Cysa Test 1 Certmaster with all Correct & 100% Verified
Answers |Actual Complete Exam |Already Graded A+
1. A financial institution experienced a security Business continuity
breach due to a phishing email that plan (BCP)
compromised employee credentials. The
incident response team responded promptly
by implementing the incident response plan
(IRP) and restoring services using the business
con-tinuity plan (BCP). After the incident, the
team con-ducted a lessons learned review to
identify areas for improvement in both plans.
Which plan will ensure business operations can
continue during and after the disruption?
Recovery time objective (RTO)
Disaster recovery plan (DRP)
Business continuity plan (BCP)
Incident response plan (IRP)
To determine the
2. A security administrator has identified se-quence of events
suspicious ac- that oc-
tivity on the network and believes a security
incident
occurred. The administrator needs to create a timeline curred during
the incident
of events to help determine the scope of the
incident and take appropriate actions. Why is
creating a time-line important in this
scenario?
To identify potential threats and incidents
1/
82
,Cysa Test 1 Certmaster with all Correct & 100% Verified
Answers |Actual Complete Exam |Already Graded A+
To determine the sequence of events that
occurred during the incident
To create an executive summary of the incident
2/
82
, Cysa Test 1 Certmaster with all Correct & 100% Verified
Answers |Actual Complete Exam |Already Graded A+
To assess the potential impacts of the incident
3. A security administrator creates an incident Stakeholder identification
response plan for the organization. What are and communication
some common components of incident Timeline
response planning that the security Incident declaration and
administrator should include in their plan? escalation
(Select the three best options.)
Stakeholder identification and communication
Timeline
Executive summary
Incident declaration and escalation
4. A security analyst has discovered a workstation infect- Educate end-
users on safe
ed with malware that has spread to other systems download-
on the network. The analyst has determined ing
that they cannot easily remove the malware unauthoriz
cannot and that ed
re-imaging the workstation is necessary. However, software
the workstation has important data that the
analyst has not backed up. After re-imaging Disable USB
the infected worksta-tion, what is the best ports on all
workstations
practice to prevent future mal-ware
infections?
Install anti-virus software on all workstations
Implement a security policy that prohibits
3/
82
, Cysa Test 1 Certmaster with all Correct & 100% Verified
Answers |Actual Complete Exam |Already Graded A+
rowsing and email prac-tices
4/
82
Answers |Actual Complete Exam |Already Graded A+
1. A financial institution experienced a security Business continuity
breach due to a phishing email that plan (BCP)
compromised employee credentials. The
incident response team responded promptly
by implementing the incident response plan
(IRP) and restoring services using the business
con-tinuity plan (BCP). After the incident, the
team con-ducted a lessons learned review to
identify areas for improvement in both plans.
Which plan will ensure business operations can
continue during and after the disruption?
Recovery time objective (RTO)
Disaster recovery plan (DRP)
Business continuity plan (BCP)
Incident response plan (IRP)
To determine the
2. A security administrator has identified se-quence of events
suspicious ac- that oc-
tivity on the network and believes a security
incident
occurred. The administrator needs to create a timeline curred during
the incident
of events to help determine the scope of the
incident and take appropriate actions. Why is
creating a time-line important in this
scenario?
To identify potential threats and incidents
1/
82
,Cysa Test 1 Certmaster with all Correct & 100% Verified
Answers |Actual Complete Exam |Already Graded A+
To determine the sequence of events that
occurred during the incident
To create an executive summary of the incident
2/
82
, Cysa Test 1 Certmaster with all Correct & 100% Verified
Answers |Actual Complete Exam |Already Graded A+
To assess the potential impacts of the incident
3. A security administrator creates an incident Stakeholder identification
response plan for the organization. What are and communication
some common components of incident Timeline
response planning that the security Incident declaration and
administrator should include in their plan? escalation
(Select the three best options.)
Stakeholder identification and communication
Timeline
Executive summary
Incident declaration and escalation
4. A security analyst has discovered a workstation infect- Educate end-
users on safe
ed with malware that has spread to other systems download-
on the network. The analyst has determined ing
that they cannot easily remove the malware unauthoriz
cannot and that ed
re-imaging the workstation is necessary. However, software
the workstation has important data that the
analyst has not backed up. After re-imaging Disable USB
the infected worksta-tion, what is the best ports on all
workstations
practice to prevent future mal-ware
infections?
Install anti-virus software on all workstations
Implement a security policy that prohibits
3/
82
, Cysa Test 1 Certmaster with all Correct & 100% Verified
Answers |Actual Complete Exam |Already Graded A+
rowsing and email prac-tices
4/
82