Geschreven door studenten die geslaagd zijn Direct beschikbaar na je betaling Online lezen of als PDF Verkeerd document? Gratis ruilen 4,6 TrustPilot
logo-home
Document preview thumbnail
Voorbeeld 3 van de 18 pagina's
Tentamen (uitwerkingen)

CYSA CORRECT STUDYS QUESTIONS AND ANSWERS SURE A.pdf

Document preview thumbnail
Voorbeeld 3 van de 18 pagina's

CYSA CORRECT STUDYS QUESTIONS AND ANSWERS SURE A.pdf

Voorbeeld van de inhoud

CYSA CORRECT STUDYS QUESTIONS AND
ANSWERS SURE A+
✔✔While reviewing a packet capture. a security analyst discovers a recent attack used
specific ports communicating across non-standard ports and exchanged a particular set
of files. In addition, forensics determines the files contain malware and have a specific
callback domain within the files. The MOST appropriate action to take in this situation
would be to implement a change request for an IPS:
A. to block the callback domain and another signature hash to block the files
B. behavioral signature and update the blacklisting on the domain
C. rule to block the non-standard ports and update the blacklisting of the callback
domain
D. signature for the callback domain and update the firewall settings to block the non-
standard ports - ✔✔rule to block the non-standard ports and update the blacklisting of
the callback domain

✔✔During a review of the vulnerability scan results on a server. an information security
analyst notices the following:The MOST appropriate action for the analyst to
recommend to developers is to charge the web server so:
A. It only accepts TLSv1.2
B. It only accepts ciphers suites using AES and SHA
C. It no longer accepts the vulnerable cipher suites
D. SSL/TLS is offloaded to a WAF and load balancer - ✔✔It no longer accepts the
vulnerable cipher suites

✔✔As part of a merger with another organization, a Chief Information Security Manager
(CISO) is working with an assessor to perform a risk assessment focused on data
privacy compliance. The CISO is primarily concerned with the potential legal liability and
fines associated with data privacy. Based on the CISO's concerns, the assessor will
MOST likely focus on:
A. qualitative probabilities
B. quantitative probabilities
C. qualitative magnitude

,D. quantitative magnitude - ✔✔quantitative magnitude

✔✔concerned developers have too much visibility into customer data. Which of the
following controls should be implemented to BEST address these concerns?
A. Data masking
B. Data loss prevention
C. Data minimization
D. Data sovereignty - ✔✔Data masking

✔✔Which of the following will allow different cloud instances to share various types of
data with a minimal amount of complexity?
A. Reverse engineering
B. Application log collections
C. Workflow or orchestration
D. API integration
E. Scripting - ✔✔API integration

✔✔A security analyst is investigating an incident that appears that appears to have
started with SQL injection against a publicly available web application. Which of the
following is the FIRST step the analyst should take to prevent future attacks?
A. Modify the IDS rules to have a signature for SQL injection.
B. Take the server offline to prevent continue SQL injection.
C. Create a WAF rule in block mode for SQL injection.
D. Ask the developers to implement parameterized SQL queries. - ✔✔Ask the
developers to implement parameterized SQL queries.

✔✔A security analyst receives an alert that highly sensitive information has left the
company's network. Upon investigation, the analyst discovers an outside IP range has
had connections from three servers more than 100 times in the past month. The
affected servers are virtual machines. Which of the following is the BEST course of
action?
A. Shut down the servers as soon as possible, move them to a clean environment,
restart, run a vulnerability scanner to find weaknesses, determine the root cause,
remediate, and report.
B. Report the data exfiltration to management, take the affected servers offline, conduct
an antivirus scan, remediate all threats found, and return the servers to service.
C. Disconnect the affected servers from the network, use the virtual machine console to
access the systems, determine which information has left the network, find the security
weakness, and remediate.
D. Determine if any other serve - ✔✔Shut down the servers as soon as possible, move
them to a clean environment, restart, run a vulnerability scanner to find weaknesses,
determine the root cause, remediate, and report.

✔✔A critical server was compromised by malware, and all functionality was lost.
Backups of the server were taken; however, management believes a logic bomb may

, have been injected by a rootkit. Which of the following should a security analyst perform
to restore functionality quickly?
A. Work backward, restoring each backup until the server is clean.
B. Restore the previous backup and scan with a live boot anti-malware scanner.
C. Stand up a new server and restore critical data from backups.
D. Offload the critical data to a new server and continue operations. - ✔✔Stand up a
new server and restore critical data from backups.

✔✔The Chief Executive Officer (CEO) of a large insurance company has reported
phishing emails that contain malicious links are targeting the entire organization. Which
of the following actions would work BEST to prevent against this type of attack?
A. Turn on full behavioral analysis to avert an infection.
B. Implement an EDR mail module that will rewrite and analyze email links.
C. Reconfigure the EDR solution to perform real-time scanning of all files.
D. Ensure EDR signatures are updated every day to avert infection.
E. Modify the EDR solution to use heuristic analysis techniques for malware. -
✔✔Implement an EDR mail module that will rewrite and analyze email links.

✔✔The Chief Information Officer (CIO) of a large healthcare institution is concerned
about all machines having direct access to sensitive patient information. Which of the
following should the security analyst implement to BEST mitigate the risk of sensitive
data exposure?
A. A cloud access service broker system
B. NAC to ensure minimum standards are met
C. MFA on all workstations
D. Network segmentation - ✔✔Network segmentation

✔✔Which of the following MOST accurately describes an HSM?
A. An HSM is a low-cost solution for encryption.
B. An HSM can be networked based or a removable USB.
C. An HSM is slower at encrypting than software.
D. An HSM is explicitly used for MFA. - ✔✔An HSM can be networked based or a
removable USB.

✔✔As a proactive threat-hunting technique, hunters must develop situational cases
based on likely attack scenarios derived from the available threat intelligence
information. After forming the basis of the scenario, which of the following may the
threat hunter construct to establish a framework for threat assessment?
A. Critical assert list
B. Threat vector
C. Attack profile
D. Hypothesis - ✔✔Hypothesis

✔✔A security analyst is investigating malicious traffic from an internal system that
attempted to download proxy avoidance software as identified from the firewall logs, but

Documentinformatie

Geüpload op
10 juli 2026
Aantal pagina's
18
Geschreven in
2025/2026
Type
Tentamen (uitwerkingen)
Bevat
Vragen en antwoorden
$16.99

Verkeerd document? Gratis ruilen Binnen 14 dagen na aankoop en voor het downloaden kun je een ander document kiezen. Je kunt het bedrag gewoon opnieuw besteden.
Geschreven door studenten die geslaagd zijn
Direct beschikbaar na je betaling
Online lezen of als PDF

Seller avatar
De reputatie van een verkoper is gebaseerd op het aantal documenten dat iemand tegen betaling verkocht heeft en de beoordelingen die voor die items ontvangen zijn. Er zijn drie niveau’s te onderscheiden: brons, zilver en goud. Hoe beter de reputatie, hoe meer de kwaliteit van zijn of haar werk te vertrouwen is.
EXAMCAFE
3.4
(19)
Verkocht
154
Volgers
7
Items
26055
Laatst verkocht
7 uur geleden



Waarom studenten kiezen voor Stuvia

Gemaakt door medestudenten, geverifieerd door reviews

Kwaliteit die je kunt vertrouwen: geschreven door studenten die slaagden en beoordeeld door anderen die dit document gebruikten.

Niet tevreden? Kies een ander document

Geen zorgen! Je kunt voor hetzelfde geld direct een ander document kiezen dat beter past bij wat je zoekt.

Betaal zoals je wilt, start meteen met leren

Geen abonnement, geen verplichtingen. Betaal zoals je gewend bent via iDeal of creditcard en download je PDF-document meteen.

Student with book image

“Gekocht, gedownload en geslaagd. Zo makkelijk kan het dus zijn.”

Alisha Student

Bezig met je bronvermelding?

Maak nauwkeurige citaten in APA, MLA en Harvard met onze gratis bronnengenerator.

Bezig met je bronvermelding?

Veelgestelde vragen