CYSA Weaknesses Exam Questions and
Answers with Verified Solutions | Latest
Updated 2026
flow for TCP 3-way handshake SYN -> SYN/ACK -> ACK
flow for Nmap Stealth (TCP SYN) SYN -> SYN/ACK -> RST
Scan? The scanner sends a Reset (RST) packet
after
receiving the SYN/ACK to "half open" the
connection and avoid being logged as a
full
session
tcpdump -C [size] limits the capture file to a specific size and
can
stop or rotate the file once reached
tcpdump -s [length] defines the "snaplen" which is the number
of bytes
to capture from each packet. setting it to 0
(-s0)
captures the whole packet
tcpdump -w [file] writes the raw packets to a.pcap file
instead of
printing them to a screen
,what does it mean when you get a firewall "reject".
"closed" response from a firewall it sends a response back to the scanner
which the
nmap interprets as the port being "closed".
the port
is accessible and scanner receives a
response but
no application is currently listening.
therefore its a
'reject' and sends a TCP RST packet back
what does it mean when you get a Drop (or Deny).
"filtered" response from a firewall The firewall silently discards the packet
because
nmap receives no response at all. it labels
the port
as "filtered". this happens when a firewall
uses
"drop" or "deny" action. scanner cant
determine if
the port is open or closed
linux command: file identifies the file type, encoding, and
whether a
binary is statistically or dynamically linked
linux command: ls -la lists the directory contents, permissions,
owners,
and file sizes. cannot tell you if a binary
has been
modified to use different libraries
, sysmon system monitor. background service that
logs
detailed system activity to the Windows
Event Log
for long-term analysis
resmon resource monitor. a GUI tool for "LIVE"
troubleshooting of CPU, memory, disk, and
network performance
linux system files: /etc/shadow stores the actual hashed passwords for
user
accounts. highly restricted to the root user
linux system files: /var/log/syslog the general purpose log file for
system-wide
events and non-critical messages
linux system files: ~/.bash_history stores the command history for specific
user
currently logged in
media sanitization: clear uses software to overwrite
user-addressable
storage locations; data may still be
recoverable
with special equipment
Answers with Verified Solutions | Latest
Updated 2026
flow for TCP 3-way handshake SYN -> SYN/ACK -> ACK
flow for Nmap Stealth (TCP SYN) SYN -> SYN/ACK -> RST
Scan? The scanner sends a Reset (RST) packet
after
receiving the SYN/ACK to "half open" the
connection and avoid being logged as a
full
session
tcpdump -C [size] limits the capture file to a specific size and
can
stop or rotate the file once reached
tcpdump -s [length] defines the "snaplen" which is the number
of bytes
to capture from each packet. setting it to 0
(-s0)
captures the whole packet
tcpdump -w [file] writes the raw packets to a.pcap file
instead of
printing them to a screen
,what does it mean when you get a firewall "reject".
"closed" response from a firewall it sends a response back to the scanner
which the
nmap interprets as the port being "closed".
the port
is accessible and scanner receives a
response but
no application is currently listening.
therefore its a
'reject' and sends a TCP RST packet back
what does it mean when you get a Drop (or Deny).
"filtered" response from a firewall The firewall silently discards the packet
because
nmap receives no response at all. it labels
the port
as "filtered". this happens when a firewall
uses
"drop" or "deny" action. scanner cant
determine if
the port is open or closed
linux command: file identifies the file type, encoding, and
whether a
binary is statistically or dynamically linked
linux command: ls -la lists the directory contents, permissions,
owners,
and file sizes. cannot tell you if a binary
has been
modified to use different libraries
, sysmon system monitor. background service that
logs
detailed system activity to the Windows
Event Log
for long-term analysis
resmon resource monitor. a GUI tool for "LIVE"
troubleshooting of CPU, memory, disk, and
network performance
linux system files: /etc/shadow stores the actual hashed passwords for
user
accounts. highly restricted to the root user
linux system files: /var/log/syslog the general purpose log file for
system-wide
events and non-critical messages
linux system files: ~/.bash_history stores the command history for specific
user
currently logged in
media sanitization: clear uses software to overwrite
user-addressable
storage locations; data may still be
recoverable
with special equipment