Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

CYSA Verified Multiple Choice and Conceptual Actual Exam Questions With Reviewed 100% Correct Detailed Answers Guaranteed Pass!!Current Update

Rating
-
Sold
-
Pages
17
Grade
A+
Uploaded on
09-07-2025
Written in
2024/2025

CYSA Verified Multiple Choice and Conceptual Actual Exam Questions With Reviewed 100% Correct Detailed Answers Guaranteed Pass!!Current Update 1. Q: A systems administrator reports suspicious PowerShell activity, including obfuscated commands and unexpected outbound connections. Which scanning tool would best detect living-off-the-land attacks like this? A: A host-based behavior analytics tool with PowerShell script detection capabilities. Rationale: Behavior analytics tools can flag abnormal PowerShell usage rather than relying solely on signature-based detection. 2. Q: A SIEM is loudly alerting with multiple port scan attempts from a single IP to various internal servers. What’s your first triage step? A: Check the asset inventory to identify whether the target IPs are active production systems or unused assets. Rationale: Understanding the context (e.g., critical asset versus retired device) helps prioritize your response. 3. Q: You suspect a fileless attack is persistently hiding in system memory. Which forensic tool should you use? A: Volatility for memory image analysis. Rationale: Volatility can extract running processes, hidden threads, and injected code—ideal for detecting memory-resident threats. 4. Q: During threat modeling, you discover that a user’s password hashes are easily accessible by unauthorized staff. Which STRIDE threat category applies? A: Tampering – unauthorized modification or access to sensitive data. Rationale: STRIDE maps threat types to specific risks; exposed hashes represent an integrity violation. 5. Q: You receive alerts for both a single low-level phishing email and a DoS attack against public web servers. Which incident gets higher priority? A: The DoS attack takes precedence. Rationale: A service outage affecting public-facing infrastructure impacts availability and poses larger business risk.

Show more Read less
Institution
CompTIA CYSA+ WGU
Course
CompTIA CYSA+ WGU

Content preview

CYSA Verified Multiple Choice and
Conceptual Actual Exam Questions With
Reviewed 100% Correct Detailed Answers

Guaranteed Pass!!Current Update


1. Q: A systems administrator reports suspicious PowerShell activity, including
obfuscated commands and unexpected outbound connections. Which
scanning tool would best detect living-off-the-land attacks like this?


A: A host-based behavior analytics tool with PowerShell script detection
capabilities.
Rationale: Behavior analytics tools can flag abnormal PowerShell usage rather
than relying solely on signature-based detection.


2. Q: A SIEM is loudly alerting with multiple port scan attempts from a single
IP to various internal servers. What’s your first triage step?
A: Check the asset inventory to identify whether the target IPs are active
production systems or unused assets.
Rationale: Understanding the context (e.g., critical asset versus retired
device) helps prioritize your response.


3. Q: You suspect a fileless attack is persistently hiding in system memory. Which
forensic tool should you use?
A: Volatility for memory image analysis.
Rationale: Volatility can extract running processes, hidden threads, and injected
code—ideal for detecting memory-resident threats.

,4. Q: During threat modeling, you discover that a user’s password hashes are
easily accessible by unauthorized staff. Which STRIDE threat category applies?
A: Tampering – unauthorized modification or access to sensitive data.
Rationale: STRIDE maps threat types to specific risks; exposed hashes represent
an integrity violation.


5. Q: You receive alerts for both a single low-level phishing email and a DoS attack
against public web servers. Which incident gets higher priority?
A: The DoS attack takes precedence.
Rationale: A service outage affecting public-facing infrastructure impacts
availability and poses larger business risk.


6. Q: You want to detect lateral movement within the corporate network. Where
should you place your network monitors?
A: Use internal network sensors (managed by your IDS/IPS) to inspect East–West
(lateral) traffic.
Rationale: Monitoring internal traffic is essential for detecting internal threats and
lateral attacks.


7. Q: Brute-force login attempts are flooding your web portal. What mitigation
should you implement?
A: Implement account lockout policies and CAPTCHA on login pages.
Rationale: Enabling lockouts slows brute-force attempts and CAPTCHA counters
automated scripts.


8. Q: You suspect DNS queries are being used for sensitive data exfiltration. What
analysis would confirm this?
A: Analyze unusually long or randomly structured DNS query names.

, Rationale: DNS tunneling often uses encoded or lengthy hostnames to conceal
transmitted data.


9. Q: A new application sends logs in XML format. How can your SIEM ingest them
correctly?
A: Create or import a custom parser for that XML log format.
Rationale: Proper log parsing ensures that field data are correctly categorized and
searchable.


10. Q: You discover an unpatched CVE in a third-party web server. What is the
primary risk now?
A: The vulnerability exists, but exploitation depends on whether an exploit packet
is available. It's currently an exposed risk.
Rationale: Distinguishing between a vulnerability (potential risk) and an exploit
(actual attack vector) is crucial for accurate risk assessment.


A newly hired cybersecurity manager oversees the organization's operational
control responsibilities. Which of the following is an example of this
responsibility?


A. Monitoring the network for unauthorized access attempts
B. Conducting a risk assessment to identify potential vulnerabilities in the system
C. Installing antivirus software on all company computers

D. Creating a strong password policy for employees to follow - ANSWER A.
Monitoring the network for unauthorized access attempts

Written for

Institution
CompTIA CYSA+ WGU
Course
CompTIA CYSA+ WGU

Document information

Uploaded on
July 9, 2025
Number of pages
17
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$11.99
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
EWLindy Harvard University
Follow You need to be logged in order to follow users or courses
Sold
760
Member since
3 year
Number of followers
431
Documents
8199
Last sold
21 hours ago
EN.CY.CLO.PE.DI.A

As a Career Tutor, I understand the pressure of managing demanding coursework, exams, and practical requirements across multiple disciplines. These professionally organized revision materials are designed to support students in nursing, healthcare administration, business, information systems, Engineering, health, IT, or trade courses management programs by simplifying complex concepts and reinforcing high-yield academic content. The materials are developed to help students: Understand core theories and practical applications across Multiple Disciplines Review exam relevant content aligned with undergraduate and graduate curriculam To Strengthen critical thinking, analytical reasoning, and decision-making skills Save time with clear, structured summaries instead of overwhelming textbooks Prepare efficiently for tests, assignments, case studies, and professional exams Each resource is created with academic standards in mind, integrating real world examples, industry terminology, and evidence based concepts commonly required in professional programs. Whether you are studying nursing fundamentals, healthcare management, information systems, project management, business strategy, Engineering these materials provide focused, reliable support for academic success. These revision guides are ideal for: Nursing and allied health students Healthcare administration and public health students Business, MBA, and management students Information technology and information systems students, engineering, business, IT, or trade courses If you are looking for clear, student-friendly, exam-focused revision materials that support multiple career pathways, these resources are designed to help you study smarter, perform better, and stay confident throughout your academic journey. WISH YOU SUCCESS!!

Read more Read less
3.7

112 reviews

5
56
4
14
3
17
2
6
1
19

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions