Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 2 out of 7 pages
Exam (elaborations)

CySa+ Exam Questions with All Correct & 100% Verified Answers |Latest Version |Already Graded A+

Document preview thumbnail
Preview 2 out of 7 pages

CySa+ Exam Questions with All Correct & 100% Verified Answers |Latest Version |Already Graded A+

Content preview

CySa+ Exam Questions with All Correct & 100% Verified
Answers |Latest Version |Already Graded A+

A Chief Information Security Officer (CISO) is concerned developers have too much visibility into
customer data. Which of the following controls should be implemented to BEST address these
concerns?
A. Data masking
B. Data loss prevention
C. Data minimization
D. Data sovereignty ✔Correct Answer-A

A Chief Information Security Officer (CISO) is concerned the development team, which consists
of contractors, has too much access to customer data. Developers use personal workstations,
giving the company little to no visibility into the development activities. Which of the following
would be BEST to implement to alleviate the CISO's concern?
A. DLP
B. Encryption
C. Test data
D. NDA ✔Correct Answer-A

A Chief Information Security Officer (CISO) wants to upgrade an organization's security posture
by improving proactive activities associated with attacks from internal and external threats.
Which of the following is the MOST proactive tool or technique that feeds incident response
capabilities?

A. Development of a hypothesis as part of threat hunting.
B. Log correlation, monitoring, and automated reporting through a SIEM platform
C. Continuous compliance monitoring using SCAP dashboards
D. Quarterly vulnerability scanning using credentialed scans ✔Correct Answer-A

A company recently experienced a break-in, whereby a number of hardware assets were stolen
through unauthorized access at the back of the building. Which of the following would BEST
prevent this type of theft from occurring in the future?

A. Motion detection
B. Perimeter fencing
C. Monitored security cameras
D. Badged entry ✔Correct Answer-D

A company wants to establish a threat-hunting team. Which of the following BEST describes the
rationale for integrating intelligence into hunt operation?

, A. It enables the learn to prioritize the focus areas and tactics within the company's
environment.
B. It provides criticality analyses for key enterprise servers and services.
C. It allows analysts to receive routine updates on newly discovered software vulnerabilities.
D. It supports rapid response and recovery during and following an incident. ✔Correct
Answer-A

A company was recently awarded several large government contracts and wants to determine
its current risk from one specific APT. Which of the following threat modelling methodologies
would be the MOST appropriate to use during this analysis?

A. Attack vectors
B. Adversary capability
C. Diamond Model of Intrusion Analysis
D. Kill chain
E. Total attack surface ✔Correct Answer-B

A company's incident response team is handling a threat that was identified on the network.
Security analysts have determined a web server is making multiple connections from TCP port
445 outbound to servers inside its subnet as well as at remote sites. Which of the following is
the MOST appropriate next step in the incident response plan?

A. Quarantine the web server.
B. Deploy virtual firewalls.
C. Capture a forensic image of the memory and disk.
D. Enable web server containerization. ✔Correct Answer-A

A company's marketing emails are either being found in a spam folder or not being delivered at
all. The security analyst investigates the issue and discovers the emails in question are being
sent on behalf of the company by a third part, mail.marketingpartners.com. Below is the
existing SPF record:
V=spfl a mx -all
Which of the following updates to the SPF record will work BEST to prevent the emails from
being marked as spam or blocked?

A. v=spfl a mx redirect:mail.marketingpartners.com ?all
B. v=spfl a mx include:mail.marketingpartners.com -all
C. v=spfl a mx +all
D. v=spfl a mx include:mail.marketingpartners.com ~all ✔Correct Answer-D

A compliance officer of a large organization has reviewed the firm's vendor management
program but has discovered there are no controls defined to evaluate third-party risk or
hardware source authenticity. The compliance officer wants to gain some level of assurance on

Document information

Uploaded on
July 10, 2026
Number of pages
7
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$16.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Studyclub
3.6
(14)
Sold
66
Followers
1
Items
12770
Last sold
6 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions