Cysa Review Exam Questions and Answers
with Verified Solutions | Latest Updated 2026
Theft from a database - which SQL Injection. SQLi payload executes ON
attack the
is the DIRECT threat? database. XSS payload executes in the
browser
(indirect).
Which VPN protocol won't trigger a IPsec. SSL v2, SSL v3, and PPTP are all
vulnerability scan alert? deprecated/broken and will be flagged.
PCI-flagged vulnerability on a Remediate and get a clean scan BEFORE
system NOT yet in production - going
what must you do? live. No exceptions.
How do you prioritize a No action / accept the risk. CVSS +
vulnerability context
with low CVSS + no exploitability + determines priority, not score alone.
internal-only exposure?
CVSS alone doesn't determine Exploitability, exposure (internet vs
action. What other factors matter? internal), asset
value, compensating controls, and
compliance
requirements.
,Always check the status/resolution Fixed = already remediated. Don't react to
column before deciding action on the
a presence of vulnerabilities - check if
vuln scan. Why? they're
already resolved.
Scanner runs fine but misses Outdated vulnerability feed/signatures.
known Check if the
vulnerabilities other scanners maintenance subscription is current.
catch.
Most likely cause?
External scan shows some Network IPS. Firewalls block all-or-nothing
requests by
in logs but attack payloads are IP/port. IPS inspects content and
missing. Firewall or IPS? selectively drops
malicious payloads while allowing normal
traffic.
Multiple different ports hit from the Port scan. Key indicator: breadth across
same source within seconds - many ports
what in short time. DoS = high volume to one
is it? target.
Failed connection = repeated attempts to
one port.
What's the difference between Clearing = data unrecoverable by normal
clearing and purging? means
(reformat, overwrite). Purging = data
unrecoverable
even with forensic techniques
(cryptographic
erase, degaussing).
, Remote scan finds nothing but A firewall is filtering traffic between the
local remote
scan finds vulnerabilities on the scanner and the server. The vulnerabilities
same exist but
server. Why? the remote scanner can't reach the ports.
Sending forensic evidence to an Integrity (hash the image) and
external party - what two things confidentiality
must you protect? (encrypt the image). Send encryption key
and hash
under separate cover (different channel).
How do you ensure no changes Use a write blocker. It allows reads but
are blocks all
made to a drive during forensic write commands at the hardware level.
analysis? Forensic
software alone isn't enough.
How do you identify a chain of Look for "Released by / Received by" with
custody form? signatures and dates. Tracks WHO
handled
evidence, WHEN, and WHERE at every
transfer
point.
How do you safely observe Isolate on a separate switch, use a span
malware port or tap
network behavior on an infected to passively capture traffic with
system? Wireshark/tcpdump. Never reconnect to
production network.
with Verified Solutions | Latest Updated 2026
Theft from a database - which SQL Injection. SQLi payload executes ON
attack the
is the DIRECT threat? database. XSS payload executes in the
browser
(indirect).
Which VPN protocol won't trigger a IPsec. SSL v2, SSL v3, and PPTP are all
vulnerability scan alert? deprecated/broken and will be flagged.
PCI-flagged vulnerability on a Remediate and get a clean scan BEFORE
system NOT yet in production - going
what must you do? live. No exceptions.
How do you prioritize a No action / accept the risk. CVSS +
vulnerability context
with low CVSS + no exploitability + determines priority, not score alone.
internal-only exposure?
CVSS alone doesn't determine Exploitability, exposure (internet vs
action. What other factors matter? internal), asset
value, compensating controls, and
compliance
requirements.
,Always check the status/resolution Fixed = already remediated. Don't react to
column before deciding action on the
a presence of vulnerabilities - check if
vuln scan. Why? they're
already resolved.
Scanner runs fine but misses Outdated vulnerability feed/signatures.
known Check if the
vulnerabilities other scanners maintenance subscription is current.
catch.
Most likely cause?
External scan shows some Network IPS. Firewalls block all-or-nothing
requests by
in logs but attack payloads are IP/port. IPS inspects content and
missing. Firewall or IPS? selectively drops
malicious payloads while allowing normal
traffic.
Multiple different ports hit from the Port scan. Key indicator: breadth across
same source within seconds - many ports
what in short time. DoS = high volume to one
is it? target.
Failed connection = repeated attempts to
one port.
What's the difference between Clearing = data unrecoverable by normal
clearing and purging? means
(reformat, overwrite). Purging = data
unrecoverable
even with forensic techniques
(cryptographic
erase, degaussing).
, Remote scan finds nothing but A firewall is filtering traffic between the
local remote
scan finds vulnerabilities on the scanner and the server. The vulnerabilities
same exist but
server. Why? the remote scanner can't reach the ports.
Sending forensic evidence to an Integrity (hash the image) and
external party - what two things confidentiality
must you protect? (encrypt the image). Send encryption key
and hash
under separate cover (different channel).
How do you ensure no changes Use a write blocker. It allows reads but
are blocks all
made to a drive during forensic write commands at the hardware level.
analysis? Forensic
software alone isn't enough.
How do you identify a chain of Look for "Released by / Received by" with
custody form? signatures and dates. Tracks WHO
handled
evidence, WHEN, and WHERE at every
transfer
point.
How do you safely observe Isolate on a separate switch, use a span
malware port or tap
network behavior on an infected to passively capture traffic with
system? Wireshark/tcpdump. Never reconnect to
production network.