CYSA CORE REVIEW QUESTIONS AND ANSWERS
SURE A+
✔✔As part of an exercise set up by the information security officer, the IT staff must
move some of the network systems to an off-site facility and redeploy them for testing.
All staff members must ensure their respective systems can power back up and match their g
old image. If they find any inconsistencies, they must formally document the information
. Which of the following BEST describes this test?
A. Walk through
B. Full interruption
C. Simulation
D. Parallel - ✔✔Parallel
✔✔A security analyst is reviewing the following log from an email security service.Which
of the following BEST describes the reason why the email was blocked?
A. The To address is invalid.
B. The email originated from the www.spamfilter.org URL.
C. The IP address and the remote server name are the same.
D. The IP address was blacklisted.
E. The From address is invalid. - ✔✔The IP address was blacklisted.
✔✔Which of the following roles is ultimately responsible for determining the
classification levels assigned to specific data sets?
A. Data custodian
B. Data owner
C. Data processor
D. Senior management - ✔✔Data owner
✔✔A security analyst is reviewing the logs from an internal chat server. The chat.log file
is too large to review manually, so the analyst wants to create a shorter log file that only
includes lines associated with a user demonstrating anomalous activity. Below is a
snippet of the log:
A. grep -v chatter14 chat.log
, B. grep -i pythonfun chat.log
C. grep -i javashark chat.log
D. grep -v javashark chat.log
E. grep -v pythonfun chat.log
F. grep -i chatter14 chat.log - ✔✔grep -v javashark chat.log
✔✔A Chief Information Security Officer (CISO) wants to upgrade an organization's
security posture by improving proactive activities associated with attacks from internal
and external threats. Which of the following is the MOST proactive tool or technique that
feeds incident response capabilities?
A. Development of a hypothesis as part of threat hunting
B. Log correlation, monitoring, and automated reporting through a SIEM platform
C. Continuous compliance monitoring using SCAP dashboards
D. Quarterly vulnerability scanning using credentialed scans - ✔✔Development of a
hypothesis as part of threat hunting
✔✔Which of the following software security best practices would prevent an attacker
from being able to run arbitrary SQL commands within a web application? (Choose
two.)
A. Parameterized queries
B. Session management
C. Input validation
D. Output encoding
E. Data protection
F. Authentication - ✔✔Parameterized queries and Input validation
✔✔A security analyst received a SIEM alert regarding high levels of memory
consumption for a critical system. After several attempts to remediate the issue, the
system went down. A root cause analysis revealed a bad actor forced the application to
not reclaim memory. This caused the system to be depleted of resources.Which of the
following BEST describes this attack?
A. Injection attack
B. Memory corruption
C. Denial of service
D. Array attack - ✔✔Denial of service
✔✔An information security analyst observes anomalous behavior on the SCADA
devices in a power plant. This behavior results in the industrial generators overheating
and destabilizing the power supply. Which of the following would BEST identify potential
indicators of compromise?
A. Use Burp Suite to capture packets to the SCADA device's IP.
B. Use tcpdump to capture packets from the SCADA device IP.
C. Use Wireshark to capture packets between SCADA devices and the management
system.
SURE A+
✔✔As part of an exercise set up by the information security officer, the IT staff must
move some of the network systems to an off-site facility and redeploy them for testing.
All staff members must ensure their respective systems can power back up and match their g
old image. If they find any inconsistencies, they must formally document the information
. Which of the following BEST describes this test?
A. Walk through
B. Full interruption
C. Simulation
D. Parallel - ✔✔Parallel
✔✔A security analyst is reviewing the following log from an email security service.Which
of the following BEST describes the reason why the email was blocked?
A. The To address is invalid.
B. The email originated from the www.spamfilter.org URL.
C. The IP address and the remote server name are the same.
D. The IP address was blacklisted.
E. The From address is invalid. - ✔✔The IP address was blacklisted.
✔✔Which of the following roles is ultimately responsible for determining the
classification levels assigned to specific data sets?
A. Data custodian
B. Data owner
C. Data processor
D. Senior management - ✔✔Data owner
✔✔A security analyst is reviewing the logs from an internal chat server. The chat.log file
is too large to review manually, so the analyst wants to create a shorter log file that only
includes lines associated with a user demonstrating anomalous activity. Below is a
snippet of the log:
A. grep -v chatter14 chat.log
, B. grep -i pythonfun chat.log
C. grep -i javashark chat.log
D. grep -v javashark chat.log
E. grep -v pythonfun chat.log
F. grep -i chatter14 chat.log - ✔✔grep -v javashark chat.log
✔✔A Chief Information Security Officer (CISO) wants to upgrade an organization's
security posture by improving proactive activities associated with attacks from internal
and external threats. Which of the following is the MOST proactive tool or technique that
feeds incident response capabilities?
A. Development of a hypothesis as part of threat hunting
B. Log correlation, monitoring, and automated reporting through a SIEM platform
C. Continuous compliance monitoring using SCAP dashboards
D. Quarterly vulnerability scanning using credentialed scans - ✔✔Development of a
hypothesis as part of threat hunting
✔✔Which of the following software security best practices would prevent an attacker
from being able to run arbitrary SQL commands within a web application? (Choose
two.)
A. Parameterized queries
B. Session management
C. Input validation
D. Output encoding
E. Data protection
F. Authentication - ✔✔Parameterized queries and Input validation
✔✔A security analyst received a SIEM alert regarding high levels of memory
consumption for a critical system. After several attempts to remediate the issue, the
system went down. A root cause analysis revealed a bad actor forced the application to
not reclaim memory. This caused the system to be depleted of resources.Which of the
following BEST describes this attack?
A. Injection attack
B. Memory corruption
C. Denial of service
D. Array attack - ✔✔Denial of service
✔✔An information security analyst observes anomalous behavior on the SCADA
devices in a power plant. This behavior results in the industrial generators overheating
and destabilizing the power supply. Which of the following would BEST identify potential
indicators of compromise?
A. Use Burp Suite to capture packets to the SCADA device's IP.
B. Use tcpdump to capture packets from the SCADA device IP.
C. Use Wireshark to capture packets between SCADA devices and the management
system.