Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

CYSA EXAM REVISED QUESTIONS AND ANSWERS VERIFIED 100% CORRECT

Rating
-
Sold
-
Pages
11
Grade
A+
Uploaded on
01-06-2025
Written in
2024/2025

CYSA EXAM REVISED QUESTIONS AND ANSWERS VERIFIED 100% CORRECT Network Access Control (NAC) - ANSWER Limits network access to only authorized individual and systems Ensures the systems connecting to the network meet basic security requirement 802.1 x - ANSWER most common standard from NAC Agent-based NAC - ANSWER Applies policy rules through a software based agent to enforce the controls. Like 802.1x Agentless NAC - ANSWER A network access control (NAC) agent that is not installed on an endpoint device but is embedded within a Microsoft Windows Active Directory domain controller. Like Wireless at a hotel, and coffee shops In-Band NAC - ANSWER Use dedicated appliances placed between the devices and the services they are requesting • Example: Hotel networks that require you to enter your name and room number before gaining access Out-of-Band NAC - ANSWER Relies on existing network and has device communicate to authentication servers (like 802.1x) NAC Approval Criteria - ANSWER Time of Day Role of the User Location of user System health status Honeypot - ANSWER System designed to look like a lucrative target due to the types of services being run or vulnerabilities contained are designed to falsely appear vulnerable and to fool malicious attackers to waste time going after them simulate successful attacks and allow us to monitor attacker techniques DNS Sinkhole - ANSWER Provide false DNS information to malicious software Hardening System Configuration - ANSWER Make it as resistant to attack as possible Disabling unnesccary services Disabling unnecessary ports Verifying secure congiuration Centrallycontrolling device security settings Patch Management - ANSWER the process of regularly applying patches and updates to software like SCCM Compensating Controls - ANSWER control procedures that compensate for the deficiency in other controls WannaCry outbreak required disabling SMBv1, but thiscould break an file share Point ofSale or embeddedsystems can be updated without possiblity of breaking GPO (Group Policy Object) - ANSWER Provides admins an efficient way to manage system and security configuration settings acrossmany devices Ex. Require the use a firewall on all hosts Mappping to a share drive on login Run scripts at login to verify compliance Endpoint Security Software - ANSWER Softeare should report to a centralized management system for cyber security analysts to view and analyze - Anti-malware - Antivirus - Anti-spyware - Spam filters - Patch management - HIPS/HIDS - Data loss prevention - Host-based firewalls - Log monitoring MAC (Mandatory Access Control) - ANSWER All security permissions centrally and the user cannot change permission DAC (Discretionary Access Control) - ANSWER allows the owners of a file or resoure to control the permission on that resource PenTest - ANSWER simulate a cyber attack against your organization resources using the same information, tools, and techniques abailable to an attacker Gain access Red Team - ANSWER participates as the attackers Blue team - ANSWER particiates as the defenders Secures the network and attempts to keep red team out through the use of security controls White Team - ANSWER participates as the referee PenTest phases - ANSWER Planning Discovery Attack Reporting NIST SP 800-115 - ANSWER Technical Guide to Information Security Testing and Assessment. Divides pentesting into 4 phases Planning -PenTest - ANSWER No technical work is preformed. Timing, scope, and authorization is gained. Always get authorizations Discovery -PenTest - ANSWER Testers conduct recon and gather as much information on the network, system, users, and applications Ex. Open source research

Show more Read less
Institution
CYSA
Course
CYSA

Content preview

CYSA EXAM REVISED QUESTIONS AND ANSWERS
VERIFIED 100% CORRECT
Network Access Control (NAC) - ANSWER Limits network access to only authorized
individual and systems

Ensures the systems connecting to the network meet basic security requirement

802.1 x - ANSWER most common standard from NAC

Agent-based NAC - ANSWER Applies policy rules through a software based agent to
enforce the controls.

Like 802.1x

Agentless NAC - ANSWER A network access control (NAC) agent that is not installed
on an endpoint device but is embedded within a Microsoft Windows Active Directory
domain controller.


Like Wireless at a hotel, and coffee shops

In-Band NAC - ANSWER Use dedicated appliances placed between the devices and
the services they are requesting

• Example: Hotel networks that require you to enter your name and room number before
gaining access

Out-of-Band NAC - ANSWER Relies on existing network and has device communicate
to authentication servers (like 802.1x)

NAC Approval Criteria - ANSWER Time of Day
Role of the User
Location of user
System health status

Honeypot - ANSWER System designed to look like a lucrative target due to the types of
services being run or vulnerabilities contained

are designed to falsely appear vulnerable and to fool malicious attackers to waste time

, going after them

simulate successful attacks and allow us to monitor attacker techniques

DNS Sinkhole - ANSWER Provide false DNS information to malicious software

Hardening System Configuration - ANSWER Make it as resistant to attack as possible

Disabling unnesccary services
Disabling unnecessary ports
Verifying secure congiuration
Centrallycontrolling device security settings

Patch Management - ANSWER the process of regularly applying patches and updates
to software

like SCCM

Compensating Controls - ANSWER control procedures that compensate for the
deficiency in other controls


WannaCry outbreak required disabling SMBv1, but thiscould break an file share

Point ofSale or embeddedsystems can be updated without possiblity of breaking

GPO (Group Policy Object) - ANSWER Provides admins an efficient way to manage
system and security configuration settings acrossmany devices

Ex.
Require the use a firewall on all hosts
Mappping to a share drive on login
Run scripts at login to verify compliance

Endpoint Security Software - ANSWER Softeare should report to a centralized
management system for cyber security analysts to view and analyze


- Anti-malware
- Antivirus
- Anti-spyware
- Spam filters

Written for

Institution
CYSA
Course
CYSA

Document information

Uploaded on
June 1, 2025
Number of pages
11
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$11.99
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF


Also available in package deal

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
TopGradeGuru Teachme2-tutor
Follow You need to be logged in order to follow users or courses
Sold
15
Member since
1 year
Number of followers
0
Documents
2395
Last sold
2 months ago
GRADEHUB

We provide access to a wide range of professionally curated exams for students and educators. It offers high-quality, up-to-date assessment materials tailored to various subjects and academic levels. With instant downloads and affordable pricing, it\'s the go-to resource for exam preparation and academic success.

1.5

2 reviews

5
0
4
0
3
0
2
1
1
1

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions