CySA study guide Exam Questions and
Answers with Verified Solutions | Latest
Updated 2026
Operational control Implemented by people rather than
systems.
Security guards and training programs.
Managerial control Oversight of the information system.
Includes risk
identification or a tool for evaluation and
selection
of other security controls.
Information Sharing and Analysis Provide critical infrastructure owners and
Centers (ISACs) operators
with cybersecurity information and
services.
Public Cloud Designed for public access and geared
toward
those without the budget, resources, or
desire to
build and manage a private cloud or data
center.
Private Cloud Designed, built, and managed in-house
using
organization-owned hardware and
software.
,Hybrid Cloud Refers to the combination of resources in
both a
public and private cloud.
Serverless All the architecture is hosted within a
cloud.
Cloud access security broker Enterprise management software designed
(CASB) to
mediate access to cloud services by users
across
all types of devices.
Federation The company trusts accounts created and
managed by a different network.
Logging levels IMPORTANT: 0 Emergency, 1 Alert, 2
Critical, 3
Error, 4 Warning, 5 Notice, 6 Informational,
7
Debug.
Webhooks Automated messages sent from
applications to
other applications, particularly when
certain events
occur.
, Single Pane of Glass Powerful way of managing security
Orchestration operations,
allowing security teams to see, monitor,
and
control all their security systems and
services in
one place.
CMMI Levels Level 1 - Initial; Level 2 - Managed; Level 3
-
Defined; Level 4 - Quantitatively Manage;
Level 5 -
Optimizing.
CVSS Base Score CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I
:H/A:H.
Attack Vector (AV) Network (N), Adjacent (A), Local (L),
Physical (P).
Attack Complexity (AC) Low (L), High (H).
Privileges Required (PR) None (N), Low (L), High (H).
User Interaction (UI) None (N), Required (R).
Scope (S) Unchanged (U), Changed (C).
Confidentiality Impact (C) None (N), Low (L), High (H).
Answers with Verified Solutions | Latest
Updated 2026
Operational control Implemented by people rather than
systems.
Security guards and training programs.
Managerial control Oversight of the information system.
Includes risk
identification or a tool for evaluation and
selection
of other security controls.
Information Sharing and Analysis Provide critical infrastructure owners and
Centers (ISACs) operators
with cybersecurity information and
services.
Public Cloud Designed for public access and geared
toward
those without the budget, resources, or
desire to
build and manage a private cloud or data
center.
Private Cloud Designed, built, and managed in-house
using
organization-owned hardware and
software.
,Hybrid Cloud Refers to the combination of resources in
both a
public and private cloud.
Serverless All the architecture is hosted within a
cloud.
Cloud access security broker Enterprise management software designed
(CASB) to
mediate access to cloud services by users
across
all types of devices.
Federation The company trusts accounts created and
managed by a different network.
Logging levels IMPORTANT: 0 Emergency, 1 Alert, 2
Critical, 3
Error, 4 Warning, 5 Notice, 6 Informational,
7
Debug.
Webhooks Automated messages sent from
applications to
other applications, particularly when
certain events
occur.
, Single Pane of Glass Powerful way of managing security
Orchestration operations,
allowing security teams to see, monitor,
and
control all their security systems and
services in
one place.
CMMI Levels Level 1 - Initial; Level 2 - Managed; Level 3
-
Defined; Level 4 - Quantitatively Manage;
Level 5 -
Optimizing.
CVSS Base Score CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I
:H/A:H.
Attack Vector (AV) Network (N), Adjacent (A), Local (L),
Physical (P).
Attack Complexity (AC) Low (L), High (H).
Privileges Required (PR) None (N), Low (L), High (H).
User Interaction (UI) None (N), Required (R).
Scope (S) Unchanged (U), Changed (C).
Confidentiality Impact (C) None (N), Low (L), High (H).