1.2 Given a scenario, analyze indicators of potentially malicious activity.
Objective 1.2 sits in Security Operations, which carries 33% of the CySA+ exam. The questions below are original, written from the official objective title above, and each explanation cites the CompTIA page it rests on.
Objective title verbatim from the official objectives. CompTIA exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
An analyst finds regular HTTPS POSTs to an unfamiliar domain, each returning short encoded replies at fixed intervals. Which activity best fits?
Correct.
Concept
Adversaries hide command channels inside protocols that are already ubiquitous, so the traffic blends with legitimate web flows. Regular timing and command-shaped exchanges give the beacon away, not the protocol.
Why A
ATT&CK describes web-protocol C2 as embedding commands and their results inside HTTP/S traffic to mimic expected flows; the steady interval and short encoded responses are the beaconing pattern.
Now you: objective 1.2 questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
A workstation beacons over HTTPS. An analyst proposes blocking the destination port to stop it. What is the flaw in that plan?
Sample question 2 of 3
A file named svch0st.exe runs from a user's Downloads folder and spawns network connections. Which technique does the naming suggest?
Sample question 3 of 3
An analyst sees the legitimate archiver renamed and executed from a temp directory just before a large outbound transfer. Which masquerading form is this?
Full CySA+ question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
Read the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.
More objectives in Security Operations
- 1.1 1.1 Explain the importance of system and network architecture concepts in security operations.
- 1.3 1.3 Given a scenario, use appropriate tools or techniques to determine malicious activity.
- 1.4 1.4 Compare and contrast threat-intelligence and threat-hunting concepts.
- 1.5 1.5 Explain the importance of efficiency and process improvement in security operations.