidence, trust scanner output blindly, over-automate containment, omit stakeholders, or report raw tool noise as strategy.

Memory anchors

MITRE ATT&CK

MITRE ATT&CK organizes adversary tactics and techniques for analysis and detection.

Kill Chain

A kill chain describes stages of an attack from preparation through objective completion.

Diamond Model

The Diamond Model relates adversary, capability, infrastructure, and victim.

Triage

Triage prioritizes alerts or events based on evidence, impact, and confidence.

Scope

Scope identifies affected systems, accounts, data, networks, and time period.

Timeline

A timeline orders events to understand sequence and root activity.

Evidence Handling

Evidence handling preserves integrity and supports later investigation.

Incident Declaration

Incident declaration formally recognizes an event as an incident requiring response process.

Confidence Level

Confidence level communicates certainty based on evidence quality and correlation.

Impact

Impact describes business, operational, data, legal, or safety consequences of an incident.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

Aster Bank observes credential dumping followed by remote service creation on domain-controller and wants reusable behavioral coverage. Which action is the BEST next step? No response action has been taken yet.

Analysts at Canyon Transit blocked delivery of a malicious attachment, but telemetry suggests a payload may already have executed on finance-workstation. Which recommendation is MOST appropriate? No response action has been taken yet.

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.