CYSA Exam Questions and Answers with
Verified Solutions | Latest Updated 2026
An analyst is performing CAN Bus
penetration
testing and vulnerability
assessment
activities against a new vehicle
automation platform. Which of the
following is MOST likely an attack
vector that is being utilized as part
of
the testing and assessment?
A cyber-incident response analyst Start packet capturing to look for traffic that
is could
investigating a suspected be indicative of command and control from
cryptocurrency miner on a the
company's server. Which of the miner.
following is the FIRST step the
analyst should take?
,A security analyst is investigating HKEY_USERS\<user
a SID>\Software\Microsoft\Windows\explorer
malware infection that occurred on \Moun
a tPoints2
Windows system. The system was
not
connected to a network and had
no
wireless capability Company policy
prohibits using portable media or
mobile storage The security
analyst
is trying to determine which use
caused the malware to get onto
the
system Which of the following
registry keys would MOST likely
have
this information?
Which of the following MOST An HSM can be networked based or a
accurately describes an HSM? removable
USB
A security analyst is investigating Shut down the computer
malicious traffic from an internal
system that attempted to
download
proxy avoidance software as
identified from the firewall logs but
the destination IP is blocked and
not
captured. Which of the following
should the analyst do?
, Which of the following Self-encrypting drive
technologies
can be used to house the entropy
keys for disk encryption on
desktops
and laptops?
A developer wrote a script to make Data loss prevention or Data masking
names and other Pll data
unidentifiable before loading a
database export into the testing
system Which of the following
describes the type of control that is
being used
A security analyst receives an alert Shut down the servers as soon as
that highly sensitive information possible, move
has them to a clean environment, restart, run a
left the company's network Upon vulnerability scanner to find weaknesses
investigation, the analyst discovers determine
an outside IP range has had the root cause, remediate, and report
connections from three servers
more
than 100 times m the past month
The
affected servers are virtual
machines
Which of the following is the BEST
course of action?
Verified Solutions | Latest Updated 2026
An analyst is performing CAN Bus
penetration
testing and vulnerability
assessment
activities against a new vehicle
automation platform. Which of the
following is MOST likely an attack
vector that is being utilized as part
of
the testing and assessment?
A cyber-incident response analyst Start packet capturing to look for traffic that
is could
investigating a suspected be indicative of command and control from
cryptocurrency miner on a the
company's server. Which of the miner.
following is the FIRST step the
analyst should take?
,A security analyst is investigating HKEY_USERS\<user
a SID>\Software\Microsoft\Windows\explorer
malware infection that occurred on \Moun
a tPoints2
Windows system. The system was
not
connected to a network and had
no
wireless capability Company policy
prohibits using portable media or
mobile storage The security
analyst
is trying to determine which use
caused the malware to get onto
the
system Which of the following
registry keys would MOST likely
have
this information?
Which of the following MOST An HSM can be networked based or a
accurately describes an HSM? removable
USB
A security analyst is investigating Shut down the computer
malicious traffic from an internal
system that attempted to
download
proxy avoidance software as
identified from the firewall logs but
the destination IP is blocked and
not
captured. Which of the following
should the analyst do?
, Which of the following Self-encrypting drive
technologies
can be used to house the entropy
keys for disk encryption on
desktops
and laptops?
A developer wrote a script to make Data loss prevention or Data masking
names and other Pll data
unidentifiable before loading a
database export into the testing
system Which of the following
describes the type of control that is
being used
A security analyst receives an alert Shut down the servers as soon as
that highly sensitive information possible, move
has them to a clean environment, restart, run a
left the company's network Upon vulnerability scanner to find weaknesses
investigation, the analyst discovers determine
an outside IP range has had the root cause, remediate, and report
connections from three servers
more
than 100 times m the past month
The
affected servers are virtual
machines
Which of the following is the BEST
course of action?