CYSA TEST BANK QUESTIONS WITH
VERIFIED ANSWERS FULL REVIEW
●● The requirement to support mobile devices, an access from home
office space devices has increased recently. The corporate security team
will implement a policy based endpoint security management system to
protect the net work and Company resources. The team needs to audit
external on mobile devices that require network access to develop the
policy which elements are typically required for an endpoint security
management policy select three.
Answer: Anti-malware support
Operating system version
VPN support
●● A company manufactures components used in aviation applications
to protect its supply chain from counterfeit products. The company plans
to install IOT tracking devices on sensitive cargo while it is transported
from suppliers the company must ensure that the devices can store
encryption keys securely. What should the company deploy to meet
these requirements
Answer: TPM
●● A cyber consultant determines that sensitive information relating to
company employees has been inappropriately released. The
recommendation is made that access to this information should be
,limited to senior management and personnel in the human resources
department what type of access control should the company implement?
Answer: Role based
●● Hey security consultant determines that recent instances of data
exfiltration occurred when employees access network service from
remote locations a security policy is set into place to limit employees
accessing the net work from outside. The net work access is restricted to
the email server and public facing websites, only which access control is
the security policy applying.
Answer: Location based
●● A company brings in a cyber security consultant to improve network
security. The consultant explains that the way client computers are used
to remotely manage high value servers as a potential risk currently
administrators use client computers to access servers that are deployed
on a VLAN through an internal firewall. What technology should a
consultant recommend to help ensure secure administration
Answer: Jump box
●● A company is setting up a small working group for a product
development project the project will have private resources that should
be accessible from a small set a client hosts. It should be as easy as
possible to add clients to or remove clients from the working group
network. Traffic related to the project should be as isolated as possible
from the network as a whole there should be no access to or from the
Internet by the working group, working group members work in various
,locations in the corporate campus, and should not change offices what
solutions should the security team use
Answer: VLAN
●● Accompanies perimeter network includes a secure Web server, not
server and FTP server and a DNS server. The network is connected to
the Internet by a firewall several remote clients access the internal net
work through the perimeter, net work, remote clients have recently been
the target of a man in the middle attack the company wants to require
remote. Client connections through encrypted VPN connections only
clients need to connect with multiple server types changes to firewall
configurations must be kept to a minimum. What type of VPN should
the company use?
Answer: SSL tunnel VPN
●● A company initiated a series of security architecture reviews after a
series of incidence among the recommendations made was to implement
a syslog server to consolidate syslog messages from the companies,
Linux servers. The company wants to limit logged messages and
warning, error and critical conditions to minimize log server, size, and to
make manual review easier which message severity level values should
be included in the log.
Answer: Four and lower
●● Hey security, Administrator is concerned that sensitive data could be
valuable to sniffing attacks which technology Kenny Administrator used
to mitigate the risk
, Answer: IPsec
●● A company wants to implement an authentication system that
supports authentication using the same user identities across
organizations and security domains. What type of authentication should
the company implement?
Answer: Federation
●● A company is deploying a server that is to be used as a development
server for security applications. Access to the server must be strictly
limited to designated developers. Physical access to the server should be
restricted as well as having no access to the Internet. The server should
be as isolated as possible. What technology should the company employ
Answer: Air gap
●● A hospital plans to deploy a patient management app that will be
used on tablets supplied to doctors and nurses. The hospital security
team needs to ensure that data entered on the tablet is protected while in
transit what solution does not require any special configuration on the
tablet while still meeting this requirement.
Answer: Deploy PKI, and configure the app server to require TLS
●● An organization plans to supply laptops to all sales executives and
has asked a security administrator to provide a list of suggested
specifications. The primary security requirement states that all data at
VERIFIED ANSWERS FULL REVIEW
●● The requirement to support mobile devices, an access from home
office space devices has increased recently. The corporate security team
will implement a policy based endpoint security management system to
protect the net work and Company resources. The team needs to audit
external on mobile devices that require network access to develop the
policy which elements are typically required for an endpoint security
management policy select three.
Answer: Anti-malware support
Operating system version
VPN support
●● A company manufactures components used in aviation applications
to protect its supply chain from counterfeit products. The company plans
to install IOT tracking devices on sensitive cargo while it is transported
from suppliers the company must ensure that the devices can store
encryption keys securely. What should the company deploy to meet
these requirements
Answer: TPM
●● A cyber consultant determines that sensitive information relating to
company employees has been inappropriately released. The
recommendation is made that access to this information should be
,limited to senior management and personnel in the human resources
department what type of access control should the company implement?
Answer: Role based
●● Hey security consultant determines that recent instances of data
exfiltration occurred when employees access network service from
remote locations a security policy is set into place to limit employees
accessing the net work from outside. The net work access is restricted to
the email server and public facing websites, only which access control is
the security policy applying.
Answer: Location based
●● A company brings in a cyber security consultant to improve network
security. The consultant explains that the way client computers are used
to remotely manage high value servers as a potential risk currently
administrators use client computers to access servers that are deployed
on a VLAN through an internal firewall. What technology should a
consultant recommend to help ensure secure administration
Answer: Jump box
●● A company is setting up a small working group for a product
development project the project will have private resources that should
be accessible from a small set a client hosts. It should be as easy as
possible to add clients to or remove clients from the working group
network. Traffic related to the project should be as isolated as possible
from the network as a whole there should be no access to or from the
Internet by the working group, working group members work in various
,locations in the corporate campus, and should not change offices what
solutions should the security team use
Answer: VLAN
●● Accompanies perimeter network includes a secure Web server, not
server and FTP server and a DNS server. The network is connected to
the Internet by a firewall several remote clients access the internal net
work through the perimeter, net work, remote clients have recently been
the target of a man in the middle attack the company wants to require
remote. Client connections through encrypted VPN connections only
clients need to connect with multiple server types changes to firewall
configurations must be kept to a minimum. What type of VPN should
the company use?
Answer: SSL tunnel VPN
●● A company initiated a series of security architecture reviews after a
series of incidence among the recommendations made was to implement
a syslog server to consolidate syslog messages from the companies,
Linux servers. The company wants to limit logged messages and
warning, error and critical conditions to minimize log server, size, and to
make manual review easier which message severity level values should
be included in the log.
Answer: Four and lower
●● Hey security, Administrator is concerned that sensitive data could be
valuable to sniffing attacks which technology Kenny Administrator used
to mitigate the risk
, Answer: IPsec
●● A company wants to implement an authentication system that
supports authentication using the same user identities across
organizations and security domains. What type of authentication should
the company implement?
Answer: Federation
●● A company is deploying a server that is to be used as a development
server for security applications. Access to the server must be strictly
limited to designated developers. Physical access to the server should be
restricted as well as having no access to the Internet. The server should
be as isolated as possible. What technology should the company employ
Answer: Air gap
●● A hospital plans to deploy a patient management app that will be
used on tablets supplied to doctors and nurses. The hospital security
team needs to ensure that data entered on the tablet is protected while in
transit what solution does not require any special configuration on the
tablet while still meeting this requirement.
Answer: Deploy PKI, and configure the app server to require TLS
●● An organization plans to supply laptops to all sales executives and
has asked a security administrator to provide a list of suggested
specifications. The primary security requirement states that all data at