← All exams
Home · CompTIA Cybersecurity Analyst (CySA+)

CompTIA Cybersecurity Analyst (CySA+)

This exam is for cybersecurity practitioners who perform data analysis and interpret the results to identify vulnerabilities, threats, and risks to an organization. Passing validates the skills required for roles like Security Analyst, Threat Intelligence Analyst, and Vulnerability Analyst.

Pass mark 750/85 165 minutes Real test fee approx CompTIA How many can I get wrong?
Sit a full mock under the clock at least once. Nerves are half the battle.
Free practice questions
Try 3 real CompTIA Cybersecurity Analyst (CySA+) questions
Have a go, then reveal the worked explanation. A taster from a bank of 207 original questions — unlock for unlimited drills and full timed mocks.
Q1. A security analyst is reviewing SIEM logs and notices a large number of failed login attempts from a single IP address targeting multiple user accounts. This activity is immediately followed by a single successful login. What type of attack is most likely occurring?
  • A.  SQL Injection
  • B.  Cross-Site Scripting (XSS)
  • C.  Password spraying
  • D.  Denial-of-Service (DoS)
Show answer & explanation
✓ Answer: C. Password spraying
The pattern of one source attempting to log into many accounts with a few common passwords, culminating in a success, is a hallmark of a password spraying attack.
Q2. An analyst is prioritizing vulnerabilities from a recent scan. A critical vulnerability has a CVSS base score of 9.8. However, the affected system is air-gapped and has no internet connectivity. Which CVSS metric group would best help the analyst adjust the priority of this finding?
  • A.  Base
  • B.  Temporal
  • C.  Environmental
  • D.  Exploitability
Show answer & explanation
✓ Answer: C. Environmental
The Environmental metric group allows an organization to customize the CVSS score based on the specific controls and context of their own environment, such as the asset's location (e.g., air-gapped).
Q3. A SIEM alert is triggered showing a user account attempting to log in to 20 different servers within one minute, with all attempts failing due to bad passwords. This is immediately followed by a successful login to one of the servers from a new IP address. This sequence is a strong indicator of what type of attack?
  • A.  Denial-of-Service (DoS)
  • B.  Phishing campaign
  • C.  Password spraying attack
  • D.  SQL injection
Show answer & explanation
✓ Answer: C. Password spraying attack
Password spraying involves an attacker trying a small number of common passwords against many different user accounts. The pattern of many failed logins across multiple systems followed by a success is characteristic of this technique.
Exam format (pass mark, question count, timing) verified against CompTIA. Questions are our own, not the official paper.
Start here
Ten questions to see where you stand
Two minutes, no timer, marked the moment you finish with every answer explained. Then you'll know which topics need the work before you sit a full mock.
Exam mode
Full mock exam
85 random questions, real timing, marked against the official pass mark. Different every time.
Create a free account for a full mock
No card needed. A free account unlocks a full timed mock and 3 drills on every exam.
Practice material only. This is revision practice, not official training, assessment or certification, and not a substitute for the required course or supervised experience. Always confirm the current requirements with the official awarding body or test provider before relying on it.
Try it free
Topic drills
Ten quick questions on one topic, marked instantly with explanations.
1 free drill left — then a free account unlocks 3 + a full mock.
Security Operations · 30
Vulnerability Management · 30
Incident Response and Management · 30
Reporting and Communication · 29
Threat Intelligence · 29
Log and Data Analysis · 19
Digital Forensics · 20
Compliance and Assessment · 20
CompTIA Cybersecurity Analyst (CySA+) — common questions
Frequently asked
How many questions are in the CompTIA Cybersecurity Analyst (CySA+)?
The exam has 85 questions. Every Revision Robin mock uses the same 85-question format so your practice matches the real thing.
What is the pass mark for the CompTIA Cybersecurity Analyst (CySA+)?
You need 750 out of 85 correct to pass, which is about 882%. Our mocks mark you against this exact threshold.
How long do you get?
The test is timed at 165 minutes. Our full mock runs on the same clock so you can practise your pacing.
Are these the real exam questions?
No. Our questions are original and written to match the current syllabus, so they give realistic practice without copying the official paper. Every answer comes with a plain-English explanation. Always confirm current rules and content with CompTIA.
How much does the official test cost?
The official CompTIA fee is approx. Revision Robin practice is separate and helps you pass first time so you only pay that fee once.