Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

CYSA EXAM STUDY GUIDE QUESTIONS AND ANSWERS VERIFIED 100% CORRECT

Rating
-
Sold
-
Pages
22
Grade
A+
Uploaded on
01-06-2025
Written in
2024/2025

CYSA EXAM STUDY GUIDE QUESTIONS AND ANSWERS VERIFIED 100% CORRECT Which one of the following is a characteristic of DevOps approaches to technology? A. Isolating operations teams from development teams B. Requiring clear hands-offs between development and production C. Increasing the frequency of application releases D. Eliminating the need for developers to understand business requirements - ANSWER C. Increasing the frequency of application releases Which one of the following conditions is not likely to trigger an alert during an automated cloud security assessment? A. Presence of an API key in a public repository B. Unrestricted API keys C. Transmission of an API key over unsecured channels D. Sharing of API keys among different developers - ANSWER D. Sharing of API keys among different developers In which cloud computing service model does the customer share responsibility with the cloud provider for datacenter security? A. IaaS B. SaaS C. PaaS D. None of the above - ANSWER D. None of the above What type of credential is commonly used to restrict access to an API?(Application Programming Interface) A. Encryption Key B. API Key C. Password D. Biometrics - ANSWER B. API Key In which of the following cloud categories are customers typically charged based on the number of virtual server instances dedicated to their use? A. Iaas Only B. SaaS only C. IaaS and PaaS D. IaaS, SaaS, and PaaS - ANSWER C. IaaS and PaaS I'm reviewing my orgs network design and am concerned that a known flaw in the border router could let an attacker disable my Internet Connectivity. Which of the following is an appropriate compensatory control? A. An identical second redundant router set up in an active/passive design B. An alternate Internet connectivity method using a a different router type C. An identical second redundant router set up in an active/active design D. A firewall in front of the router to stop any potential exploits that could cause a failure of connectivity - ANSWER B. An alternate Internet connectivity method using a a different router type Which of the following layered security controls is commonly used at the WAN, LAN, and host layer in a security design? A. Encryption of data at rest B. Firewalls C. DMZs D. Antivirus - ANSWER B. Firewalls I need to implement a control to ensure that I'm notified of changes to important configuration files on my server. What type of tool should I use for this control? A. Antimalware B. Config Management C. File integrity checking D. Logging - ANSWER C. File integrity checking I've configured my network to provide false DNS responses for known malware domains. What technique am I using? A. Blacklisting B. Whitelisting C. Sinkholing D. Honeypotting - ANSWER C. Sinkholing I'm designing a multifactor authentication system for my company. I've decided to use a passphrase, a time-based code generator, and a PIN to provide additional security. How many distinct factors will I have implemented when done? A. One B. Two C. Three D. Four - ANSWER B. Two I want to manage access based on the job titles of members of my orgs staff. What kind of access control is best suited to this requirement? A. Role-based access control B. Attribute-based access control C. Mandatory access control D. Discretionary access control - ANSWER B. Attribute-based access control Which of the follwing technologies is not a shared authentication technology? A. OpenID Connect B. Attribute-based access control C. OAuth D. Facebook Connect - ANSWER B. Attribute-based access control What security design is best suited to protect authentication and authorization for a network that uses TACACS+? A. Use TACACS+ built-in encryption to protect traffic B. Implement TACACS++ C. Enable accounting services to detect issues D. Route management traffic over a dedicated network - ANSWER D. Route management traffic over a dedicated network I have user rights on my Linux workstation, but want to read my departments financial reports, which I know is sotred in a directory that only administrators can access. I execute a local exploit, which gives the ability to act as root. What type of attack is this? A. Privilege Esc B. Zero-Day C. Rootkit D. Session Hijacking - ANSWER A. Privilege Esc Which party in a federated identity service model makes assertions about identities to service providers? A. RPs B. CDUs C. IDPs D. APs - ANSWER C. IDPs My successful attack on an authenticated user required me to duplicate the cookies that the web app put in place to identify the legitimate user. What type of attack did I conduct? A. Impersonation B. MitM C. Session Hijacking D. Privilege Esc - ANSWER C. Session Hijacking After a major patch is released for the web application that I'm responsible for, I proceed to run my web app security scanner against the web application to verify that it is still secure. What is the term for the process I'm conducting? A. Code review

Show more Read less
Institution
CYSA
Course
CYSA

Content preview

CYSA EXAM STUDY GUIDE QUESTIONS AND ANSWERS
VERIFIED 100% CORRECT

Which one of the following is a characteristic of DevOps approaches to technology?
A. Isolating operations teams from development teams
B. Requiring clear hands-offs between development and production
C. Increasing the frequency of application releases
D. Eliminating the need for developers to understand business requirements -
ANSWER C. Increasing the frequency of application releases

Which one of the following conditions is not likely to trigger an alert during an automated
cloud security assessment?
A. Presence of an API key in a public repository
B. Unrestricted API keys
C. Transmission of an API key over unsecured channels
D. Sharing of API keys among different developers - ANSWER D. Sharing of API keys
among different developers

In which cloud computing service model does the customer share responsibility with the
cloud provider for datacenter security?
A. IaaS
B. SaaS
C. PaaS
D. None of the above - ANSWER D. None of the above

What type of credential is commonly used to restrict access to an API?(Application
Programming Interface)
A. Encryption Key
B. API Key
C. Password
D. Biometrics - ANSWER B. API Key

In which of the following cloud categories are customers typically charged based on the
number of virtual server instances dedicated to their use?
A. Iaas Only
B. SaaS only
C. IaaS and PaaS
D. IaaS, SaaS, and PaaS - ANSWER C. IaaS and PaaS

,I'm reviewing my orgs network design and am concerned that a known flaw in the
border router could let an attacker disable my Internet Connectivity. Which of the
following is an appropriate compensatory control?
A. An identical second redundant router set up in an active/passive design
B. An alternate Internet connectivity method using a a different router type
C. An identical second redundant router set up in an active/active design
D. A firewall in front of the router to stop any potential exploits that could cause a failure
of connectivity - ANSWER B. An alternate Internet connectivity method using a a
different router type

Which of the following layered security controls is commonly used at the WAN, LAN,
and host layer in a security design?
A. Encryption of data at rest
B. Firewalls
C. DMZs
D. Antivirus - ANSWER B. Firewalls

I need to implement a control to ensure that I'm notified of changes to important
configuration files on my server. What type of tool should I use for this control?
A. Antimalware
B. Config Management
C. File integrity checking
D. Logging - ANSWER C. File integrity checking

I've configured my network to provide false DNS responses for known malware
domains. What technique am I using?
A. Blacklisting
B. Whitelisting
C. Sinkholing
D. Honeypotting - ANSWER C. Sinkholing

I'm designing a multifactor authentication system for my company. I've decided to use a
passphrase, a time-based code generator, and a PIN to provide additional security.
How many distinct factors will I have implemented when done?
A. One
B. Two
C. Three
D. Four - ANSWER B. Two

I want to manage access based on the job titles of members of my orgs staff. What kind
of access control is best suited to this requirement?
A. Role-based access control
B. Attribute-based access control

, C. Mandatory access control
D. Discretionary access control - ANSWER B. Attribute-based access control

Which of the follwing technologies is not a shared authentication technology?
A. OpenID Connect
B. Attribute-based access control
C. OAuth
D. Facebook Connect - ANSWER B. Attribute-based access control

What security design is best suited to protect authentication and authorization for a
network that uses TACACS+?
A. Use TACACS+ built-in encryption to protect traffic
B. Implement TACACS++
C. Enable accounting services to detect issues
D. Route management traffic over a dedicated network - ANSWER D. Route
management traffic over a dedicated network

I have user rights on my Linux workstation, but want to read my departments financial
reports, which I know is sotred in a directory that only administrators can access. I
execute a local exploit, which gives the ability to act as root. What type of attack is this?
A. Privilege Esc
B. Zero-Day
C. Rootkit
D. Session Hijacking - ANSWER A. Privilege Esc

Which party in a federated identity service model makes assertions about identities to
service providers?
A. RPs
B. CDUs
C. IDPs
D. APs - ANSWER C. IDPs

My successful attack on an authenticated user required me to duplicate the cookies that
the web app put in place to identify the legitimate user. What type of attack did I
conduct? A. Impersonation
B. MitM
C. Session Hijacking
D. Privilege Esc - ANSWER C. Session Hijacking

After a major patch is released for the web application that I'm responsible for, I proceed
to run my web app security scanner against the web application to verify that it is still
secure. What is the term for the process I'm conducting?
A. Code review

Written for

Institution
CYSA
Course
CYSA

Document information

Uploaded on
June 1, 2025
Number of pages
22
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$12.99
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF


Also available in package deal

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
TopGradeGuru Teachme2-tutor
Follow You need to be logged in order to follow users or courses
Sold
15
Member since
1 year
Number of followers
0
Documents
2395
Last sold
2 months ago
GRADEHUB

We provide access to a wide range of professionally curated exams for students and educators. It offers high-quality, up-to-date assessment materials tailored to various subjects and academic levels. With instant downloads and affordable pricing, it\'s the go-to resource for exam preparation and academic success.

1.5

2 reviews

5
0
4
0
3
0
2
1
1
1

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions