Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 16 pages
Exam (elaborations)

CYSA EVALUATION TEST 2026 QUESTIONS AND ANSWERS SURE A.pdf

Document preview thumbnail
Preview 3 out of 16 pages

CYSA EVALUATION TEST 2026 QUESTIONS AND ANSWERS SURE A.pdf

Content preview

CYSA EVALUATION TEST 2026 QUESTIONS AND
ANSWERS SURE A+
✔✔Allan is developing a document that lists the acceptable mechanisms for securely
obtaining remote administrative access to servers in his organization. What type of
document is Allan writing? - ✔✔standard

✔✔______________ describe specific security controls that must be in place for an
organization. - ✔✔Standards

✔✔Which one of the following is not a common use of the NIST Cybersecurity
Framework? - ✔✔create specific technology requirements for an organization

✔✔The ______________ is designed to help organizations describe their current
cybersecurity posture, describe their target state for cybersecurity, identify and prioritize
opportunities for improvement, assess progress, and communicate with stakeholders
about risk. - ✔✔NIST Cybersecurity Framework

✔✔Shelly is writing a document that describes the steps that incident response teams
will follow upon first notice of a potential incident. What type of document is she
creating? - ✔✔procedure

✔✔______________ provide checklist-style sets of step-by-step instructions guiding
how employees should react in a given circumstance and commonly guide the early
stages of incident response. - ✔✔Procedures

✔✔Sue is a manager of a group of system administrators and is in charge of approving
all requests for administrative rights. In her role, she files a change request to grant a
staff member administrative rights and then approves it. What personnel control would
best help to prevent this abuse of her role? - ✔✔separation of duties

,✔✔Ben wants to ensure that a single person cannot independently access his
organization's secure vault. What personnel control is best suite to this need? - ✔✔dual
control

✔✔Lauren's departure from her organization leaves her team without a Linux systems
administrator and means they no longer have in-depth knowledge of a critical business
system. What should her manager have done to ensure that this issue did not have a
significant impact? - ✔✔succession planning

✔✔Rick is reviewing his organization's network design and is concerned that a known
flaw in the border router could let an attacker disable their Internet connectivity. Which
of the following is an appropriate compensatory control? - ✔✔an alternate Internet
connectivity method using a different router type

✔✔Fred has been assigned to review his organization's host security policies due to a
recent theft of a workstation that contained sensitive data. Which of the following
controls would best help to prevent a stolen machine from causing a data breach? -
✔✔full disk encryption

✔✔_________________ is useful for reporting machine state and might even help
locate a machine if it was reconnect to a network, but it does not protect the data a
machine contains. - ✔✔Central management

✔✔Full disk encryption protects sensitive data on a workstation in the event of theft
occurring. _________________ would provide helpful additional capabilities, but both
rely on the system connecting to a network after it is stolen. - ✔✔remote wipe
capabilities and machine tracking software

✔✔A member of Susan's team recently fell for a phishing scam and provided his
password and personal information to a scammer. What layered security approach is
not an appropriate layer for Susan to implement to protect her organization from future
issues? - ✔✔multi-tiered firewalls

✔✔In the event a scammer acquired passwords and personal information,
_________________ would require the attacker to have the second factor in addition to
the password. - ✔✔multifactor authentication

✔✔Chris is in charge of his organization's Windows security standard, including their
Windows XP security standard, and has recently decommissioned the organization's
last Windows XP system. What is the next step in his security standard's life cycle? -
✔✔retiring the Windows XP standard

, ✔✔Retirement is the last step at the end of the life cycle for a standard or process. This
means that if the process is retired, a _________________ is not needed. - ✔✔final
update

✔✔Example Corporation has split their network into network zones that include sales,
HR, research and development, and guest networks, each separated from the others
using network security devices. What concept is Example Corporation using for their
security network? - ✔✔segmentation

✔✔Zoned routing is a _________________. - ✔✔made up term

✔✔Which of the following layered security controls is commonly used at the WAN, LAN,
and host layer in a security design? - ✔✔firewalls

✔✔_________________ are commonly used to create network protection zones, to
protect network borders, and at the host level to help armor the host against attacks. -
✔✔Firewalls

✔✔_________________ at rest is most frequently used at the host layer. -
✔✔Encryption

✔✔_________________ are typically used at the edge of a network for publicly
accessible services. - ✔✔DMZs

✔✔In Lauren's initial design for a secure network, she applied the same security
controls to every system and network. After reviewing her design, she decided to isolate
systems based on their functions and to apply controls to protected network segments
for more sensitive data and systems. What two design models did she apply? -
✔✔uniform protection and protected enclaves

✔✔An _________________ design would have applied protections based on
information classification or control requirements. - ✔✔information-based

✔✔Michelle has been asked to review her corporate network's design for single points
of failure that would impact the core network operations. This is a redundant network
design with a critical fault: a single point of failure that could take the network offline if it
failed. What could be the single point of failure? - ✔✔the internet access connected
directly to the ISP

✔✔During a penetration test of Anna's company, the penetration testers were able to
compromise the company's web servers and deleted their log files, preventing analysis
of their attacks. What compensating control is best suited to prevent this issue in the
future? - ✔✔sending logs to a syslog server or bastion host

Document information

Uploaded on
July 10, 2026
Number of pages
16
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$16.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
EXAMCAFE
3.4
(19)
Sold
154
Followers
7
Items
26055
Last sold
8 hours ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions