Flashcards
CySA+ flashcards
Flashcards for the CS0-004 terms that sit side by side and get swapped: Nmap flags, filter syntax, indicator types, framework phases, scoring systems and security operations center (SOC) metrics. Open a card only after you have said the back aloud. Two cards lead to longer pages: CVSS vs EPSS and MTTD vs MTTR vs MTTC. To compare decks and books, see the CySA+ prep comparison; to fit the deck into a schedule, use the CySA+ study plan.
The deck: tools, frameworks, scoring and metrics
nmap -sS
SYN scan, also called half-open: Nmap sends a SYN, reads the reply and never completes the handshake.nmap -sT
TCP connect scan: the full three-way handshake through the operating system. Slower and easier to log than-sS.nmap -sU
UDP scan. Use it for services such as DNS and SNMP that a TCP scan never sees.nmap -sV and nmap -O
-sVprobes open ports for service versions;-Oguesses the operating system.nmap -Pn
Skips host discovery and treats every target as up. Use it when ping is blocked but services may still listen.Nmap port state: filtered
Nmap got no answer it can trust, usually because a firewall drops the probes. It does not mean the port is closed.tcpdump -n and -w
-nskips name resolution;-w file.pcapwrites raw packets for later.-rreads them back.Capture filter vs display filter
Capture (BPF, tcpdump):host 192.0.2.10 and port 53. Display (Wireshark):ip.addr==192.0.2.10 && dns. Different syntax.Zeek
A network security monitor that writes structured logs such asconn.loganddns.log. It records; Snort and Suricata alert on rules.YARA
Pattern rules matched against files or memory to classify malware. Network rules belong to Snort and Suricata.LOLBins
Signed, built-in binaries (certutil, mshta, rundll32) abused to download or run code. A Microsoft signature does not make the activity safe.Impossible travel
Two sign-ins on one account from places too far apart for the time between them. Check VPN and proxy egress before you call it compromise.An unescaped dot in a regex
Matches any character:192.0.2.1also matches192a0b2c1. Write192\.0\.2\.1.Pyramid of Pain, bottom to top
Hash values, IP addresses, domain names, network and host artifacts, tools, tactics, techniques and procedures (TTPs). Higher levels cost the attacker more to change.Atomic, computed, behavioral indicators
Atomic: an IP, domain or email address. Computed: a file hash or regex. Behavioral: a pattern that combines them, close to TTPs.Cyber Kill Chain, in order
Reconnaissance, weaponization, delivery, exploitation, installation, command and control, actions on objectives.Diamond Model vertices
Adversary, capability, infrastructure, victim: four corners describing one intrusion event.ATT&CK tactic vs technique
Tactic = the attacker's goal (TA codes); technique = how it is reached (T codes). As of ATT&CK v19, TA0005 is named Stealth, formerly Defense Evasion.CVSS v4.0 Attack Requirements (AT)
A base metric new in v4.0: conditions on the target that must hold for the exploit to work, such as a specific configuration or a race to win.CVSS vs EPSS
CVSS (Common Vulnerability Scoring System) rates severity from 0 to 10. EPSS (Exploit Prediction Scoring System) gives the probability, 0 to 1, of exploitation in the next 30 days.KEV
CISA's Known Exploited Vulnerabilities catalog: proof of exploitation in the wild, which moves a finding up the queue.Credentialed scan
The scanner logs in, so it sees missing patches and local settings with fewer false positives. How intrusive it is depends on the checks you enable.Compensating control
A documented substitute when you cannot patch: segmentation, a web application firewall, extra monitoring. Validate it; it is not the fix.Risk transfer
Moving the financial impact elsewhere, usually insurance or a contract. Accountability stays with the organization.Chain of custody
The record of who held the evidence, when and why, from collection on. Hash at collection and check the hash at each hand-off.MTTD, MTTR, MTTC
Mean time to detect; to respond or to remediate (both are MTTR, so spell out which); to close (MTTC, CS0-004 objective 4.2). Each clock starts and stops at a different event.NIST SP 800-61r3
NIST's incident response guidance, April 2025. It replaced SP 800-61r2 and maps response to the CSF 2.0 functions; CS0-004 lists its own seven steps.
How to work the deck
Run the deck in one pass and sort as you go: cards you answered cleanly, cards you hesitated on, cards you missed. Next session, start with the missed pile and finish with one clean pass of the whole deck.
The tool cards pay off on performance-based questions (PBQs), where you read output instead of recalling a definition. Say what the flag does and what the output would look like, then flip.
The framework cards have longer pages behind them: the Pyramid of Pain page and the attack frameworks area. Tool flags are drilled further in analysis tools.
What the port-state card looks like in output
$ nmap -sS -sV -Pn 192.0.2.10Nmap scan report for 192.0.2.10Host is up (0.0040s latency).PORT STATE SERVICE VERSION22/tcp open ssh OpenSSH 9.x80/tcp closed http443/tcp open https nginx3389/tcp filtered ms-wbt-serverNmap done: 1 IP address (1 host up) scannedLine 8: no reply came back for 3389, so Nmap cannot tell open from closed. Line 6: the host answered with a reset, so the port is reachable and nothing listens.
Cards that depend on a versionTrap
- ATT&CK tactic names: v19 renamed TA0005 to Stealth; older books still say Defense Evasion.
- CVSS v4.0 has Threat metrics; CVSS v3.1 had Temporal. The CVSS v4.0 vs v3.1 page reads both vectors.
- NIST incident response: NIST SP 800-61r3 (April 2025) replaced the four-phase NIST SP 800-61r2 cycle.
Study between shifts
This site's practice app puts CySA+ questions on your phone. Available for iPhone and Android.