Geschreven door studenten die geslaagd zijn Direct beschikbaar na je betaling Online lezen of als PDF Verkeerd document? Gratis ruilen 4,6 TrustPilot
logo-home
Tentamen (uitwerkingen)

CYSA EXAM Questions AND Answers Verified 100% Correct

Beoordeling
-
Verkocht
-
Pagina's
5
Cijfer
A+
Geüpload op
01-06-2025
Geschreven in
2024/2025

CYSA EXAM Questions AND Answers Verified 100% Correct Bill would like to run an internal vulnerability scan on a system for PCI DSS compliance purposes. Who is authorized to complete one of these scans? A. Any Employee of the Organization B. An Approved Scanning Vendor C. A PCI DSS Service Provider D. Any Qualified Individual - ANSWER D: Any Qualified Individual. Internal scans completed for PCI DSS compliance purposes may be conducted by any qualified individual. Which type of organization is the most likely to face a regulatory requirement to conduct vulnerability scans? A. Bank B. Hospital C. Government Agency D. Doctor's Office - ANSWER C: Government Agency. The Federal Information Security Management Act (FISMA) requires that government agencies conduct vulnerability scans. HIPAA, which governs hospitals and doctors' offices, does not include a vulnerability scanning requirement, nor does GLBA, which covers financial institutions. What minimum level of impact must a system have under FISMA before the organization is required to determine what information about the system is discoverable by adversaries? A. Low B. Moderate C. High D. Severe - ANSWER C: High. Control enhancement number 4 requires that an organization determine what information about the system is discoverable by adversaries. This enhancement only applies to FISMA high systems. What term describes an organization's willingness to tolerate risk in their comping environment? A. Risk Landscape B. Risk Appetite C. Risk Level D. Risk Adaptation - ANSWER B: Risk Appetite. The organization's risk appetite is it's willingness to tolerate risk within the environment. If an organization is extremely risk averse, it may choose to conduct scans more frequently to minimize the amount of time between when a vulnerability comes into existence and when it is detected by a scan. Which one of the following factors is least likely to impact vulnerability scanning schedules? A. Regulatory Requirements B. Technical Constraints C. Business Constraints D. Staff Availability - ANSWER D: Staff Availability. Scan schedules are most often determined by the organization's risk appetite, regulatory requirements, technical constraints, business constraints, and licensing limitations. Most scans are automated and do not require staff availability. Barry placed all of his organization's credit card processing systems on an isolated network dedicated to card processing. He has implemented appropriate segmentation controls to limit the scope of PCI DSS to those systems through the use of VLANs and firewalls. When Barry goes to conduct vulnerability scans for PCI DSS compliance purposes, what systems must he scan? A. Customer Systems B. Systems on the Isolated Network C. Systems on the General Enterprise Network D. Both B and C - ANSWER B: Systems on the Isolated Network. If Barry is able to limit the scope of his PCI DSS compliance efforts to the isolated network, then that is the only network requirement that must be scanned for PCI DSS compliance purposes. Ryan is planning to conduct a vulnerability scan of a business critical system using dangerous plug-ins. What would be the best approach for the initial scan? A. Run the Scan Against Production Systems to Achieve the Most Realistic Results Possible B. Run the Scan During Business Hours C. Run the Scan in a Test Environment D. Do not Run the Scan to Avoid Disrupting the Business - ANSWER C: Run the Scan in a Test Environment. Ryan should first run his scan against a test environment to identify likely vulnerabilities and asses whether the scan itself might disrupt business activities. Which of the following activities is not part of the vulnerability management life cycle? A. Detection B. Remediation C. Reporting D. Testing - ANSWER C: Reporting. While reporting and communication are an important part of vulnerability management, they are not included in the life cycle. The three life-cycle phases are detection, remediation, and testing. What approach to vulnerability scanning incorporates information from agents running on the target servers? A. Continuous Monitoring B. Ongoing Scanning C. On-Demand Scanning D. Alerting - ANSWER A: Continuous Monitoring. Continuous monitoring incorporates data from agent-based approaches to vulnerability detection and reports securityrelated configuration changes to the vulnerability management platform as soon as they occur, providing the ability analyze those changes for potential vulnerabilities. Brian is seeking to determine the appropriate impact categorization for a federal information system as he plans the vulnerability scanning controls for that system. After consulting management, he discovers that the system contains information that, if disclosed improperly, would have a serious adverse impact on the organization. How should this system be categorized? A. Low Impact B. Moderate Impact C. High Impact D. Severe Impact - ANSWER B: Moderate Impact. Systems have a moderate impact from a confidentiality perspective if the unauthorized disclosure of information could be expected to have a serious adverse effect on organizational operations, organizational assets, or individuals. Jessica is reading reports from vulnerability scans run by different parts of her organization using different products. She is responsible for assigning remediation resources and is having difficulty prioritizing issues from different sources. What SCAP component can help Jessica with this task? A. CVSS B. CVE C. CPE D. XCCDF - ANSWER A: CVSS. The Common Vulnerability Scoring System (CVSS) provides a standardized approach for measuring and describing the severity of security vulnerabilities. Jessica could use this scoring system to prioritize issues raised by different source systems. Sarah would like to run an external vulnerability scan on a system for PCI DSS compliance purposes. Who is authorized to complete one of these scans? A. Any Employee of the Organization B. An Approved Scanning Vendor C. A PCI DSS Service Provider D. Any Qualified Individual - ANSWER B: An Approved Scanning Vendor. While any qualified individual may conduct internal compliance scans, PCI DSS requires the use of a scanning vendor approved by the PCI SSC for external compliance scans.

Meer zien Lees minder
Instelling
CYSA
Vak
CYSA

Voorbeeld van de inhoud

CYSA EXAM Questions AND Answers Verified 100%
Correct

Bill would like to run an internal vulnerability scan on a system for PCI DSS compliance
purposes. Who is authorized to complete one of these scans?
A. Any Employee of the Organization
B. An Approved Scanning Vendor
C. A PCI DSS Service Provider
D. Any Qualified Individual - ANSWER D: Any Qualified Individual. Internal scans
completed for PCI DSS compliance purposes may be conducted by any qualified
individual.

Which type of organization is the most likely to face a regulatory requirement to conduct
vulnerability scans?
A. Bank
B. Hospital
C. Government Agency
D. Doctor's Office - ANSWER C: Government Agency. The Federal Information
Security Management Act (FISMA) requires that government agencies conduct
vulnerability scans. HIPAA, which governs hospitals and doctors' offices, does not
include a vulnerability scanning requirement, nor does GLBA, which covers financial
institutions.

What minimum level of impact must a system have under FISMA before the
organization is required to determine what information about the system is discoverable
by adversaries? A. Low
B. Moderate
C. High
D. Severe - ANSWER C: High. Control enhancement number 4 requires that an
organization determine what information about the system is discoverable by
adversaries. This enhancement only applies to FISMA high systems.

What term describes an organization's willingness to tolerate risk in their comping
environment? A. Risk Landscape
B. Risk Appetite C.
Risk Level
D. Risk Adaptation - ANSWER B: Risk Appetite. The organization's risk appetite is it's
willingness to tolerate risk within the environment. If an organization is extremely risk
averse, it may choose to conduct scans more frequently to minimize the amount of time
between when a vulnerability comes into existence and when it is detected by a scan.

, Which one of the following factors is least likely to impact vulnerability scanning
schedules?
A. Regulatory Requirements
B. Technical Constraints
C. Business Constraints
D. Staff Availability - ANSWER D: Staff Availability. Scan schedules are most often
determined by the organization's risk appetite, regulatory requirements, technical
constraints, business constraints, and licensing limitations. Most scans are
automated and do not require staff availability.

Barry placed all of his organization's credit card processing systems on an isolated
network dedicated to card processing. He has implemented appropriate segmentation
controls to limit the scope of PCI DSS to those systems through the use of VLANs and
firewalls. When Barry goes to conduct vulnerability scans for PCI DSS compliance
purposes, what systems must he scan?
A. Customer Systems
B. Systems on the Isolated Network
C. Systems on the General Enterprise Network
D. Both B and C - ANSWER B: Systems on the Isolated Network. If Barry is able to
limit the scope of his PCI DSS compliance efforts to the isolated network, then that
is the only network requirement that must be scanned for PCI DSS compliance
purposes.

Ryan is planning to conduct a vulnerability scan of a business critical system using
dangerous plug-ins. What would be the best approach for the initial scan? A. Run
the Scan Against Production Systems to Achieve the Most Realistic Results
Possible
B. Run the Scan During Business Hours
C. Run the Scan in a Test Environment
D. Do not Run the Scan to Avoid Disrupting the Business - ANSWER C: Run the Scan
in a Test Environment. Ryan should first run his scan against a test environment to
identify likely vulnerabilities and asses whether the scan itself might disrupt business
activities.

Which of the following activities is not part of the vulnerability management life cycle?
A. Detection
B. Remediation
C. Reporting
D. Testing - ANSWER C: Reporting. While reporting and communication are an
important part of vulnerability management, they are not included in the life cycle.
The three life-cycle phases are detection, remediation, and testing.

Geschreven voor

Instelling
CYSA
Vak
CYSA

Documentinformatie

Geüpload op
1 juni 2025
Aantal pagina's
5
Geschreven in
2024/2025
Type
Tentamen (uitwerkingen)
Bevat
Vragen en antwoorden

Onderwerpen

$9.99
Krijg toegang tot het volledige document:

Verkeerd document? Gratis ruilen Binnen 14 dagen na aankoop en voor het downloaden kun je een ander document kiezen. Je kunt het bedrag gewoon opnieuw besteden.
Geschreven door studenten die geslaagd zijn
Direct beschikbaar na je betaling
Online lezen of als PDF


Ook beschikbaar in voordeelbundel

Maak kennis met de verkoper

Seller avatar
De reputatie van een verkoper is gebaseerd op het aantal documenten dat iemand tegen betaling verkocht heeft en de beoordelingen die voor die items ontvangen zijn. Er zijn drie niveau’s te onderscheiden: brons, zilver en goud. Hoe beter de reputatie, hoe meer de kwaliteit van zijn of haar werk te vertrouwen is.
TopGradeGuru Teachme2-tutor
Volgen Je moet ingelogd zijn om studenten of vakken te kunnen volgen
Verkocht
15
Lid sinds
1 jaar
Aantal volgers
0
Documenten
2395
Laatst verkocht
2 maanden geleden
GRADEHUB

We provide access to a wide range of professionally curated exams for students and educators. It offers high-quality, up-to-date assessment materials tailored to various subjects and academic levels. With instant downloads and affordable pricing, it\'s the go-to resource for exam preparation and academic success.

1.5

2 beoordelingen

5
0
4
0
3
0
2
1
1
1

Recent door jou bekeken

Waarom studenten kiezen voor Stuvia

Gemaakt door medestudenten, geverifieerd door reviews

Kwaliteit die je kunt vertrouwen: geschreven door studenten die slaagden en beoordeeld door anderen die dit document gebruikten.

Niet tevreden? Kies een ander document

Geen zorgen! Je kunt voor hetzelfde geld direct een ander document kiezen dat beter past bij wat je zoekt.

Betaal zoals je wilt, start meteen met leren

Geen abonnement, geen verplichtingen. Betaal zoals je gewend bent via iDeal of creditcard en download je PDF-document meteen.

Student with book image

“Gekocht, gedownload en geslaagd. Zo makkelijk kan het dus zijn.”

Alisha Student

Bezig met je bronvermelding?

Maak nauwkeurige citaten in APA, MLA en Harvard met onze gratis bronnengenerator.

Bezig met je bronvermelding?

Veelgestelde vragen