CYSA COMPREHENSIVE EXAM QUESTIONS
AND CORRECT ANSWERS STUDY GUIDE
●● A cybersecurity analyst is reviewing the current BYOD security
posture. The users must be able to synchronize their calendars, email,
and contacts to a smartphone
or other personal device. The recommendation must provide the most
flexibility to users. Which of the following recommendations would
meet both the mobile data
protection efforts and the business requirements described in this
scenario?
A. Develop a minimum security baseline while restricting the type of
data that can be accessed.
B. Implement a single computer configured with USB access and
monitored by sensors.
C. Deploy a kiosk for synchronizing while using an access list of
approved users.
D. Implement a wireless network configured for mobile device access
and monitored by sensors.
Answer: D
●● A security analyst received a compromised workstation. The
workstation's hard drive may contain evidence of criminal activities.
Which of the following is the FIRST
,thing the analyst must do to ensure the integrity of the hard drive while
performing the analysis?
A. Make a copy of the hard drive.
B. Use write blockers.
C. Run rm -R command to create a hash.
D. Install it on a different machine and explore the content.
Answer: B
●● File integrity monitoring states the following files have been
changed without a written request or approved change. The following
change has been made:
chmod 777 -Rv /usr
Which of the following may be occurring?
A. The ownership pf /usr has been changed to the current user.
B. Administrative functions have been locked from users.
C. Administrative commands have been made world readable/
Answer: C
●● A security analyst has created an image of a drive from an incident.
Which of the following describes what the analyst should do NEXT?
A. The analyst should create a backup of the drive and then hash the
drive.
,B. The analyst should begin analyzing the image and begin to report
findings.
C. The analyst should create a hash of the image and compare it to the
original drive's hash.
D. The analyst should create a chain of custody document and notify
stakeholders.
Answer: C
●● A cybersecurity analyst is currently investigating a server outage.
The analyst has discovered the following value was entered for the
username: 0xbfff601a. Which of
the following attacks may be occurring?
A. Buffer overflow attack
B. Man-in-the-middle attack
C. Smurf attack
D. Format string attack
Answer: D
●● External users are reporting that a web application is slow and
frequently times out when attempting to submit information. Which of
the following software
development best practices would have helped prevent this issue?
A. Stress testing
B. Regression testing
, C. Input validation
D. Fuzzing
Answer: A
●● An analyst has initiated an assessment of an organization's security
posture. As a part of this review, the analyst would like to determine how
much information about
the organization is exposed externally. Which of the following
techniques would BEST help the analyst accomplish this goal? (Select
two.)
A. Fingerprinting
B. DNS query log reviews
C. Banner grabbing
D. Internet searches
E. Intranet portal reviews
F. Sourcing social network sites
G. Technical control audits
Answer: DF
●● A cybersecurity professional typed in a URL and discovered the
admin panel for the e-commerce application is accessible over the open
web with the default
password. Which of the following is the MOST secure solution to
remediate this vulnerability?
AND CORRECT ANSWERS STUDY GUIDE
●● A cybersecurity analyst is reviewing the current BYOD security
posture. The users must be able to synchronize their calendars, email,
and contacts to a smartphone
or other personal device. The recommendation must provide the most
flexibility to users. Which of the following recommendations would
meet both the mobile data
protection efforts and the business requirements described in this
scenario?
A. Develop a minimum security baseline while restricting the type of
data that can be accessed.
B. Implement a single computer configured with USB access and
monitored by sensors.
C. Deploy a kiosk for synchronizing while using an access list of
approved users.
D. Implement a wireless network configured for mobile device access
and monitored by sensors.
Answer: D
●● A security analyst received a compromised workstation. The
workstation's hard drive may contain evidence of criminal activities.
Which of the following is the FIRST
,thing the analyst must do to ensure the integrity of the hard drive while
performing the analysis?
A. Make a copy of the hard drive.
B. Use write blockers.
C. Run rm -R command to create a hash.
D. Install it on a different machine and explore the content.
Answer: B
●● File integrity monitoring states the following files have been
changed without a written request or approved change. The following
change has been made:
chmod 777 -Rv /usr
Which of the following may be occurring?
A. The ownership pf /usr has been changed to the current user.
B. Administrative functions have been locked from users.
C. Administrative commands have been made world readable/
Answer: C
●● A security analyst has created an image of a drive from an incident.
Which of the following describes what the analyst should do NEXT?
A. The analyst should create a backup of the drive and then hash the
drive.
,B. The analyst should begin analyzing the image and begin to report
findings.
C. The analyst should create a hash of the image and compare it to the
original drive's hash.
D. The analyst should create a chain of custody document and notify
stakeholders.
Answer: C
●● A cybersecurity analyst is currently investigating a server outage.
The analyst has discovered the following value was entered for the
username: 0xbfff601a. Which of
the following attacks may be occurring?
A. Buffer overflow attack
B. Man-in-the-middle attack
C. Smurf attack
D. Format string attack
Answer: D
●● External users are reporting that a web application is slow and
frequently times out when attempting to submit information. Which of
the following software
development best practices would have helped prevent this issue?
A. Stress testing
B. Regression testing
, C. Input validation
D. Fuzzing
Answer: A
●● An analyst has initiated an assessment of an organization's security
posture. As a part of this review, the analyst would like to determine how
much information about
the organization is exposed externally. Which of the following
techniques would BEST help the analyst accomplish this goal? (Select
two.)
A. Fingerprinting
B. DNS query log reviews
C. Banner grabbing
D. Internet searches
E. Intranet portal reviews
F. Sourcing social network sites
G. Technical control audits
Answer: DF
●● A cybersecurity professional typed in a URL and discovered the
admin panel for the e-commerce application is accessible over the open
web with the default
password. Which of the following is the MOST secure solution to
remediate this vulnerability?