• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 56 pages
Exam (elaborations)

Cysa Actual Test Questions With Complete Answer Key

Document preview thumbnail
Preview 4 out of 56 pages

CYSA ACTUAL TEST QUESTIONS WITH COMPLETE ANSWER KEY

Content preview

CYSA ACTUAL TEST QUESTIONS WITH
COMPLETE ANSWER KEY

●● A gray hat hacker who desires to be ethical has discovered a critical
vulnerability that could potentially compromise a glass bottle
manufacturing company's user data. What should the gray hat hacker do
next?
Answer: Submit the findings to the company's bug bounty program


●● A company's security team reviews its security policies and
procedures to ensure they align with the company's current needs. What
is the most likely reason for this review?
Answer: To adapt to changing business requirements


●● A security engineer utilizes the Common Vulnerability Scoring
System (CVSS) to identify and calculate the likelihood of an exploit on
a server. Several users log in locally to the server in question. Which
metrics concern does the security engineer have when considering logon
account properties? (Select the two best options.)
Answer: Privileges, Interaction


●● A large tech company wants to design and implement secure systems
and applications resilient to cyber-attacks. Which cybersecurity process
should the company follow to implement secure features into its
products and service

,Answer: Security engineering


●● A large military contractor has recently experienced a series of cyber
attacks targeting their systems, resulting in the theft of sensitive military
technology. Upon investigation, the network administrator discovered
that the attackers used highly sophisticated methods and had access to
significant resources. What type of attacker is most likely responsible for
this breach?
Answer: Nation State


●● A security administrator uses Arachni, an open-source web scanner
application, to scan a web application for vulnerabilities. What type of
vulnerabilities does this application actively test?
Answer: Code injection, SQL injection, XSS, CSRF, and others


●● A cloud operations engineer monitors and maintains visibility into an
organization's serverless architecture. The engineer needs to ensure that
the system is functioning optimally and efficiently. What action would
be most helpful for the engineer to achieve this goal?
Answer: Monitor system processes


●● A security team is analyzing their system and network architecture to
improve their security posture. In the context of a potential security
incident, which aspect should the team prioritize to effectively detect
and respond to various types of unauthorized access to critical systems?
Answer: Analyzing anomalies in network traffic

,●● A security analyst suspects a file on a company's server may be
malicious. To determine if the file is known to be malicious or safe,
which of the following tools would be most appropriate for the analyst
to use?
Answer: Virus Total


●● The Chief Information Security Officer (CISO) at XYZ Corporation
received a legal request to preserve an employee's data under
investigation for insider trading. The CISO has to ensure that the data is
preserved and kept under legal hold until the company concludes its
investigation. Which of the following is true regarding chain of custody
in the scenario?
Answer: Chain of custody is the documentation of evidence movement
from one person to another, including who had custody of the evidence,
when and why they transferred it, and what they did with it.


●● A paintbrush bristle supply company has a business-critical web
server running old software on the internal network. Despite available
updates, the new software versions would not communicate with the rest
of the company's IT ecosystem. What type of controls should the
company consider implementing to address this issue?
Answer: Compensating


●● A security analyst needs to investigate a potential security incident
on their network. They collected log data from several sources, including

, one threat intelligence source and their IDS. However, they need
additional information to determine the scope and severity of the
incident. What technology can automatically add relevant context to the
raw log data
Answer: Data enrichment


●● A security analyst has identified a compromised system on the
network and needs to take action to prevent further damage. The analyst
has decided to implement compensating controls to limit the potential
damage. After implementing compensating controls, the security analyst
wants to isolate the compromised system from the network for further
analysis. Which of the following is the best approach for isolating the
system?
Answer: Physically disconnecting the system from the network


●● A security analyst is investigating a series of cyberattacks on their
organization. They suspect the threat actors use a specific method to
maintain communication with the compromised systems. Which method
do the threat actors most likely use to control the systems?
Answer: C2


●● The CIO (Chief Information Officer) for a modular dog furniture
startup receives a report that an advanced persistent threat (APT) has
compromised the startup's mail servers. What should be the CIO's top
priority for preventing future incidents?

Document information

Uploaded on
September 15, 2026
Number of pages
56
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$17.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
FocusFile7
4.0
(27)
Sold
278
Followers
4
Items
73761
Last sold
9 hours ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions