CYSA Key Terms Exam Questions and
Answers with Verified Solutions | Latest
Updated 2026
What does repeated failed login Brute force attack or credential stuffing
attempts followed by a success
indicate
What log source is best for Security logs / Active Directory logs
detecting
authentication failures
What indicates DNS tunneling High volume of DNS requests with
long/random
subdomains
What is beaconing traffic Regular interval outbound communication
to a
command-and-control server
What is the FIRST step after Isolate the system from the network
detecting malware on a host
What is the purpose of isolating a Prevent lateral movement and further
host compromise
, When should you preserve Before making major changes to an
evidence infected
system
What tool is best for packet Wireshark
capture
analysis
What tool is best for command-line tcpdump
packet capture
What is the difference between SIEM aggregates logs; EDR monitors
SIEM endpoint
and EDR behavior
What type of traffic indicates data Large outbound transfers or unusual
exfiltration encrypted
traffic
What does a SYN scan look like Multiple SYN packets without completing
handshake
What does lateral movement look Logins from one system to multiple internal
like in logs systems
What is pass-the-hash Using stolen hash to authenticate without
cracking
password
What MITRE tactic is Lateral Movement
pass-the-hash
Answers with Verified Solutions | Latest
Updated 2026
What does repeated failed login Brute force attack or credential stuffing
attempts followed by a success
indicate
What log source is best for Security logs / Active Directory logs
detecting
authentication failures
What indicates DNS tunneling High volume of DNS requests with
long/random
subdomains
What is beaconing traffic Regular interval outbound communication
to a
command-and-control server
What is the FIRST step after Isolate the system from the network
detecting malware on a host
What is the purpose of isolating a Prevent lateral movement and further
host compromise
, When should you preserve Before making major changes to an
evidence infected
system
What tool is best for packet Wireshark
capture
analysis
What tool is best for command-line tcpdump
packet capture
What is the difference between SIEM aggregates logs; EDR monitors
SIEM endpoint
and EDR behavior
What type of traffic indicates data Large outbound transfers or unusual
exfiltration encrypted
traffic
What does a SYN scan look like Multiple SYN packets without completing
handshake
What does lateral movement look Logins from one system to multiple internal
like in logs systems
What is pass-the-hash Using stolen hash to authenticate without
cracking
password
What MITRE tactic is Lateral Movement
pass-the-hash