CySA Exam Questions and Answers with
Verified Solutions | Latest Updated 2026
Which one of the following nonrepudiation
objectives is not one of the three
main objectives that information
security professionals must
achieve
to protect their organizations
against
cybersecurity threats?
Tommy is assessing the security vulnerability
database servers in his datacenter
and realizes that one of them is
missing a critical Oracle security
patch. What type of situation has
Tommy detected?
Ben is preparing to conduct a Identify threats
cybersecurity risk assessment for
his
organization. If he chooses to
follow
the standard process proposed by
NIST, which one of the following
steps would come first?
,Cindy is conducting a environmental
cybersecurity
risk assessment and is
considering
the impact that a failure of her
city's
power grid might have on the
organization. What type of threat is
she considering?
Which one of the following adversarial
categories of threat requires that
cybersecurity analysts consider
the
capability, intent and targeting of
the
threat source?
Vincent is responding to a security availability
incident that compromised one of
his
organization's web servers. He
does
not believe that the attackers
modified or stole any information,
but they did disrupt access to the
organization's website. What
cybersecurity objective did this
attack violate?
Which one of the following is an penetration tests
example of an operational security
control?
, Encryption software, network technical
firewalls, and antivirus software
are
all examples of
_________________ security
controls.
Paul recently completed a risk risk mitigation
assessment and determined that
his
network was vulnerable to hackers
connecting to open ports on
servers.
He implemented a network firewall
to reduce the likelihood of a
successful attack. What risk
management strategy did Paul
choose to pursue?
Robert's organization has a BYOD network access control
policy, and he would like to ensure
that devices connected to the
network under this policy have
current antivirus software. What
technology can best assist him
with
this goal?
When performing 802.1x RADIUS
authentication, what protocol does
the authenticator use to
communicate with the
authentication
server?
Verified Solutions | Latest Updated 2026
Which one of the following nonrepudiation
objectives is not one of the three
main objectives that information
security professionals must
achieve
to protect their organizations
against
cybersecurity threats?
Tommy is assessing the security vulnerability
database servers in his datacenter
and realizes that one of them is
missing a critical Oracle security
patch. What type of situation has
Tommy detected?
Ben is preparing to conduct a Identify threats
cybersecurity risk assessment for
his
organization. If he chooses to
follow
the standard process proposed by
NIST, which one of the following
steps would come first?
,Cindy is conducting a environmental
cybersecurity
risk assessment and is
considering
the impact that a failure of her
city's
power grid might have on the
organization. What type of threat is
she considering?
Which one of the following adversarial
categories of threat requires that
cybersecurity analysts consider
the
capability, intent and targeting of
the
threat source?
Vincent is responding to a security availability
incident that compromised one of
his
organization's web servers. He
does
not believe that the attackers
modified or stole any information,
but they did disrupt access to the
organization's website. What
cybersecurity objective did this
attack violate?
Which one of the following is an penetration tests
example of an operational security
control?
, Encryption software, network technical
firewalls, and antivirus software
are
all examples of
_________________ security
controls.
Paul recently completed a risk risk mitigation
assessment and determined that
his
network was vulnerable to hackers
connecting to open ports on
servers.
He implemented a network firewall
to reduce the likelihood of a
successful attack. What risk
management strategy did Paul
choose to pursue?
Robert's organization has a BYOD network access control
policy, and he would like to ensure
that devices connected to the
network under this policy have
current antivirus software. What
technology can best assist him
with
this goal?
When performing 802.1x RADIUS
authentication, what protocol does
the authenticator use to
communicate with the
authentication
server?