Free CS0-002: CompTIA CySA Certification Exam (CS0-002) Exam Questions and Answers
This exam retired on 5 December 2023. It was replaced by CS0-003: CompTIA CySA (CS0-003). The questions here still cover most of the same ground, and the new exam’s own page has the current bank.
Replaces CS0-001: CompTIA CySA Certification Exam. Questions from the earlier version are also in this bank.
CompTIA CySA Certification Exam (CS0-002) is exam CS0-002, part of the CompTIA certification programme. CompTIA exam codes carry a family prefix and a version number — SY0- for Security+, N10- for Network+, CS0- for CySA+, 220- for A+ — and most Plus-series exams allow 90 minutes for up to 90 questions, mixing multiple choice with performance-based items in a simulated environment.
Candidates comparing CS0-002 exam dumps, ExamTopics and other CS0-002 practice tests use this page for the answers and explanations behind each question. Download the free CS0-002 PDF, then sit the timed CS0-002 exam simulation before booking with CompTIA.
Last updated: September 28, 2026
- Exam code
- CS0-002
- Provider
- CompTIA
- Questions in our bank
- 1000+
- Free to read
- First 10, with answers
- Official page
- Official Exam website
- Our test mode duration & pass mark
- 130 mins · 70%
Recommended: Switch to Test Mode to start a practice test that simulates the real exam experience.
Question #7
An organization has the following risk mitigation policies • Risks without compensating controls will be mitigated first it the nsk value is greater than $50,000 • Other nsk mitigation will be pnontized based on risk value. The following risks have been identified: Which of the following is the ordei of priority for risk mitigation from highest to lowest?

Correct answer: C
Explanation
The order of priority for risk mitigation from highest to lowest is C, B, A, D. This order is based on applying the risk mitigation policies of the organization. According to the first policy, risks without compensating controls will be mitigated first if the risk value is greater than $50,000. Risk C has no compensating controls and a risk value of $75,000, so it is the highest priority. Risk B also has no compensating controls, but a risk value of $40,000, so it is the second priority. According to the second policy, other risk mitigation will be prioritized based on risk value. Risk A has a risk value of $60,000 and a compensating control of encryption, so it is the third priority. Risk D has a risk value of $50,000 and a compensating control of backup power supply, so it is the lowest priority.
Continue with CS0-002: CompTIA CySA Certification Exam (CS0-002)
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in CS0-002: CompTIA CySA Certification Exam (CS0-002), the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Discussion
Explain your reasoning, not just the letterBrowse the free questions by topic
More CS0-002 questions
- Question 1Due to a rise m cyberattackers seeking PHI, a healthcare company that collects highly sensitive data from millions of…
- Question 2Which of the following is a vulnerability associated with the Modbus protocol?
- Question 3A security technician configured a NIDS to monitor network traffic. Which of the following is a condition in which…
- Question 4An analyst reviews the most recent vulnerability management report and notices a firewall with 99.98% required uptime…
- Question 5While reviewing a vulnerability assessment, an analyst notices the following issue is identified in the report: this…
All CS0-002: CompTIA CySA Certification Exam (CS0-002) practice questions →
Other CompTIA certifications
Reviews
Write a review★★★★★
Exam Practice is worth every penny. The mock exams are realistic, and the feedback helped me focus on key areas.
Amit SharmaVerified buyer
★★★★★
I highly recommend Exam Practice. The feedback after each test helped me improve significantly, and I passed my exams easily.
Oscar NyströmVerified buyer
★★★★★
This platform is a lifesaver. The practice questions and explanations are so detailed. It’s the best study tool I’ve ever used.
Hannah SmithVerified buyer
FAQ
Learn More: https://www.comptia.org/certifications
- Q1: Is the CompTIA CySA+ CS0-002 exam still available?
- A: No. CS0-002 retired on December 5, 2023 and was replaced by CS0-003, which launched on June 6, 2023. CompTIA has announced that CS0-003 will itself retire in English on December 22, 2026, with a new CySA+ version taking over.
- Q2: How many questions were on the CS0-002 exam and how long was it?
- A: CS0-002 had a minimum of 85 multiple-choice and performance-based questions and a 165-minute time limit. The current CS0-003 exam has a maximum of 85 questions in the same 165 minutes.
- Q3: What was the passing score for CS0-002?
- A: The passing score was 750 on a scale of 100 to 900, which is also the passing score for CS0-003.
- Q4: What domains did the CS0-002 exam cover and how were they weighted?
- A: CS0-002 was weighted Threat and Vulnerability Management 22%, Software and Systems Security 18%, Security Operations and Monitoring 25%, Incident Response 22% and Compliance and Assessment 13%. CS0-003 uses four domains: Security Operations 33%, Vulnerability Management 30%, Incident Response Management 20% and Reporting and Communication 17%.
- Q5: What experience did CompTIA recommend for CS0-002?
- A: CompTIA recommended four years of hands-on experience in a technical cybersecurity job role plus Security+ and Network+ or equivalent knowledge and experience.
- Q6: In what languages is the current CySA+ exam offered?
- A: As of October 2026, CS0-003 is offered in English, Japanese, Portuguese and Spanish. The English version retires on December 22, 2026 and the translated versions on March 23, 2027.
- Q7: What is the CS0-002: CompTIA CySA Certification Exam (CS0-002) exam?
- A: CS0-002: CompTIA CySA Certification Exam (CS0-002) is a CompTIA certification exam. Judging by the questions in our bank, it concentrates on analyst, ciso, chief, vulnerability and officer.
- Q8: What topics does the CS0-002: CompTIA CySA Certification Exam (CS0-002) exam cover?
- A: Questions in our CS0-002: CompTIA CySA Certification Exam (CS0-002) bank cluster around analyst, ciso, chief, vulnerability, officer, reviewing, hard and compromised. Working through the full set is the quickest way to find which of these you are weakest on.
- Q9: How should I prepare for CS0-002: CompTIA CySA Certification Exam (CS0-002)?
- A: Work through the CS0-002: CompTIA CySA Certification Exam (CS0-002) practice questions here, checking your answer on each one, then sit the practice test to rehearse the exam under timed conditions before the real thing.
- Q10: Are these real CS0-002: CompTIA CySA Certification Exam (CS0-002) exam questions?
- A: They are drawn from officially released past questions and from community members who have sat CS0-002: CompTIA CySA Certification Exam (CS0-002). Answers are verified and updated weekly.
- Q11: Where do I register for the CS0-002: CompTIA CySA Certification Exam (CS0-002) exam?
- A: Register through CompTIA directly at https://www.comptia.org/certifications. Exampractice is not affiliated with CompTIA and does not administer the exam.
- Q12: Is there a free CS0-002: CompTIA CySA Certification Exam (CS0-002) sample?
- A: Yes. Every CS0-002: CompTIA CySA Certification Exam (CS0-002) page shows a free sample of real questions. Upgrading opens the full bank and the practice test.
- Q13: What are CompTIA Certification Exams?
- A: CompTIA Certification Exams validate your expertise in various IT disciplines, including networking, security, cloud computing, and IT support. These certifications demonstrate your proficiency in applying best practices and industry standards to manage and troubleshoot IT environments.
- Q14: Why should I pursue CompTIA Certification?
- A: CompTIA Certification enhances your professional credibility, showcasing your skills and knowledge in essential IT areas. This can lead to better job opportunities, higher salaries, and career advancement in IT support, networking, cybersecurity, and cloud computing fields.
- Q15: What are the benefits of CompTIA Certification?
- A: Benefits include recognition as a certified IT professional, improved job performance, access to exclusive resources, continuing education opportunities, and staying current with the latest IT industry trends and best practices.
- Q16: Who should take CompTIA Certification Exams?
- A: IT professionals, network administrators, cybersecurity experts, cloud engineers, and anyone involved in managing and supporting IT infrastructure should consider these certifications to validate their expertise and advance their careers.
- Q17: What types of CompTIA Certification Exams are available?
- A: CompTIA offers various certification paths, including:
- Q18: How do I prepare for CompTIA Certification Exams?
- A: Preparation can include official CompTIA training courses, study guides, practice exams, online tutorials, and hands-on experience in relevant IT disciplines.
- Q19: Where can I take CompTIA Certification Exams?
- A: CompTIA Certification Exams can be taken at authorized Pearson VUE testing centers worldwide or online, providing flexibility to fit your schedule and location.
- Q20: How do CompTIA Certifications impact my career?
- A: CompTIA Certifications significantly boost your career by demonstrating your expertise to employers, making you a more competitive candidate for advanced roles and promotions in IT support, networking, cybersecurity, and cloud computing.
- Q21: Are there any prerequisites for CompTIA Certification Exams?
- A: Some exams may have prerequisites, such as foundational knowledge or prior certifications. Check the specific requirements for each certification path on the CompTIA website.
- Q22: How often do I need to recertify for CompTIA Certifications?
- A: CompTIA Certifications typically require recertification every three years to ensure that certified professionals stay updated with the latest IT technologies and industry practices.



