PassYour
Try for freeSign in

CySA+ Glossary: Key Terms for the CS0-003 Exam

A plain-English glossary of the CySA+ CS0-003 terms that appear most - ATT&CK, CVSS, KEV, SOAR, UEBA, order of volatility and more, grouped by domain.

CySA+ glossary · 9 min read · updated 2026-09-05

CySA+ has its own working vocabulary - the tools, frameworks and forensic terms a SOC analyst uses daily. These are the terms the CS0-003 exam leans on most.

Threat and vulnerability management

MITRE ATT&CK - a knowledge base mapping real attacker techniques to tactics; the exam expects you to map observed behaviour to techniques and use the framework to prioritise detections. CVSS - vulnerability severity scoring from 0 to 10; use it with exploitability and exposure context, never alone. KEV - CISA's Known Exploited Vulnerabilities catalogue: anything on it gets remediation priority regardless of score.

IOC vs IOA - indicators of compromise prove an attack happened, indicators of attack suggest one is in progress. TIP - threat intelligence platform, where feeds are aggregated and enriched. Remediation vs mitigation - fixing the flaw versus reducing its exploitability while a fix is pending. Re-scan validation - proving the fix worked; the exam treats it as the closing step of every ticket.

Operations and monitoring

SIEM - centralised log collection, correlation and alerting. SOAR - Security Orchestration, Automation and Response: playbooks that execute response steps across tools. UEBA - user and entity behaviour analytics, anomaly detection on identities and hosts. EDR - endpoint detection and response with process-level telemetry and containment actions.

The data sources the exam cites constantly: firewall and DNS logs, NetFlow, full packet capture, endpoint process telemetry, identity and cloud logs. Normalisation and NTP time sync make cross-source correlation possible - questions test what breaks without them.

Incident response and forensics

IR phases - preparation, detection and analysis, containment, eradication, recovery, lessons learned (PICERL). Order of volatility - capture evidence in the order it disappears: RAM and running state before disk, disk before backups. Chain of custody - documented, unbroken evidence handling. Legal hold - preserving data for anticipated litigation.

Containment vs eradication - stopping the spread versus removing the foothold entirely. Playbook - the documented, rehearsed response for a scenario; SOAR automation is expected where it is reliable. Forensic artefacts the exam names: memory captures, disk images, log archives and network captures.

Frequently asked questions

How much terminology is on the CySA+ exam?
A lot, but it is working vocabulary rather than trivia: the exam shows artefacts and asks which term, tool or process applies. Learn each term with the artefact it appears in - a CVSS score inside a scan report, an ATT&CK technique inside a threat report.
Is MITRE ATT&CK required knowledge for CySA+?
Yes. CS0-003 expects fluency in mapping observed behaviour to ATT&CK tactics and techniques, and in using the framework to prioritise detections and communicate coverage gaps.
Where can I drill CySA+ terms with real questions?
The PassYour CySA+ track includes 179 questions with explanations mapped to the four domains and 16 lessons with flashcards, plus a free 10-question quiz to start with no account.

Keep reading for CySA+

PassYour is an independent study aid and is not affiliated with, endorsed by or sponsored by ISC2, CompTIA or Microsoft.

CySA+ Glossary: Key Terms for the CS0-003 Exam | PassYour CISSP