Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

CYSA Exam Practice Test Questions And Answers Verified 100% Correct

Rating
-
Sold
-
Pages
8
Grade
A+
Uploaded on
01-06-2025
Written in
2024/2025

CYSA Exam Practice Test Questions And Answers Verified 100% Correct What are the phases of incident response? - ANSWER Preparation; Detection & Analysis; Containment, Eradication, & Recovery; and Post-Incident Activity What type of documents provide the detailed, tactical information that CSIRT members need when responding to an incident? - ANSWER Procedures What document serves as the cornerstone of an organization's incident response program? - ANSWER Incident Response Policy What type of threat consists of highly skilled and talented attackers focused on a specific objective? - ANSWER Advanced Persistent Threat (APT) What are the types of impact used to describe the scope of a security incident? - ANSWER Functional impact, economic impact, and recoverability effort What are the common attack vectors for security incidents? - ANSWER Common attack vectors for security incidents include external/removable media, attrition, the web, email, impersonation, improper usage, loss or theft of equipment, and other/unknown sources. What Linux command displays processes, memory utilization, and other detail about running programs? - ANSWER Top or ps What term is used to describe traffic sent to a command and control system by a PC that is part of a botnet? - ANSWER Beaconing What Windows tool provides information on memory, CPU, and disk use? - ANSWER Perfmon What protocol is used to gather information about and manage network devices? - ANSWER SNMP What Linux command allows you to list the files that are open by processes on a system? - ANSWER lsof What type of information is found in network flow data? - ANSWER Flow data provides information about the source and destination IP address, protocol, and total data sent. What protocol is used to ensure that all security devices on a network have synchronized clocks? - ANSWER NTP What tool can administrators use to determine the maximum bandwidth available on a network connection? - ANSWER iPerf What is the purpose of FTK, EnCase, SIFT, and the Sleuth Kit (TSK)? - ANSWER Forensic toolkits What type of device is designed to copy drives for forensic investigation, and then provide validation that the original drive and the content of the new drive match? - ANSWER Forensic drive duplicator Where can forensic analysts turn to find point-in-time information from prior actions on a Windows system? - ANSWER Volume shadow copies Where can forensic analysts turn to find information about logins, service start/stop events, and evidence of applications being - ANSWER Event logs What Linux utility is commonly used to clone drives in RAW format? - ANSWER dd What type of device can ensure that attaching a drive to a forensic copy device or workstation does not result in modifications - ANSWER Write blocker What Linux kernel modules allow forensic access to physical memory? - ANSWER fmem and LiME What tool provides a list of USB devices that have been connected to a Windows system? - ANSWER USB Historian What is the first action that incident responders should take after identifying a potential incident? - ANSWER Contain the damage Network segmentation, isolation, and removal of affected systems are examples of ___________ strategies - ANSWER Containment Once responders have contained the damage caused by an incident they should move on to __________ and ________ steps. - ANSWER Eradication and recovery At the conclusion of a cybersecurity incident response effort, CSIRT members should conduct a formal ____________ session. - ANSWER Lessons learned What activities should always occur to validate an incident recovery effort? - ANSWER Verify user accounts, verify permissions, verify logging, and conduct vulnerability scans. What are the three options available for the secure disposition of media containing sensitive information? - ANSWER Clear, purge, and destroy What is the focus of the recovery phase of incident response? - ANSWER Restoring normal operations ____________ is a time-consuming investigative task that often distracts incident responders and results in dead ends. - ANSWER Identifying the attackers ________ are high-level statements of management intent. - ANSWER Policies _______ outline what information the organization will maintain and the length of time different categories of information will be retained prior to destruction. - ANSWER Data retention policies ________ provide mandatory requirements describing how an organization will carry out its information security policies. - ANSWER Standards __________ are detailed, step-by-step processes that individuals and organizations must follow in specific circumstances. - ANSWER Procedures _________ provide best practices and recommendations related to a given concept, technology, or task. - ANSWER Guidelines Many exception processes require the use of ___________________ to mitigate the risk associated with exceptions to security - ANSWER Compensating controls What law includes security and privacy rules for protected health information? - ANSWER HIPAA What law applies to the financial records of publicly traded companies? - ANSWER Sarbanes-Oxley __________ provides the same level of protection to all systems or networks. - ANSWER Uniform protection What type of controls include firewalls, intrusion detection and prevention systems, network segmentation, and authentication - ANSWER Technical (or logical) controls

Show more Read less
Institution
CYSA
Course
CYSA

Content preview

CYSA Exam Practice Test Questions And Answers
Verified 100% Correct
What are the phases of incident response? - ANSWER Preparation; Detection &
Analysis; Containment, Eradication, & Recovery; and Post-Incident Activity

What type of documents provide the detailed, tactical information that CSIRT members
need when responding to an incident? - ANSWER Procedures

What document serves as the cornerstone of an organization's incident response
program? - ANSWER Incident Response Policy

What type of threat consists of highly skilled and talented attackers focused on a
specific objective? - ANSWER Advanced Persistent Threat (APT)
What are the types of impact used to describe the scope of a security incident? -
ANSWER Functional impact, economic impact, and recoverability effort

What are the common attack vectors for security incidents? - ANSWER Common
attack vectors for security incidents include external/removable media, attrition, the web,
email, impersonation, improper usage, loss or theft of equipment, and other/unknown
sources.

What Linux command displays processes, memory utilization, and other detail about
running programs? - ANSWER Top or ps

What term is used to describe traffic sent to a command and control system by a PC
that is part of a botnet? - ANSWER Beaconing

What Windows tool provides information on memory, CPU, and disk use? - ANSWER
Perfmon

What protocol is used to gather information about and manage network devices? -
ANSWER SNMP

What Linux command allows you to list the files that are open by processes on a
system? - ANSWER lsof

What type of information is found in network flow data? - ANSWER Flow data provides
information about the source and destination IP address, protocol, and total data sent.

, What protocol is used to ensure that all security devices on a network have
synchronized clocks? - ANSWER NTP

What tool can administrators use to determine the maximum bandwidth available on a
network connection? - ANSWER iPerf

What is the purpose of FTK, EnCase, SIFT, and the Sleuth Kit (TSK)? - ANSWER
Forensic toolkits

What type of device is designed to copy drives for forensic investigation, and then
provide validation that the original drive and the content of the new drive match? -
ANSWER Forensic drive duplicator

Where can forensic analysts turn to find point-in-time information from prior actions on a
Windows system? - ANSWER Volume shadow copies

Where can forensic analysts turn to find information about logins, service start/stop
events, and evidence of applications being - ANSWER Event logs

What Linux utility is commonly used to clone drives in RAW format? - ANSWER dd

What type of device can ensure that attaching a drive to a forensic copy device or
workstation does not result in modifications - ANSWER Write blocker

What Linux kernel modules allow forensic access to physical memory? - ANSWER
fmem and LiME

What tool provides a list of USB devices that have been connected to a Windows
system? - ANSWER USB Historian

What is the first action that incident responders should take after identifying a potential
incident? - ANSWER Contain the damage

Network segmentation, isolation, and removal of affected systems are examples of
___________ strategies - ANSWER Containment

Once responders have contained the damage caused by an incident they should move
on to __________ and ________ steps. - ANSWER Eradication and recovery

At the conclusion of a cybersecurity incident response effort, CSIRT members should
conduct a formal ____________ session. - ANSWER Lessons learned

Written for

Institution
CYSA
Course
CYSA

Document information

Uploaded on
June 1, 2025
Number of pages
8
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$9.99
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF


Also available in package deal

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
TopGradeGuru Teachme2-tutor
Follow You need to be logged in order to follow users or courses
Sold
15
Member since
1 year
Number of followers
0
Documents
2395
Last sold
2 months ago
GRADEHUB

We provide access to a wide range of professionally curated exams for students and educators. It offers high-quality, up-to-date assessment materials tailored to various subjects and academic levels. With instant downloads and affordable pricing, it\'s the go-to resource for exam preparation and academic success.

1.5

2 reviews

5
0
4
0
3
0
2
1
1
1

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions