CYSA LATEST EXAMS SCRIPT QUESTIONS AND
ANSWERS SURE A+
✔✔Which one of the following terms is not typically used to describe the connection of
physical devices to a network? - ✔✔Intrusion detection systems (IDS)
✔✔Intrusion detection systems (IDS) are a __________________ used to detect
network or host attacks. - ✔✔security control
✔✔The Internet of Things (IoT), supervisory control and data acquisition (SCADA)
systems, and industrial control systems (ICS) are all associated with connecting
__________________ to a network. - ✔✔physical world objects
✔✔Monica discovers that an attacker posted a message in a web forum that she
manages that is attacking users who visit the site. Which one of the following attack
types is most likely to have occurred? - ✔✔cross-site scripting (XSS)
✔✔In a __________________, an attacker embeds scripting commands on a website
that will later be executed by an unsuspecting visitor accessing the site. The idea is to
trick a user visiting a trusted site into executing malicious code placed there by an
untrusted third party. - ✔✔cross-site scripting (XSS) attack
✔✔Alan is reviewing web server logs after an attack and finds many records that
contain semicolons and apostrophes in queries from end users. What type of attack
should he suspect? - ✔✔SQL injection
✔✔In an __________________, the attacker seeks to use a web application to gain
access to an underlying database. Semicolons and apostrophes are characteristic of
this attack. - ✔✔SQL injection attack
,✔✔Which one of the following is an example of a computer security incident? -
✔✔former employee crashes a server
✔✔A user accessing a secure file and an administrator changing a file permission
settings are examples of __________________ not security incidents. - ✔✔security
events
✔✔During what phase of the incident response process would an organization
implement defenses designed to reduce the likelihood of a security event? -
✔✔Preparation
✔✔Organizations should build solid, defense-in-depth approaches to cybersecurity
during the preparation phase of the __________________. The controls built during this
phase serve to reduce the likelihood and impact of future incidents. - ✔✔incident
response process
✔✔Alan is responsible for developing his organization's detection and analysis
capabilities. He would like to purchase a system that can combine log records from
multiple sources to detect potential security incidents. What type of system is best
suited to meet Alan's security objective? - ✔✔SIEM
✔✔A security information and event management (SIEM) system correlates log entries
from multiple sources and attempts to identify potential __________________. -
✔✔security incidents
✔✔Ben is working to classify the functional impact of an incident. The incident has
disabled email service for approximately 30 percent of his organization's staff. How
should Ben classify the functional impact of this incident according to the NIST scale? -
✔✔medium
✔✔According to the NIST scale, the definition of medium functional impact is that the
organization has lost the ability to provide a __________________ to a subset of
system users. - ✔✔critical service
✔✔According to the NIST scale, assigning a __________________ functional impact is
only done when the organization can provide all critical services to all users at
diminished efficiency. - ✔✔low
✔✔According to the NIST scale, assigning a __________________ functional impact is
only done if a critical service is not available to all users. - ✔✔high
,✔✔What phase of the incident response process would include measures designed to
limit the damage caused by an ongoing breach? - ✔✔containment, eradication, and
recovery
✔✔The __________________ contained in the containment, eradication, and recovery
phases are designed to limit the damage caused by an ongoing security incident. -
✔✔containment protocols
✔✔Grace is the CSIRT team leader for a business unit within NASA, a federal agency.
What is the minimum amount of time that Grace must retain incident handling records? -
✔✔three years
✔✔Karen is responding to a security incident that resulted from an intruder stealing files
from a government agency. Those files contained unencrypted information about
protected critical infrastructure. How should Karen rate the information impact of this
loss? - ✔✔proprietary breach
✔✔In a proprietary breach, __________________ proprietary information is accessed
or exfiltrated. - ✔✔unclassified
✔✔__________________ is an example of unclassified proprietary information. -
✔✔protected critical infrastructure information (PCII)
✔✔Matt is concerned about the fact that log records from his organization contain
conflicting timestamps due to unsynchronized clocks. What protocol can he use to
synchronize clocks throughout the enterprise? - ✔✔network time protocol (NTP)
✔✔Which one of the following document types would outline the authority of a CSIRT
responding to a security incident? - ✔✔policy
✔✔An organization's __________________ should contain a clear description of the
authority assigned to the CSIRT while responding to an active security incident. -
✔✔incident response policy
✔✔A cross-site scripting attack is an example of what type of threat vector? - ✔✔web
✔✔A __________________ is an attack executed from a website or web-based
application. - ✔✔web attack
✔✔A cross-site scripting (XSS) attack is used to steal credentials or redirect to a site
that exploits a browser vulnerability and installs __________________. - ✔✔malware
, ✔✔Which one of the following parties is not commonly the target of external
communications during an incident? - ✔✔the perpetrator
✔✔__________________ members do not normally communicate directly with the
perpetrator of a cybersecurity incident. - ✔✔CSIRT
✔✔Robert is finishing a draft of a proposed incident response policy for his
organization. Who would be the most appropriate person to sign the policy? - ✔✔CEO
✔✔The __________________ provides the CSIRT with the authority needed to do their
job. Therefore, it should be approved by the highest possible level of authority within the
organization, preferably the CEO. - ✔✔incident response policy
✔✔Which one of the following is not an objective of the containment, eradication, and
recovery phase of incident response? - ✔✔detect an incident in progress
✔✔Implementing a containment strategy, identifying the attackers, and eradicating the
effects of an incident are all objectives of the __________________ of incident
response. - ✔✔containment, eradication and recovery phase
✔✔Renee is responding to a security incident that resulted in the unavailability of a
website critical to her company's operations. She is unsure of the amount of time and
effort that it will take to recover the website. How should Renee classify the
recoverability effort? - ✔✔extended
✔✔__________________effort occurs when the time to recovery is unpredictable. In
those cases, additional resources and outside help are typically needed. - ✔✔extended
recoverability
✔✔Which one of the following is an example of an attrition attack? - ✔✔brute-force
password attack
✔✔An __________________ attack employs brute-force methods to compromise,
degrade, or destroy systems, networks, or services - for example, a DDoS attack
intended to impair or deny access to a service or application or a brute-force attack
against an authentication mechanism. - ✔✔attrition attack
✔✔Who is the best facilitator for a post-incident lessons-learned session? -
✔✔independent facilitator
✔✔__________________ sessions are most effective when facilitated by an
independent party who was not involved in the incident response effort. - ✔✔Lessons-
learned
ANSWERS SURE A+
✔✔Which one of the following terms is not typically used to describe the connection of
physical devices to a network? - ✔✔Intrusion detection systems (IDS)
✔✔Intrusion detection systems (IDS) are a __________________ used to detect
network or host attacks. - ✔✔security control
✔✔The Internet of Things (IoT), supervisory control and data acquisition (SCADA)
systems, and industrial control systems (ICS) are all associated with connecting
__________________ to a network. - ✔✔physical world objects
✔✔Monica discovers that an attacker posted a message in a web forum that she
manages that is attacking users who visit the site. Which one of the following attack
types is most likely to have occurred? - ✔✔cross-site scripting (XSS)
✔✔In a __________________, an attacker embeds scripting commands on a website
that will later be executed by an unsuspecting visitor accessing the site. The idea is to
trick a user visiting a trusted site into executing malicious code placed there by an
untrusted third party. - ✔✔cross-site scripting (XSS) attack
✔✔Alan is reviewing web server logs after an attack and finds many records that
contain semicolons and apostrophes in queries from end users. What type of attack
should he suspect? - ✔✔SQL injection
✔✔In an __________________, the attacker seeks to use a web application to gain
access to an underlying database. Semicolons and apostrophes are characteristic of
this attack. - ✔✔SQL injection attack
,✔✔Which one of the following is an example of a computer security incident? -
✔✔former employee crashes a server
✔✔A user accessing a secure file and an administrator changing a file permission
settings are examples of __________________ not security incidents. - ✔✔security
events
✔✔During what phase of the incident response process would an organization
implement defenses designed to reduce the likelihood of a security event? -
✔✔Preparation
✔✔Organizations should build solid, defense-in-depth approaches to cybersecurity
during the preparation phase of the __________________. The controls built during this
phase serve to reduce the likelihood and impact of future incidents. - ✔✔incident
response process
✔✔Alan is responsible for developing his organization's detection and analysis
capabilities. He would like to purchase a system that can combine log records from
multiple sources to detect potential security incidents. What type of system is best
suited to meet Alan's security objective? - ✔✔SIEM
✔✔A security information and event management (SIEM) system correlates log entries
from multiple sources and attempts to identify potential __________________. -
✔✔security incidents
✔✔Ben is working to classify the functional impact of an incident. The incident has
disabled email service for approximately 30 percent of his organization's staff. How
should Ben classify the functional impact of this incident according to the NIST scale? -
✔✔medium
✔✔According to the NIST scale, the definition of medium functional impact is that the
organization has lost the ability to provide a __________________ to a subset of
system users. - ✔✔critical service
✔✔According to the NIST scale, assigning a __________________ functional impact is
only done when the organization can provide all critical services to all users at
diminished efficiency. - ✔✔low
✔✔According to the NIST scale, assigning a __________________ functional impact is
only done if a critical service is not available to all users. - ✔✔high
,✔✔What phase of the incident response process would include measures designed to
limit the damage caused by an ongoing breach? - ✔✔containment, eradication, and
recovery
✔✔The __________________ contained in the containment, eradication, and recovery
phases are designed to limit the damage caused by an ongoing security incident. -
✔✔containment protocols
✔✔Grace is the CSIRT team leader for a business unit within NASA, a federal agency.
What is the minimum amount of time that Grace must retain incident handling records? -
✔✔three years
✔✔Karen is responding to a security incident that resulted from an intruder stealing files
from a government agency. Those files contained unencrypted information about
protected critical infrastructure. How should Karen rate the information impact of this
loss? - ✔✔proprietary breach
✔✔In a proprietary breach, __________________ proprietary information is accessed
or exfiltrated. - ✔✔unclassified
✔✔__________________ is an example of unclassified proprietary information. -
✔✔protected critical infrastructure information (PCII)
✔✔Matt is concerned about the fact that log records from his organization contain
conflicting timestamps due to unsynchronized clocks. What protocol can he use to
synchronize clocks throughout the enterprise? - ✔✔network time protocol (NTP)
✔✔Which one of the following document types would outline the authority of a CSIRT
responding to a security incident? - ✔✔policy
✔✔An organization's __________________ should contain a clear description of the
authority assigned to the CSIRT while responding to an active security incident. -
✔✔incident response policy
✔✔A cross-site scripting attack is an example of what type of threat vector? - ✔✔web
✔✔A __________________ is an attack executed from a website or web-based
application. - ✔✔web attack
✔✔A cross-site scripting (XSS) attack is used to steal credentials or redirect to a site
that exploits a browser vulnerability and installs __________________. - ✔✔malware
, ✔✔Which one of the following parties is not commonly the target of external
communications during an incident? - ✔✔the perpetrator
✔✔__________________ members do not normally communicate directly with the
perpetrator of a cybersecurity incident. - ✔✔CSIRT
✔✔Robert is finishing a draft of a proposed incident response policy for his
organization. Who would be the most appropriate person to sign the policy? - ✔✔CEO
✔✔The __________________ provides the CSIRT with the authority needed to do their
job. Therefore, it should be approved by the highest possible level of authority within the
organization, preferably the CEO. - ✔✔incident response policy
✔✔Which one of the following is not an objective of the containment, eradication, and
recovery phase of incident response? - ✔✔detect an incident in progress
✔✔Implementing a containment strategy, identifying the attackers, and eradicating the
effects of an incident are all objectives of the __________________ of incident
response. - ✔✔containment, eradication and recovery phase
✔✔Renee is responding to a security incident that resulted in the unavailability of a
website critical to her company's operations. She is unsure of the amount of time and
effort that it will take to recover the website. How should Renee classify the
recoverability effort? - ✔✔extended
✔✔__________________effort occurs when the time to recovery is unpredictable. In
those cases, additional resources and outside help are typically needed. - ✔✔extended
recoverability
✔✔Which one of the following is an example of an attrition attack? - ✔✔brute-force
password attack
✔✔An __________________ attack employs brute-force methods to compromise,
degrade, or destroy systems, networks, or services - for example, a DDoS attack
intended to impair or deny access to a service or application or a brute-force attack
against an authentication mechanism. - ✔✔attrition attack
✔✔Who is the best facilitator for a post-incident lessons-learned session? -
✔✔independent facilitator
✔✔__________________ sessions are most effective when facilitated by an
independent party who was not involved in the incident response effort. - ✔✔Lessons-
learned