Cysa Review Activities Exam Questions and
Answers with Verified Solutions | Latest
Updated 2026
Describe one advantage and one This sets an extremely high delay between
disadvantage of using the -T0 probes,
switch which may help to evade detection
when performing an Nmap scan. systems but will
take a very long time to return results.
What is the principal challenge in UDP does not send ACK messages so the
scanning UDP ports? scan
must use timeouts to interpret the port
state. This
makes scanning a wide range of UDP
ports a
lengthy process.
True or false? A port that is False. A closed port responds to probes
reported with an
as "closed" by Nmap is likely to be RST because there is no service available
one protected by a firewall. to
process the request. This means that the
port is
accessible through the firewall. A port
blocked by
a firewall is in the "filtered" state.
,4.What is the function of the -A Performs service detection (verify that the
switch in Nmap? packets
delivered over a port correspond to the
"well
known" protocol associated with that port)
and
version detection (using the scripts marked
"default").
How do you run a specific Nmap Use the --script argument with the script
script or category of scripts? name or
path or category name.
What is the advantage of the grep is a Linux command for running a
Nmap regular
"grepable" output format? expression to search for a particular string.
Nmap's
grepable output is easier for this tool to
parse.
,2A bespoke application used by This is a technical control as it is
your implemented in
company has been the target of software. In functional terms, it acts as a
malware. The developers have detective
created signatures for the control because it does not stop malware
application's binaries, and these from
have replacing the original file image
been added to endpoint detection (preventative
and response (EDR) scanning control) or restore the original file
software running on each automatically
workstation. If a scan shows that a (corrective control).
binary image no longer matches
its
signature, an administrative alert is
generated. What type of security
control is this?
Your company is interested in You should consider the confidentiality
implementing routine backups of component. The backups contain the
all same
customer databases. This will help privileged information as the live copy and
uphold availability because you so must
will be protected by confidentiality controls.
be able to quickly and easily Access
restore controls can be used to ensure that only
the backed-up copy, and it will authorized backup operators have access
also to the
help uphold integrity in case data. Encryption can be used as an
someone tampers with the additional layer
database. of protection.
What controls can you implement
to
round out your risk mitigation
strategy and uphold the
components
of the CIA triad?
, Your chief information security Yes, it is a valid concern. The
officer (CISO) wants to develop a requirements (or
new collection and analysis planning and direction) phase of the
platform intelligence
that will enable the security team cycle can be used to evaluate data
to sources and
extract actionable data from its develop goals and objectives for producing
assets. The CISO would like your actionable intelligence to support use
input as far as which data sources cases
to demanded by intelligence consumers. You
draw from as part of the new can also
collection platform, worrying that mention that the feedback phase of the
collecting from too many sources, cycle
or provides the opportunity to review sources
not enough, could impede the and
company's ability to analyze determine whether they are delivering
information. Is this a valid concern, valuable
and how can it be addressed intelligence.
within
an intelligence life-cycle model?
What are the characteristics to use Firstly, you can distinguish sources as
to either
evaluate threat data and proprietary/closed-source,
intelligence public/open-source, or
sources? community-based, such as an ISAC.
Within those
categories, data feeds can be assessed for
timeliness, relevancy, and accuracy. It is
also
important for analyst opinions and threat
data
points to be tagged with a confidence
level.
Answers with Verified Solutions | Latest
Updated 2026
Describe one advantage and one This sets an extremely high delay between
disadvantage of using the -T0 probes,
switch which may help to evade detection
when performing an Nmap scan. systems but will
take a very long time to return results.
What is the principal challenge in UDP does not send ACK messages so the
scanning UDP ports? scan
must use timeouts to interpret the port
state. This
makes scanning a wide range of UDP
ports a
lengthy process.
True or false? A port that is False. A closed port responds to probes
reported with an
as "closed" by Nmap is likely to be RST because there is no service available
one protected by a firewall. to
process the request. This means that the
port is
accessible through the firewall. A port
blocked by
a firewall is in the "filtered" state.
,4.What is the function of the -A Performs service detection (verify that the
switch in Nmap? packets
delivered over a port correspond to the
"well
known" protocol associated with that port)
and
version detection (using the scripts marked
"default").
How do you run a specific Nmap Use the --script argument with the script
script or category of scripts? name or
path or category name.
What is the advantage of the grep is a Linux command for running a
Nmap regular
"grepable" output format? expression to search for a particular string.
Nmap's
grepable output is easier for this tool to
parse.
,2A bespoke application used by This is a technical control as it is
your implemented in
company has been the target of software. In functional terms, it acts as a
malware. The developers have detective
created signatures for the control because it does not stop malware
application's binaries, and these from
have replacing the original file image
been added to endpoint detection (preventative
and response (EDR) scanning control) or restore the original file
software running on each automatically
workstation. If a scan shows that a (corrective control).
binary image no longer matches
its
signature, an administrative alert is
generated. What type of security
control is this?
Your company is interested in You should consider the confidentiality
implementing routine backups of component. The backups contain the
all same
customer databases. This will help privileged information as the live copy and
uphold availability because you so must
will be protected by confidentiality controls.
be able to quickly and easily Access
restore controls can be used to ensure that only
the backed-up copy, and it will authorized backup operators have access
also to the
help uphold integrity in case data. Encryption can be used as an
someone tampers with the additional layer
database. of protection.
What controls can you implement
to
round out your risk mitigation
strategy and uphold the
components
of the CIA triad?
, Your chief information security Yes, it is a valid concern. The
officer (CISO) wants to develop a requirements (or
new collection and analysis planning and direction) phase of the
platform intelligence
that will enable the security team cycle can be used to evaluate data
to sources and
extract actionable data from its develop goals and objectives for producing
assets. The CISO would like your actionable intelligence to support use
input as far as which data sources cases
to demanded by intelligence consumers. You
draw from as part of the new can also
collection platform, worrying that mention that the feedback phase of the
collecting from too many sources, cycle
or provides the opportunity to review sources
not enough, could impede the and
company's ability to analyze determine whether they are delivering
information. Is this a valid concern, valuable
and how can it be addressed intelligence.
within
an intelligence life-cycle model?
What are the characteristics to use Firstly, you can distinguish sources as
to either
evaluate threat data and proprietary/closed-source,
intelligence public/open-source, or
sources? community-based, such as an ISAC.
Within those
categories, data feeds can be assessed for
timeliness, relevancy, and accuracy. It is
also
important for analyst opinions and threat
data
points to be tagged with a confidence
level.