Cysa Test 1 Certmaster Practice Exam
Questions and Answers with Verified
Solutions | Latest Updated 2026
A security administrator has To determine the sequence of events that
identified suspicious activity on the occurred
network and believes a security during the incident
incident occurred. The
administrator
needs to create a timeline of
events
to help determine the scope of the
incident and take appropriate
actions. Why is creating a timeline
important in this scenario?
To identify potential threats and
incidents
To determine the sequence of
events
that occurred during the incident
To create an executive summary
of
the incident
To assess the potential impacts of
the incident
,A security administrator creates an Stakeholder identification and
incident response plan for the communication
organization. What are some Timeline
common components of incident Incident declaration and escalation
response planning that the
security
administrator should include in
their
plan? (Select the three best
options.)
Stakeholder identification and
communication
Timeline
Executive summary
Incident declaration and escalation
,A security analyst has discovered Educate end-users on safe browsing and
a email
workstation infected with malware practices
that has spread to other systems
on
the network. The analyst has
determined that they cannot easily
remove the malware cannot and
that
re-imaging the workstation is
necessary. However, the
workstation
has important data that the analyst
has not backed up. After
re-imaging
the infected workstation, what is
the
best practice to prevent future
malware infections?
Install anti-virus software on all
workstations
Implement a security policy that
prohibits downloading
unauthorized
software
Disable USB ports on all
workstations
Educate end-users on safe
browsing
and email practices
, A company's security team wants Webhooks
to
receive real-time alerts from its
Intrusion Detection System (IDS)
whenever a potential threat is
detected. Which solution should
the
team consider to achieve this
goal?
Application programming interface
(API)
Security orchestration, automation
and response (SOAR)
Plugins
Webhooks
Questions and Answers with Verified
Solutions | Latest Updated 2026
A security administrator has To determine the sequence of events that
identified suspicious activity on the occurred
network and believes a security during the incident
incident occurred. The
administrator
needs to create a timeline of
events
to help determine the scope of the
incident and take appropriate
actions. Why is creating a timeline
important in this scenario?
To identify potential threats and
incidents
To determine the sequence of
events
that occurred during the incident
To create an executive summary
of
the incident
To assess the potential impacts of
the incident
,A security administrator creates an Stakeholder identification and
incident response plan for the communication
organization. What are some Timeline
common components of incident Incident declaration and escalation
response planning that the
security
administrator should include in
their
plan? (Select the three best
options.)
Stakeholder identification and
communication
Timeline
Executive summary
Incident declaration and escalation
,A security analyst has discovered Educate end-users on safe browsing and
a email
workstation infected with malware practices
that has spread to other systems
on
the network. The analyst has
determined that they cannot easily
remove the malware cannot and
that
re-imaging the workstation is
necessary. However, the
workstation
has important data that the analyst
has not backed up. After
re-imaging
the infected workstation, what is
the
best practice to prevent future
malware infections?
Install anti-virus software on all
workstations
Implement a security policy that
prohibits downloading
unauthorized
software
Disable USB ports on all
workstations
Educate end-users on safe
browsing
and email practices
, A company's security team wants Webhooks
to
receive real-time alerts from its
Intrusion Detection System (IDS)
whenever a potential threat is
detected. Which solution should
the
team consider to achieve this
goal?
Application programming interface
(API)
Security orchestration, automation
and response (SOAR)
Plugins
Webhooks