Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 18 pages
Exam (elaborations)

CYSA CORRECT STUDYS QUESTIONS AND ANSWERS SURE A.pdf

Document preview thumbnail
Preview 3 out of 18 pages

CYSA CORRECT STUDYS QUESTIONS AND ANSWERS SURE A.pdf

Content preview

CYSA CORRECT STUDYS QUESTIONS AND
ANSWERS SURE A+
✔✔While reviewing a packet capture. a security analyst discovers a recent attack used
specific ports communicating across non-standard ports and exchanged a particular set
of files. In addition, forensics determines the files contain malware and have a specific
callback domain within the files. The MOST appropriate action to take in this situation
would be to implement a change request for an IPS:
A. to block the callback domain and another signature hash to block the files
B. behavioral signature and update the blacklisting on the domain
C. rule to block the non-standard ports and update the blacklisting of the callback
domain
D. signature for the callback domain and update the firewall settings to block the non-
standard ports - ✔✔rule to block the non-standard ports and update the blacklisting of
the callback domain

✔✔During a review of the vulnerability scan results on a server. an information security
analyst notices the following:The MOST appropriate action for the analyst to
recommend to developers is to charge the web server so:
A. It only accepts TLSv1.2
B. It only accepts ciphers suites using AES and SHA
C. It no longer accepts the vulnerable cipher suites
D. SSL/TLS is offloaded to a WAF and load balancer - ✔✔It no longer accepts the
vulnerable cipher suites

✔✔As part of a merger with another organization, a Chief Information Security Manager
(CISO) is working with an assessor to perform a risk assessment focused on data
privacy compliance. The CISO is primarily concerned with the potential legal liability and
fines associated with data privacy. Based on the CISO's concerns, the assessor will
MOST likely focus on:
A. qualitative probabilities
B. quantitative probabilities
C. qualitative magnitude

,D. quantitative magnitude - ✔✔quantitative magnitude

✔✔concerned developers have too much visibility into customer data. Which of the
following controls should be implemented to BEST address these concerns?
A. Data masking
B. Data loss prevention
C. Data minimization
D. Data sovereignty - ✔✔Data masking

✔✔Which of the following will allow different cloud instances to share various types of
data with a minimal amount of complexity?
A. Reverse engineering
B. Application log collections
C. Workflow or orchestration
D. API integration
E. Scripting - ✔✔API integration

✔✔A security analyst is investigating an incident that appears that appears to have
started with SQL injection against a publicly available web application. Which of the
following is the FIRST step the analyst should take to prevent future attacks?
A. Modify the IDS rules to have a signature for SQL injection.
B. Take the server offline to prevent continue SQL injection.
C. Create a WAF rule in block mode for SQL injection.
D. Ask the developers to implement parameterized SQL queries. - ✔✔Ask the
developers to implement parameterized SQL queries.

✔✔A security analyst receives an alert that highly sensitive information has left the
company's network. Upon investigation, the analyst discovers an outside IP range has
had connections from three servers more than 100 times in the past month. The
affected servers are virtual machines. Which of the following is the BEST course of
action?
A. Shut down the servers as soon as possible, move them to a clean environment,
restart, run a vulnerability scanner to find weaknesses, determine the root cause,
remediate, and report.
B. Report the data exfiltration to management, take the affected servers offline, conduct
an antivirus scan, remediate all threats found, and return the servers to service.
C. Disconnect the affected servers from the network, use the virtual machine console to
access the systems, determine which information has left the network, find the security
weakness, and remediate.
D. Determine if any other serve - ✔✔Shut down the servers as soon as possible, move
them to a clean environment, restart, run a vulnerability scanner to find weaknesses,
determine the root cause, remediate, and report.

✔✔A critical server was compromised by malware, and all functionality was lost.
Backups of the server were taken; however, management believes a logic bomb may

, have been injected by a rootkit. Which of the following should a security analyst perform
to restore functionality quickly?
A. Work backward, restoring each backup until the server is clean.
B. Restore the previous backup and scan with a live boot anti-malware scanner.
C. Stand up a new server and restore critical data from backups.
D. Offload the critical data to a new server and continue operations. - ✔✔Stand up a
new server and restore critical data from backups.

✔✔The Chief Executive Officer (CEO) of a large insurance company has reported
phishing emails that contain malicious links are targeting the entire organization. Which
of the following actions would work BEST to prevent against this type of attack?
A. Turn on full behavioral analysis to avert an infection.
B. Implement an EDR mail module that will rewrite and analyze email links.
C. Reconfigure the EDR solution to perform real-time scanning of all files.
D. Ensure EDR signatures are updated every day to avert infection.
E. Modify the EDR solution to use heuristic analysis techniques for malware. -
✔✔Implement an EDR mail module that will rewrite and analyze email links.

✔✔The Chief Information Officer (CIO) of a large healthcare institution is concerned
about all machines having direct access to sensitive patient information. Which of the
following should the security analyst implement to BEST mitigate the risk of sensitive
data exposure?
A. A cloud access service broker system
B. NAC to ensure minimum standards are met
C. MFA on all workstations
D. Network segmentation - ✔✔Network segmentation

✔✔Which of the following MOST accurately describes an HSM?
A. An HSM is a low-cost solution for encryption.
B. An HSM can be networked based or a removable USB.
C. An HSM is slower at encrypting than software.
D. An HSM is explicitly used for MFA. - ✔✔An HSM can be networked based or a
removable USB.

✔✔As a proactive threat-hunting technique, hunters must develop situational cases
based on likely attack scenarios derived from the available threat intelligence
information. After forming the basis of the scenario, which of the following may the
threat hunter construct to establish a framework for threat assessment?
A. Critical assert list
B. Threat vector
C. Attack profile
D. Hypothesis - ✔✔Hypothesis

✔✔A security analyst is investigating malicious traffic from an internal system that
attempted to download proxy avoidance software as identified from the firewall logs, but

Document information

Uploaded on
July 10, 2026
Number of pages
18
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$16.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
EXAMCAFE
3.4
(19)
Sold
154
Followers
7
Items
26055
Last sold
8 hours ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions