CYSA - Exam 1 - Attempt 1 Questions and
Answers with Verified Solutions | Latest
Updated 2026
An analyst reviews a triple-homed A triple-homed firewall connects to three
firewall configuration that connects networks: internal (private), external
to the internet, a private network, (internet/public), and the Screened Subnet.
and one other network. Which of
the
following would best describe the
third network connected to this
firewall?
NIDS
GPO
Screened Subnet (DMZ)
Subnet
As a cybersecurity professional, This line of code demonstrates a potential
you're reviewing a Python script command injection. The os.system
used in your organization's function in
automation process. You notice Python executes a shell command from a
the string,
following line of code: which in this case, is 'rm -rf /' - a Unix
os.system('rm command to
-rf /') What potential security delete all files from the root directory.
concern does this line of code
represent?
Command Injection
Buffer Overflow
SQL Injection
Cross-Site Scripting (XSS)
,Which of the following type of Air gaps are designed to remove
threats did the Stuxnet attack rely connections
on between two networks to create physical
to cross an airgap between a segmentation between them. The only way
business and an industrial control to cross
system network? an air gap is to have a physical device
Cross-site scripting between
Session hijacking these systems, such as using a removable
Directory traversal media
Removable media device to transfer files between them.
Which of the following methods is Tokenization means that all or part of data
used to replace all or part of a data in a field
field with a randomly generated is replaced with a randomly generated
number used to reference the token. The
original value stored in another token is stored with the original value on a
vault token
or database? server or token vault, separate from the
Anonymization production
Tokenization database. An authorized query or app can
Data minimization retrieve
Data masking the original value from the vault, if
necessary, so
tokenization is a reversible technique.
,You are analyzing the logs of a This is an example of an XSS attack as
web recorded by
server and see the following entry: a web server's log. In this example, the
<br /><br XSS attack
/>-=-=-=-=-=--=-=-=-=-=--=-=- was obfuscated by the attacker using
=-=-=-<br /><br />192.168.1.25 - - HTML
[05/Aug/2020:15:16:42 -0400] encoding. The encoding of %27%27
"GET translates to
/%27%27;!-%22%3CDION%3E=& two single quote marks (' '). While you
{()} don't need
HTTP/1.1″ 404 310 "-" "Mozilla/5.0 to be able to decode the exact string used
(X11; in the
U; Linux x86_64; en-US; logs, when you see HTML encoding on the
rv:1.9.0.12)Gecko/2009070812 exam, it
Ubuntu/19.04 (disco dingo) is usually going to be an XSS attack
Firefox/3.0.12″<br /><br unless you see
/>-=-=-=-=-=-- SQL or XML statements in the string,
=-=-=-=-=--=-=-=-=-=-<br /><br which in this
/>Based case there are neither of those.
on this entry, which of the
following
attacks was attempted?
SQL injection
XSS
Buffer overflow
XML injection
, When using tcpdump, which The -e option includes the ethernet header
option during
or flag would you use to record the packet capture.
ethernet frames during a packet The -n flag will show the IP addresses in
capture? numeric
-nn form.
-e The -nn option shows IP addresses and
-X ports in
-n numeric format.
The -X option will capture the packet's
payload in
hex and ASCII formats.
Which of the following protocols is Simple Network Management Protocol
commonly used to collect (SNMP) is
information about CPU utilization commonly used to gather information from
and memory usage from network routers,
devices? MIB, SMPT, SNMP, switches, and other network devices. It
Neflow provides
information about a device's status,
including CPU
and memory utilization, and many other
useful
details about the device.
Answers with Verified Solutions | Latest
Updated 2026
An analyst reviews a triple-homed A triple-homed firewall connects to three
firewall configuration that connects networks: internal (private), external
to the internet, a private network, (internet/public), and the Screened Subnet.
and one other network. Which of
the
following would best describe the
third network connected to this
firewall?
NIDS
GPO
Screened Subnet (DMZ)
Subnet
As a cybersecurity professional, This line of code demonstrates a potential
you're reviewing a Python script command injection. The os.system
used in your organization's function in
automation process. You notice Python executes a shell command from a
the string,
following line of code: which in this case, is 'rm -rf /' - a Unix
os.system('rm command to
-rf /') What potential security delete all files from the root directory.
concern does this line of code
represent?
Command Injection
Buffer Overflow
SQL Injection
Cross-Site Scripting (XSS)
,Which of the following type of Air gaps are designed to remove
threats did the Stuxnet attack rely connections
on between two networks to create physical
to cross an airgap between a segmentation between them. The only way
business and an industrial control to cross
system network? an air gap is to have a physical device
Cross-site scripting between
Session hijacking these systems, such as using a removable
Directory traversal media
Removable media device to transfer files between them.
Which of the following methods is Tokenization means that all or part of data
used to replace all or part of a data in a field
field with a randomly generated is replaced with a randomly generated
number used to reference the token. The
original value stored in another token is stored with the original value on a
vault token
or database? server or token vault, separate from the
Anonymization production
Tokenization database. An authorized query or app can
Data minimization retrieve
Data masking the original value from the vault, if
necessary, so
tokenization is a reversible technique.
,You are analyzing the logs of a This is an example of an XSS attack as
web recorded by
server and see the following entry: a web server's log. In this example, the
<br /><br XSS attack
/>-=-=-=-=-=--=-=-=-=-=--=-=- was obfuscated by the attacker using
=-=-=-<br /><br />192.168.1.25 - - HTML
[05/Aug/2020:15:16:42 -0400] encoding. The encoding of %27%27
"GET translates to
/%27%27;!-%22%3CDION%3E=& two single quote marks (' '). While you
{()} don't need
HTTP/1.1″ 404 310 "-" "Mozilla/5.0 to be able to decode the exact string used
(X11; in the
U; Linux x86_64; en-US; logs, when you see HTML encoding on the
rv:1.9.0.12)Gecko/2009070812 exam, it
Ubuntu/19.04 (disco dingo) is usually going to be an XSS attack
Firefox/3.0.12″<br /><br unless you see
/>-=-=-=-=-=-- SQL or XML statements in the string,
=-=-=-=-=--=-=-=-=-=-<br /><br which in this
/>Based case there are neither of those.
on this entry, which of the
following
attacks was attempted?
SQL injection
XSS
Buffer overflow
XML injection
, When using tcpdump, which The -e option includes the ethernet header
option during
or flag would you use to record the packet capture.
ethernet frames during a packet The -n flag will show the IP addresses in
capture? numeric
-nn form.
-e The -nn option shows IP addresses and
-X ports in
-n numeric format.
The -X option will capture the packet's
payload in
hex and ASCII formats.
Which of the following protocols is Simple Network Management Protocol
commonly used to collect (SNMP) is
information about CPU utilization commonly used to gather information from
and memory usage from network routers,
devices? MIB, SMPT, SNMP, switches, and other network devices. It
Neflow provides
information about a device's status,
including CPU
and memory utilization, and many other
useful
details about the device.