• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 75 pages
Exam (elaborations)

Chapter 8 – Cybersecurity Threat Intelligence and Analysis: Verified Questions and Answers (CySA+ Domain Focus)

Document preview thumbnail
Preview 4 out of 75 pages

This document contains comprehensive questions and answers on threat intelligence and analysis, aligning with key CySA+ certification content. Topics include the intelligence cycle, MITRE ATT&CK framework, threat actor types, tactics and techniques, and the role of open-source intelligence (OSINT). It provides essential insights for students and professionals preparing for exams or enhancing their incident analysis capabilities.

Content preview

8. Incident Management Operations questions
with verified answers
A computer incident response team manual should PRIMARILY contain
which of the following documents?


A. Risk assessment results
B. Severity criteria
C. Emergency call tree directory
D. Table of critical backup files Ans✓✓✓B is the correct answer.


Justification
B. Quickly ranking the severity criteria of an incident is a key element of
incident response.


A customer credit card database has been reported as being breached by
hackers. What is the FIRST step in dealing with this attack?


A. Confirm the incident.
B. Notify senior management.
C. Start containment.
D. Notify law enforcement. Ans✓✓✓A is the correct answer.


Justification

,A. Validating that the condition is a true security incident is the
necessary first step in determining the correct response.


A database was compromised by guessing the password for a shared
administrative account and confidential customer information was
stolen. The information security manager was able to detect this breach
by analyzing which of the following?


A. Invalid logon attempts
B. Write access violations
C. Concurrent logons
D. Firewall logs Ans✓✓✓A is the correct answer.


Justification
A. Because the password for the shared administrative account was
obtained through guessing, it is probable that there were multiple
unsuccessful logon attempts before the correct password was deduced.
Searching the logs for invalid logon attempts could, therefore, lead to the
discovery of this unauthorized activity.


A forensic team was commissioned to perform an analysis of
unrecognized processes running on a desktop personal computer. The
lead investigator advised the team against disconnecting the power in
order to:


A. prevent disk corruption.

,B. conduct a hot-swap of the main disk drive.
C. avoid loss of data in server logs.
D. avoid loss of data stored in volatile memory. Ans✓✓✓Justification
D. Disconnecting power from a system results in loss of data stored in
volatile memory. Those data could be vital for the investigation and for
understanding the extent of the impact of the event. Disconnecting
power is not recommended if analysis of running processes or the
content of volatile memory is required.


A new email virus that uses an attachment disguised as a picture file is
spreading rapidly over the Internet. Which of the following should be
performed FIRST in response to this threat?


A. Quarantine all picture files stored on file servers.
B. Block all emails containing picture file attachments.
C. Quarantine all mail servers connected to the Internet.
D. Block incoming Internet mail but permit outgoing mail. Ans✓✓✓B
is the correct answer.


Justification
B. Until signature files can be updated, incoming email containing
picture file attachments should be blocked.


A password hacking tool was used to capture detailed bank account
information and personal identification numbers. Upon confirming the
incident, the NEXT step is to:

, A. notify law enforcement.
B. start containment.
C. make an image copy of the media.
D. isolate affected servers. Ans✓✓✓B is the correct answer.


Justification
B. After an incident has been confirmed, containment is the first priority
of incident response because it will generally mitigate further impact.


A root kit was used to capture detailed accounts receivable information.
What is the next step to ensure admissibility of evidence from a legal
standpoint, once the incident has been identified and the server isolated?


A. Document how the attack occurred.
B. Notify law enforcement.
C. Take an image copy of the media.
D. Close the accounts receivable system. Ans✓✓✓C is the correct
answer.


Justification
C. Taking an image copy of the media along with preserving any other
evidence and maintaining the chain of custody is a recommended
practice to ensure legal admissibility.

Document information

Uploaded on
June 26, 2025
Number of pages
75
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$17.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
cracker
3.8
(401)
Sold
2168
Followers
1346
Items
50099
Last sold
3 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions