CySA Practice Exam C questions with verified answers
A company is concerned with finding sensitive file storage locations that are open
to the public. The
current internal cloud network is flat. Which of the following is the best solution
to secure the network?
• A. Implement segmentation with ACLs.
• B. Configure logging and monitoring to the SIEM.
• C. Deploy MFA to cloud storage locations.
• D. Roll out an IDS. Ans✓✓✓ A. Implement segmentation with ACLs.
A company is in the process of implementing a vulnerability management
program. Which of the
following scanning methods should be implemented to minimize the risk of
OT/ICS devices
malfunctioning due to the vulnerability identification process?
A. Non-credentialed scanning
B. Passive scanning
C. Agent-based scanning
D. Credentialed scanning Ans✓✓✓ B. Passive scanning
A company receives a penetration test report summary from a third party. The
report summary indicates
a proxy has some patches that need to be applied. The proxy is sitting in a rack
and is not being used, as
the company has replaced it with a new one. The CVE score of the vulnerability on
the proxy is a 9.8.
,Which of the following best practices should the company follow with this proxy?
• A. Leave the proxy as is.
• B. Decomission the proxy.
• C. Migrate the proxy to the cloud.
• D. Patch the proxy. Ans✓✓✓ B. Decomission the proxy.
A cybersecurity analyst is reviewing SIEM logs and observes consistent requests
originating from an internal host to a blocklisted external server. Which of the
following best describes the activity that is taking place?
A. Data exfiltration
B. Rogue device
C. Scanning
D. Beaconing Ans✓✓✓ D. Beaconing
A managed security service provider is having difficulty retaining talent due to an
increasing workload caused by a client doubling the number of devices connected
to the network. Which of the following would best aid in decreasing the workload
without increasing staff?
A. SIEM
B. XDR
, C. SOAR
D. EDR Ans✓✓✓ C. SOAR
A recent vulnerability scan resulted in an abnormally large number of critical and
high findings that
require patching. The SLA requires that the findings be remediated within a
specific amount of time.
Which of the following is the best approach to ensure all vulnerabilities are
patched in accordance with
the SLA?
• A. Integrate an IT service delivery ticketing system to track remediation and
closure
• B. Create a compensating control item until the system can be fully patched
• C. Accept the risk and decommission current assets as end of life
• D. Request an exception and manually patch each system Ans✓✓✓ A. Integrate
an IT service delivery ticketing system to track remediation and closure
A security analyst at a company called ACME Commercial notices there is
outbound traffic to a host IP that resolves to https://office365password.acme.co.
The site's standard VPN logon page is www.acme.com/logon. Which of the
following is most likely true?
A. This is a normal password change URL.
B. The security operations center is performing a routine password audit.
A company is concerned with finding sensitive file storage locations that are open
to the public. The
current internal cloud network is flat. Which of the following is the best solution
to secure the network?
• A. Implement segmentation with ACLs.
• B. Configure logging and monitoring to the SIEM.
• C. Deploy MFA to cloud storage locations.
• D. Roll out an IDS. Ans✓✓✓ A. Implement segmentation with ACLs.
A company is in the process of implementing a vulnerability management
program. Which of the
following scanning methods should be implemented to minimize the risk of
OT/ICS devices
malfunctioning due to the vulnerability identification process?
A. Non-credentialed scanning
B. Passive scanning
C. Agent-based scanning
D. Credentialed scanning Ans✓✓✓ B. Passive scanning
A company receives a penetration test report summary from a third party. The
report summary indicates
a proxy has some patches that need to be applied. The proxy is sitting in a rack
and is not being used, as
the company has replaced it with a new one. The CVE score of the vulnerability on
the proxy is a 9.8.
,Which of the following best practices should the company follow with this proxy?
• A. Leave the proxy as is.
• B. Decomission the proxy.
• C. Migrate the proxy to the cloud.
• D. Patch the proxy. Ans✓✓✓ B. Decomission the proxy.
A cybersecurity analyst is reviewing SIEM logs and observes consistent requests
originating from an internal host to a blocklisted external server. Which of the
following best describes the activity that is taking place?
A. Data exfiltration
B. Rogue device
C. Scanning
D. Beaconing Ans✓✓✓ D. Beaconing
A managed security service provider is having difficulty retaining talent due to an
increasing workload caused by a client doubling the number of devices connected
to the network. Which of the following would best aid in decreasing the workload
without increasing staff?
A. SIEM
B. XDR
, C. SOAR
D. EDR Ans✓✓✓ C. SOAR
A recent vulnerability scan resulted in an abnormally large number of critical and
high findings that
require patching. The SLA requires that the findings be remediated within a
specific amount of time.
Which of the following is the best approach to ensure all vulnerabilities are
patched in accordance with
the SLA?
• A. Integrate an IT service delivery ticketing system to track remediation and
closure
• B. Create a compensating control item until the system can be fully patched
• C. Accept the risk and decommission current assets as end of life
• D. Request an exception and manually patch each system Ans✓✓✓ A. Integrate
an IT service delivery ticketing system to track remediation and closure
A security analyst at a company called ACME Commercial notices there is
outbound traffic to a host IP that resolves to https://office365password.acme.co.
The site's standard VPN logon page is www.acme.com/logon. Which of the
following is most likely true?
A. This is a normal password change URL.
B. The security operations center is performing a routine password audit.