Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

CySA EXAM |93 QUESTIONS AND ANSWERS

Rating
-
Sold
-
Pages
7
Grade
A+
Uploaded on
10-09-2025
Written in
2025/2026

CySA EXAM |93 QUESTIONS AND ANSWERS

Institution
Course

Content preview

CySA EXAM |93 QUESTIONS AND ANSWERS
Confidentiality, integrity, and availability - -What are the three key objectives of
information security?

-Threats and vulnerabilities. - -Risk exists at the intersection of _______ and _________.

-Network access control - -What type of system controls access to a network based on
criteria such as time of day, location, device type, and system health?

-The Internet, an internal network, and a DMZ - -What are the three networks typically
connected to a triple-homed firewall?

-Packet filters
Stateful inspection firewalls
Next-generation firewalls
Web application firewalls. - -What are the four types of firewalls?

-Group Policy Objects (GPOs) - -______ may be used to apply settings to many different
Windows systems at the same time.

-Planning, Discovery, Attack, and Reporting - -Four phases of penetration testing

-Port scanner - -What type of software can you use to enumerate the services that are
accepting network connections on a remote system without probing that system for
vulnerabilities?

-nmap - -What is the most commonly used port scanner?

-Traceroute or tracert, depending on the operating system - -What tool can be used to
determine the path between two systems over the Internet?

-Anomaly analysis - -What type of data analysis looks for differences from expected
behaviors?

-Trend analysis - -What type of data analysis predicts threats based on existing data?

-Credentialed scan - -What type of vulnerability scan leverages read-only access to the
scan target?

-Risk appetite - -What term is used to describe an organization's willingness to tolerate
risk?

-Read-only account - -What type of account should be used to perform credentialed
vulnerability scans?

, -Vulnerability scanning - -What function is performed by QualysGuard, Nessus, Nexpose,
and OpenVAS?

-Web application scanning - -What is the purpose of Nikto and Acunetix?

-Criticality
Difficulty
Severity
Exposure - -Remediation Priority

-CVSS - -What industry-standard system is used to assess the severity of security
vulnerabilities?

-False positive - -What is the term used to describe when a scanner reports a vulnerability
that does not really exist?

-Buffer overflow - -What type of vulnerability allows an attacker to place more data into
an area of memory than is allocated for a specific purpose?

-Privilege escalation - -What type of attack seeks to increase the level of access that an
attacker has to a targeted system?

-Arbitrary code execution - -What type of attack allows an attacker to run software of his
or her choice on the targeted system?

-TLS 1.2 or later - -What is the current secure standard for providing HTTPS encryption?

-DNS amplification - -In what type of attack does the attacker sends spoofed DNS requests
to a DNS server that are carefully designed to elicit responses that are much larger in size
than the original requests?

-Security event - -What term is used to describe any observable occurrence in a system or
network that relates to a security function?

-Security incident - -What term is used to describe a violation or imminent threat of
violation of computer security policies, acceptable use policies, or standard security
practices?

-Preparation
Detection & Analysis
Containment, Eradication, & Recovery
Post-Incident Activity - -What are the phases of incident response?

-Procedures - -What type of documents provide the detailed, tactical information that
CSIRT members need when responding to an incident?

Written for

Institution
Study
Course

Document information

Uploaded on
September 10, 2025
Number of pages
7
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$12.99
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Bravoscores American InterContinental University
Follow You need to be logged in order to follow users or courses
Sold
132
Member since
3 year
Number of followers
50
Documents
9552
Last sold
6 days ago

4.0

33 reviews

5
17
4
6
3
5
2
2
1
3

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions