Triage BoardGet the app

Flashcards

CySA+ flashcards

Flashcards for the CS0-004 terms that sit side by side and get swapped: Nmap flags, filter syntax, indicator types, framework phases, scoring systems and security operations center (SOC) metrics. Open a card only after you have said the back aloud. Two cards lead to longer pages: CVSS vs EPSS and MTTD vs MTTR vs MTTC. To compare decks and books, see the CySA+ prep comparison; to fit the deck into a schedule, use the CySA+ study plan.

The deck: tools, frameworks, scoring and metrics

  1. nmap -sS
    SYN scan, also called half-open: Nmap sends a SYN, reads the reply and never completes the handshake.
  2. nmap -sT
    TCP connect scan: the full three-way handshake through the operating system. Slower and easier to log than -sS.
  3. nmap -sU
    UDP scan. Use it for services such as DNS and SNMP that a TCP scan never sees.
  4. nmap -sV and nmap -O
    -sV probes open ports for service versions; -O guesses the operating system.
  5. nmap -Pn
    Skips host discovery and treats every target as up. Use it when ping is blocked but services may still listen.
  6. Nmap port state: filtered
    Nmap got no answer it can trust, usually because a firewall drops the probes. It does not mean the port is closed.
  7. tcpdump -n and -w
    -n skips name resolution; -w file.pcap writes raw packets for later. -r reads them back.
  8. Capture filter vs display filter
    Capture (BPF, tcpdump): host 192.0.2.10 and port 53. Display (Wireshark): ip.addr==192.0.2.10 && dns. Different syntax.
  9. Zeek
    A network security monitor that writes structured logs such as conn.log and dns.log. It records; Snort and Suricata alert on rules.
  10. YARA
    Pattern rules matched against files or memory to classify malware. Network rules belong to Snort and Suricata.
  11. LOLBins
    Signed, built-in binaries (certutil, mshta, rundll32) abused to download or run code. A Microsoft signature does not make the activity safe.
  12. Impossible travel
    Two sign-ins on one account from places too far apart for the time between them. Check VPN and proxy egress before you call it compromise.
  13. An unescaped dot in a regex
    Matches any character: 192.0.2.1 also matches 192a0b2c1. Write 192\.0\.2\.1.
  14. Pyramid of Pain, bottom to top
    Hash values, IP addresses, domain names, network and host artifacts, tools, tactics, techniques and procedures (TTPs). Higher levels cost the attacker more to change.
  15. Atomic, computed, behavioral indicators
    Atomic: an IP, domain or email address. Computed: a file hash or regex. Behavioral: a pattern that combines them, close to TTPs.
  16. Cyber Kill Chain, in order
    Reconnaissance, weaponization, delivery, exploitation, installation, command and control, actions on objectives.
  17. Diamond Model vertices
    Adversary, capability, infrastructure, victim: four corners describing one intrusion event.
  18. ATT&CK tactic vs technique
    Tactic = the attacker's goal (TA codes); technique = how it is reached (T codes). As of ATT&CK v19, TA0005 is named Stealth, formerly Defense Evasion.
  19. CVSS v4.0 Attack Requirements (AT)
    A base metric new in v4.0: conditions on the target that must hold for the exploit to work, such as a specific configuration or a race to win.
  20. CVSS vs EPSS
    CVSS (Common Vulnerability Scoring System) rates severity from 0 to 10. EPSS (Exploit Prediction Scoring System) gives the probability, 0 to 1, of exploitation in the next 30 days.
  21. KEV
    CISA's Known Exploited Vulnerabilities catalog: proof of exploitation in the wild, which moves a finding up the queue.
  22. Credentialed scan
    The scanner logs in, so it sees missing patches and local settings with fewer false positives. How intrusive it is depends on the checks you enable.
  23. Compensating control
    A documented substitute when you cannot patch: segmentation, a web application firewall, extra monitoring. Validate it; it is not the fix.
  24. Risk transfer
    Moving the financial impact elsewhere, usually insurance or a contract. Accountability stays with the organization.
  25. Chain of custody
    The record of who held the evidence, when and why, from collection on. Hash at collection and check the hash at each hand-off.
  26. MTTD, MTTR, MTTC
    Mean time to detect; to respond or to remediate (both are MTTR, so spell out which); to close (MTTC, CS0-004 objective 4.2). Each clock starts and stops at a different event.
  27. NIST SP 800-61r3
    NIST's incident response guidance, April 2025. It replaced SP 800-61r2 and maps response to the CSF 2.0 functions; CS0-004 lists its own seven steps.

How to work the deck

Run the deck in one pass and sort as you go: cards you answered cleanly, cards you hesitated on, cards you missed. Next session, start with the missed pile and finish with one clean pass of the whole deck.

The tool cards pay off on performance-based questions (PBQs), where you read output instead of recalling a definition. Say what the flag does and what the output would look like, then flip.

The framework cards have longer pages behind them: the Pyramid of Pain page and the attack frameworks area. Tool flags are drilled further in analysis tools.

What the port-state card looks like in output

nmapFictional scan of a documentation-range host (RFC 5737)
$ nmap -sS -sV -Pn 192.0.2.10Nmap scan report for 192.0.2.10Host is up (0.0040s latency).PORT     STATE    SERVICE  VERSION22/tcp   open     ssh      OpenSSH 9.x80/tcp   closed   http443/tcp  open     https    nginx3389/tcp filtered ms-wbt-serverNmap done: 1 IP address (1 host up) scanned

Line 8: no reply came back for 3389, so Nmap cannot tell open from closed. Line 6: the host answered with a reset, so the port is reachable and nothing listens.

Cards that depend on a versionTrap

  • ATT&CK tactic names: v19 renamed TA0005 to Stealth; older books still say Defense Evasion.
  • CVSS v4.0 has Threat metrics; CVSS v3.1 had Temporal. The CVSS v4.0 vs v3.1 page reads both vectors.
  • NIST incident response: NIST SP 800-61r3 (April 2025) replaced the four-phase NIST SP 800-61r2 cycle.

Study between shifts

This site's practice app puts CySA+ questions on your phone. Available for iPhone and Android.