Glossary

CompTIA CySA+ (CS0-003) Glossary

By The Exam Atlas Editorial Team · Verified 2026-05-29

Plain-English definitions of the operations terms that recur in CySA+ study. Simplified for learning; CompTIA’s objectives are authoritative.

TermDefinition
SIEMA system that collects and correlates logs to detect and alert on threats.
SOCSecurity Operations Centre — the team that monitors and responds.
IoCIndicator of Compromise — evidence that a system was attacked.
TTPTactics, Techniques and Procedures used by an attacker.
Threat intelligenceInformation about threats used to inform detection and defence.
BaselineA profile of normal activity, used to detect anomalies.
False positiveAn alert that turns out not to be a real threat.
CVSSCommon Vulnerability Scoring System, rating severity 0–10.
CVECommon Vulnerabilities and Exposures — a catalogue of known flaws.
Vulnerability scanAn automated check for known weaknesses.
PrioritisationRanking vulnerabilities by real-world risk, not just score.
Incident responseThe organised approach to handling a security incident.
ContainmentSteps to stop an incident from spreading.
EradicationRemoving the cause of an incident.
Chain of custodyDocumented, unbroken handling of evidence.
MTTDMean Time To Detect an incident.
MTTRMean Time To Respond to or repair an incident.
SOARSecurity Orchestration, Automation and Response.
PlaybookA predefined set of response steps for a scenario.
EDREndpoint Detection and Response tooling.
Threat huntingProactively searching for threats that evaded detection.

Sources