Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

CYSA EXAM TEST QUESTIONS WITH 100% VERIFIED SOLUTIONS

Rating
-
Sold
-
Pages
6
Grade
A+
Uploaded on
01-06-2025
Written in
2024/2025

CYSA EXAM TEST QUESTIONS WITH 100% VERIFIED SOLUTIONS An analyst is participating in the solution analysis process for a cloud-hosted SIEM platform to centralize log monitoring and alerting capabilities in the SOC. Which of the following is the BEST approach for supply chain assessment when selecting a vendor? - ANSWER Identify SLA requirements for monitoring and logging A security technician is testing a solution that will prevent outside entities from spoofing the company's email domain, which is . The testing is successful, and the security technician is prepared to fully implement the solution. Which of the following actions should the technician take to accomplish this task? - ANSWER Add TXT @ "v=spf1 mx include:_ −all" to the DNS record. A security analyst on the threat-hunting team has developed a list of unneeded, benign services that are currently running as part of the standard OS deployment for workstations. The analyst will provide this list to the operations team to create a policy that will automatically disable the services for all workstations in the organization. Which of the following BEST describes the security analyst's goal? - ANSWER To reduce the attack surface An information security analyst observes anomalous behavior on the SCADA devices in a power plant. This behavior results in the industrial generators overheating and destabilizing the power supply - ANSWER Use Wireshark to capture packets between SCADA devices and the management system Which of the following roles is ultimately responsible for determining the classification levels assigned to specific datasets - ANSWER Data owner A security analyst suspects a malware infection was caused by a user who downloaded malware after clicking Error! Hyperlink reference not valid. in a phishing email. To prevent other computers from being infected by the same malware variation, the analyst should create a rule on the - ANSWER proxy to block all connections to malwaresource. An information security analyst is reviewing backup data sets as part of a project focused on eliminating archival datasets Which of the following should be considered FIRST prior to disposing of the electronic data? - ANSWER Retention standards A security analyst is evaluating two vulnerability management tools for possible use in an organization. The analyst set up each of the tools according to the respective vendor's instructions and generated a report of vulnerabilities that ran against the same target server. Tool A reported the following Tool B reported the following Which of the following BEST describes the method used by each tool? (Choose two.) - ANSWER Tool A is unauthenticated. Tool B is agent based. Which of the following would MOST likely be included in the incident response procedure after a security breach of customer PII? - ANSWER Public relations A security analyst received an alert from the SIEM indicating numerous login attempts from users outside their usual geographic zones, all of which were initiated through the web-based mail server. The logs indicate all domain accounts experienced two login attempts during the same time frame. Which of the following is the MOST likely cause of this issue? - ANSWER A passwordspraying attack was performed against the organization. During an investigation, a security analyst identified machines that are infected with malware the antivirus was unable to detect. Which of the following is the BEST place to acquire evidence to perform data carving? - ANSWER The hard drive & The system memory A cybersecurity analyst has access to several threat feeds and wants to organize them while simultaneously comparing intelligence against network traffic. Which of the following would BEST accomplish this goal - ANSWER Automation and orchestration An analyst is performing penetration testing and vulnerability assessment activities against a new vehicle automation platform. Which of the following is MOST likely an attack vector that is being utilized as part of the testing and assessment? - ANSWER CAN Bus A cyber-incident response analyst is investigating a suspected cryptocurrency miner on a company's server. Which of the following is the FIRST step the analyst should take? - ANSWER Start packet capturing to look for traffic that could be indicative of command and control from the miner. A security analyst is investigating a malware infection that occurred on a Windows system. The system was not connected to a network and had no wireless capability Company policy prohibits using portable media or mobile storage The security analyst is trying to determine which use caused the malware to get onto the system Which of the following registry keys would MOST likely have this information? - ANSWER HKEY_USERSuser SIDSoftwareMicrosoftWindowsexplorerMountPoints2 Which of the following MOST accurately describes an HSM? - ANSWER An HSM can be networked based or a removable USB A security analyst is investigating malicious traffic from an internal system that attempted to download proxy avoidance software as identified from the firewall logs but the destination IP is blocked and not captured. Which of the following should the analyst do? - ANSWER Shut down the computer Which of the following technologies can be used to house the entropy keys for disk encryption on desktops and laptops? - ANSWER Self-encrypting drive A developer wrote a script to make names and other Pll data unidentifiable before loading a database export into the testing system Which of the following describes the type of control that is being used - ANSWER Data loss prevention or Data masking A security analyst receives an alert that highly sensitive information has left the company's network Upon investigation, the analyst discovers an outside IP range has had connections from three servers more than 100 times m the past month The affected servers are virtual machines Which of the following is the BEST course of action? - ANSWER Shut down the servers as soon as possible, move them to a clean environment, restart, run a vulnerability scanner to find weaknesses determine the root cause, remediate, and report A security analyst is investigating a compromised Linux server. The analyst issues the ps command and receives the following output. 1301 ? Ss 0:00 ./usr/sbin/sshd -D Which of the following commands should the administrator run NEXT to further analyze the compromised system? - ANSWER A. strace /proc/1301 A small organization has proprietary software that is used internally. The system has not been well maintained and cannot be updated with the rest of the environment Which of the following is the BEST solution? - ANSWER Virtualize the system and decommission the physical machine. Which of the following attacks can be prevented by using output encoding? - ANSWER Cross-site scripting A security analyst is responding to an incident on a web server on the company network

Show more Read less
Institution
CYSA
Course
CYSA

Content preview

CYSA EXAM TEST QUESTIONS WITH 100% VERIFIED
SOLUTIONS


An analyst is participating in the solution analysis process for a cloud-hosted SIEM
platform to centralize log monitoring and alerting capabilities in the SOC.
Which of the following is the BEST approach for supply chain assessment when
selecting a vendor? - ANSWER Identify SLA requirements for monitoring and logging

A security technician is testing a solution that will prevent outside entities from spoofing
the company's email domain, which is comptia.org. The testing is successful, and the
security technician is prepared to fully implement the solution.
Which of the following actions should the technician take to accomplish this task? -
ANSWER Add TXT @ "v=spf1 mx include:_spf.comptia.org −all" to the DNS record.

A security analyst on the threat-hunting team has developed a list of unneeded, benign
services that are currently running as part of the standard OS deployment for
workstations.
The analyst will provide this list to the operations team to create a policy that will
automatically disable the services for all workstations in the organization.
Which of the following BEST describes the security analyst's goal? - ANSWER To
reduce the attack surface

An information security analyst observes anomalous behavior on the SCADA devices in
a power plant. This behavior results in the industrial generators overheating and
destabilizing the power supply - ANSWER Use Wireshark to capture packets between
SCADA devices and the management system

Which of the following roles is ultimately responsible for determining the classification
levels assigned to specific datasets - ANSWER Data owner

A security analyst suspects a malware infection was caused by a user who downloaded
malware after clicking Error! Hyperlink reference not valid. in a phishing email. To
prevent other computers from being infected by the same malware variation, the analyst
should create a rule on the - ANSWER proxy to block all connections to
<malwaresource>.

An information security analyst is reviewing backup data sets as part of a project
focused on eliminating archival datasets

, Which of the following should be considered FIRST prior to disposing of the electronic
data? - ANSWER Retention standards

A security analyst is evaluating two vulnerability management tools for possible use in
an organization. The analyst set up each of the tools according to the respective
vendor's instructions and generated a report of vulnerabilities that ran against the same
target server.
Tool A reported the following
Tool B reported the following
Which of the following BEST describes the method used by each tool? (Choose two.) -
ANSWER Tool A is unauthenticated.
Tool B is agent based.

Which of the following would MOST likely be included in the incident response
procedure after a security breach of customer PII? - ANSWER Public relations

A security analyst received an alert from the SIEM indicating numerous login attempts
from users outside their usual geographic zones, all of which were initiated through the
web-based mail server. The logs indicate all domain accounts experienced two login
attempts during the same time frame.
Which of the following is the MOST likely cause of this issue? - ANSWER A
passwordspraying attack was performed against the organization.

During an investigation, a security analyst identified machines that are infected with
malware the antivirus was unable to detect.
Which of the following is the BEST place to acquire evidence to perform data carving? -
ANSWER The hard drive & The system memory

A cybersecurity analyst has access to several threat feeds and wants to organize them
while simultaneously comparing intelligence against network traffic. Which of the
following would BEST accomplish this goal - ANSWER Automation and orchestration

An analyst is performing penetration testing and vulnerability assessment activities
against a new vehicle automation platform. Which of the following is MOST likely an
attack vector that is being utilized as part of the testing and assessment? - ANSWER
CAN Bus

A cyber-incident response analyst is investigating a suspected cryptocurrency miner on
a company's server. Which of the following is the FIRST step the analyst should take? -
ANSWER Start packet capturing to look for traffic that could be indicative of command
and control from the miner.

A security analyst is investigating a malware infection that occurred on a Windows
system. The system was not connected to a network and had no wireless capability

Written for

Institution
CYSA
Course
CYSA

Document information

Uploaded on
June 1, 2025
Number of pages
6
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$10.99
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF


Also available in package deal

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
TopGradeGuru Teachme2-tutor
Follow You need to be logged in order to follow users or courses
Sold
15
Member since
1 year
Number of followers
0
Documents
2395
Last sold
2 months ago
GRADEHUB

We provide access to a wide range of professionally curated exams for students and educators. It offers high-quality, up-to-date assessment materials tailored to various subjects and academic levels. With instant downloads and affordable pricing, it\'s the go-to resource for exam preparation and academic success.

1.5

2 reviews

5
0
4
0
3
0
2
1
1
1

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions