My CYSA Study Guide Exam Questions and
Answers with Verified Solutions | Latest
Updated 2026
Operation Aurora used spear-phishing emails
zero-day vulnerability in Internet Explorer
SMBGhost attackers execute arbitrary code on a
vulnerable
system.
Non Zero day
ProcDump a command-line utility whose primary
purpose is
monitoring an application for CPU spikes
and
generating crash dumps during a spike
that an
administrator or developer can use to
determine
the cause of the spike
Process Monitor shows real-time file system, Registry, and
process/thread activity
DiskMon displays all hard disk activity on a
Windows system
,a common attack model of an APT Quietly gathers information from
attack compromised
systems
Exact data match a pattern matching technique that uses a
structured
database of string values to detect
matches.
NOT usually included in a Denial-of-service attacks
penetration test
HEAD / HTTP/1.1 vs 2.0 requests the document header from the
server and
provides information such as the server
software
version and the server’s operating system.
- Easier to read vs 2.0
-HTTP/2 improves performance and
evasion due to
binary framing + multiplexing
1.1 = 80, 23,21,25, 143, 389
2.0 = 443
PUT Upload or overwrite files
Update API resources
*kind of dangerous for remote code
execution
Guideline Policy = what/why (management intent)
Policy Standards = mandatory specifics
Standard Procedures = how (step■by■step)
Procedure Guidelines = recommended practices
, Secure attribute cookies Secures cookies to where they can only be
transferred over HTTPS
- Prevents MITM
registered port a port between 1024 and 49151
Relying parties (RPs) provide services to members of a
federation.
IdP provides identities, makes assertions
about those
identities, and releases information about
the
identity holders.
Port 23 telnet and is not considered secure
because it
sends all of its data in cleartext, including
authentication data like usernames and
passwords
Data retention policies highlight what types of information an
organization
will maintain and the length of time they
will
maintain it. Data classification would not
be
covered in the retention policy
Answers with Verified Solutions | Latest
Updated 2026
Operation Aurora used spear-phishing emails
zero-day vulnerability in Internet Explorer
SMBGhost attackers execute arbitrary code on a
vulnerable
system.
Non Zero day
ProcDump a command-line utility whose primary
purpose is
monitoring an application for CPU spikes
and
generating crash dumps during a spike
that an
administrator or developer can use to
determine
the cause of the spike
Process Monitor shows real-time file system, Registry, and
process/thread activity
DiskMon displays all hard disk activity on a
Windows system
,a common attack model of an APT Quietly gathers information from
attack compromised
systems
Exact data match a pattern matching technique that uses a
structured
database of string values to detect
matches.
NOT usually included in a Denial-of-service attacks
penetration test
HEAD / HTTP/1.1 vs 2.0 requests the document header from the
server and
provides information such as the server
software
version and the server’s operating system.
- Easier to read vs 2.0
-HTTP/2 improves performance and
evasion due to
binary framing + multiplexing
1.1 = 80, 23,21,25, 143, 389
2.0 = 443
PUT Upload or overwrite files
Update API resources
*kind of dangerous for remote code
execution
Guideline Policy = what/why (management intent)
Policy Standards = mandatory specifics
Standard Procedures = how (step■by■step)
Procedure Guidelines = recommended practices
, Secure attribute cookies Secures cookies to where they can only be
transferred over HTTPS
- Prevents MITM
registered port a port between 1024 and 49151
Relying parties (RPs) provide services to members of a
federation.
IdP provides identities, makes assertions
about those
identities, and releases information about
the
identity holders.
Port 23 telnet and is not considered secure
because it
sends all of its data in cleartext, including
authentication data like usernames and
passwords
Data retention policies highlight what types of information an
organization
will maintain and the length of time they
will
maintain it. Data classification would not
be
covered in the retention policy