Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 25 pages
Exam (elaborations)

CSX CYBERSECURITY FUNDAMENTALS: COMPREHENSIVE VERIFIED PRACTICE QUESTIONS AND CORRECT ANSWERS FOR GRADE A+

Document preview thumbnail
Preview 3 out of 25 pages

CSX CYBERSECURITY FUNDAMENTALS: COMPREHENSIVE VERIFIED PRACTICE QUESTIONS AND CORRECT ANSWERS FOR GRADE A+ CSX CYBERSECURITY FUNDAMENTALS: COMPREHENSIVE VERIFIED PRACTICE QUESTIONS AND CORRECT ANSWERS FOR GRADE A+ CSX CYBERSECURITY FUNDAMENTALS: COMPREHENSIVE VERIFIED PRACTICE QUESTIONS AND CORRECT ANSWERS FOR GRADE A+ CSX CYBERSECURITY FUNDAMENTALS: COMPREHENSIVE VERIFIED PRACTICE QUESTIONS AND CORRECT ANSWERS FOR GRADE A+

Content preview

CSX CYBERSECURITY FUNDAMENTALS


CSX CYBERSECURITY
FUNDAMENTALS:
COMPREHENSIVE VERIFIED
PRACTICE QUESTIONS AND
CORRECT ANSWERS FOR
GRADE A+

According to the NIST framework, which of the following are considered key functions
necessary for the protection of digital assets?

Protecting information assets by addressing threats to information that is processed,
stored or transported by interworked information systems - VERIFIED ANSWERS-The
best definition for cybersecurity?

Cybersecurity management - VERIFIED ANSWERS-Cybersecurity role that is charged
with the duty of managing incidents and remediation?

risk to an organization's digital assets. - VERIFIED ANSWERS-The core duty of
cybersecurity is to identify, respond and manage

is anything capable of acting against an asset in a manner that can cause harm. -
VERIFIED ANSWERS-A threat

is something of value worth protecting. - VERIFIED ANSWERS-A asset

is a weakness in the design, implementation, operation or internal controls in a process
that could be exploited to violate the system security - VERIFIED ANSWERS-A
vulnerability

attack vector - VERIFIED ANSWERS-The path or route used to gain access to the
target asset is known as a

payload - VERIFIED ANSWERS-In an attack, the container that delivers the exploit to
the target is called

communicate required and prohibited activities and behaviors. - VERIFIED ANSWERS-
Policies



1|Page

,CSX CYBERSECURITY FUNDAMENTALS

is a class of malware that hides the existence of other malware by modifying the
underlying operating system. - VERIFIED ANSWERS-Rootkit

provide details on how to comply with policies and standards. - VERIFIED ANSWERS-
Procedures

contain step-by-step instructions to carry out procedures. - VERIFIED ANSWERS-
Guidelines

also called malicious code, is software designed to gain access to targeted computer
systems, steal information or disrupt computer operations. - VERIFIED ANSWERS-
Malware

are used to interpret policies in specific situations. - VERIFIED ANSWERS-Standards

are solutions to software programming and coding errors. - VERIFIED ANSWERS-
Patches

includes many components such as directory services, authentication and authorization
services, and user management capabilities such as provisioning and deprovisioning. -
VERIFIED ANSWERS-Identity Management

Detect and block traffic from infected internal end points, Eliminate threats such as
email spam, viruses and worms, Control user traffic bound toward the Internet, Monitor
and detect network ports for rogue activity. - VERIFIED ANSWERS-The Internet
perimeter should

ensures that data are transferred reliably in the correct sequence - VERIFIED
ANSWERS-Transport layer of the OSI

coordinates and manages user connections - VERIFIED ANSWERS-Session layer of
the OSI

Encryption is an essential but incomplete form of access control - VERIFIED
ANSWERS-best states the role of encryption within an overall cybersecurity program

Asset value, criticality, reliability of each control and degree of exposure. - VERIFIED
ANSWERS-The number and types of layers needed for defense in depth are a function
of

Least privilege or access control - VERIFIED ANSWERS-System hardening should
implement the principle of

Accounting management, Fault management, Performance management, Security
management - VERIFIED ANSWERS-Which of the following are considered functional
areas of network management as defined by ISO?

2|Page

, CSX CYBERSECURITY FUNDAMENTALS


Multiple guests coexisting on the same server in isolation of one another - VERIFIED
ANSWERS-Virtualization involves

Maintaining an asset inventory. - VERIFIED ANSWERS-Vulnerability management
begins with an understanding of cybersecurity assets and their locations, which can be
accomplished by

Preparation, Detection and analysis, Investigation, Mitigation and recovery, Postincident
analysis - VERIFIED ANSWERS-Arrange the steps of the incident response process
into the correct order

Containment - VERIFIED ANSWERS-Which element of an incident response plan
involves obtaining and preserving evidence

Who had access to the evidence, in chronological order, Proof that the analysis is
based on copies identical to the original evidence, The procedures followed in working
with the evidence - VERIFIED ANSWERS-Select three. The chain of custody contains
information regarding

"violation or imminent threat of violation of computer security policies, acceptable use
policies, or standard security practices." - VERIFIED ANSWERS-NIST defines a Threat
as a

The estimated probability of the identified threats actually occurring, The efficiency and
effectiveness of existing risk mitigation controls, A list of potential vulnerabilities,
dangers and/or threats. - VERIFIED ANSWERS-Select all that apply. A business impact
analysis (BIA) should identify

is defined as "a model for enabling convenient, on-demand network access to a shared
pool of configurable resources (e.g., networks, servers, storage, applications and
services) that can be rapidly provisioned and released with minimal management or
service provider interaction - VERIFIED ANSWERS-Cloud computing

APTs typically originate from sources such as organized crime groups, activists or
governments, APTs use obfuscation techniques that help them remain undiscovered for
months or even years, APTs are often long-term, multi-phase projects with a focus on
reconnaissance - VERIFIED ANSWERS-Select all that apply. Which of the following
statements about advanced persistent threats (APTs) are true?

The reorientation of technologies and services designed around the individual end user.
- VERIFIED ANSWERS-Smart devices, BYOD strategies and freely available
applications and services are all examples of:

- cloud computing
- social media

3|Page

Document information

Uploaded on
February 28, 2026
Number of pages
25
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$15.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
PresleyKhalid
5.0
(2)
Sold
4
Followers
2
Items
137
Last sold
3 months ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions