• ¿Documento equivocado? Cámbialo gratis
  • Escrito por estudiantes que aprobaron
  • Inmediatamente disponible después del pago
  • Leer en línea o como PDF
Vender
¿Dónde estudias?
Tu idioma
Document preview thumbnail
Vista previa 4 fuera de 47 páginas
Examen

CySA Exam with all Correct & 100% Verified Answers |Actual Complete Update |Already Graded A+

Document preview thumbnail
Vista previa 4 fuera de 47 páginas

CySA Exam with all Correct & 100% Verified Answers |Actual Complete Update |Already Graded A+

Vista previa del contenido

CySA Exam with all Correct & 100% Verified Answers |
Actual Complete Update |Already Graded A+

Which one of the following objectives is not one of the three main objectives that information
security professionals must achieve to protect their organizations against cybersecurity threats?
✔Correct Answer-nonrepudiation

Tommy is assessing the security database servers in his datacenter and realizes that one of them
is missing a critical Oracle security patch. What type of situation has Tommy detected?
✔Correct Answer-vulnerability

Ben is preparing to conduct a cybersecurity risk assessment for his organization. If he chooses to
follow the standard process proposed by NIST, which one of the following steps would come
first? ✔Correct Answer-Identify threats

Cindy is conducting a cybersecurity risk assessment and is considering the impact that a failure
of her city's power grid might have on the organization. What type of threat is she considering?
✔Correct Answer-environmental

Which one of the following categories of threat requires that cybersecurity analysts consider
the capability, intent and targeting of the threat source? ✔Correct Answer-adversarial

Vincent is responding to a security incident that compromised one of his organization's web
servers. He does not believe that the attackers modified or stole any information, but they did
disrupt access to the organization's website. What cybersecurity objective did this attack
violate? ✔Correct Answer-availability

Which one of the following is an example of an operational security control? ✔Correct
Answer-penetration tests

Encryption software, network firewalls, and antivirus software are all examples of
_________________ security controls. ✔Correct Answer-technical

Paul recently completed a risk assessment and determined that his network was vulnerable to
hackers connecting to open ports on servers. He implemented a network firewall to reduce the
likelihood of a successful attack. What risk management strategy did Paul choose to pursue?
✔Correct Answer-risk mitigation

Robert's organization has a BYOD policy, and he would like to ensure that devices connected to
the network under this policy have current antivirus software. What technology can best assist
him with this goal? ✔Correct Answer-network access control

,When performing 802.1x authentication, what protocol does the authenticator use to
communicate with the authentication server? ✔Correct Answer-RADIUS

Juan is configuring a new device that will join his organization's wireless network. The wireless
network uses 802.1x authentication. What type of agent must be running on the device for it to
join this network? ✔Correct Answer-802.1x supplicant

Rick is preparing a firewall rule that will allow network traffic from external systems to a web
server running the HTTPS protocol. What TCP port must he allow to pass through the firewall?
✔Correct Answer-443

What type of firewall provides the greatest degree of contextual information and can include
information about users and applications in its decision-making process? ✔Correct Answer-
Next Generation Firewalls

Wayne is configuring a jump box server that system administrators will connect to from their
laptops. Which port should definitely not be open on the jump box? ✔Correct Answer-23

Tom would like to deploy consistent security settings to all of his Windows settings
simultaneously. What technology can he use to achieve this goal? ✔Correct Answer-group
policy object

During what phase of a penetration test should the testers obtain written authorization to
conduct the test? ✔Correct Answer-planning

Which step occurs first during the attack phase of a penetration test? ✔Correct Answer-
gaining access

Barry is participating in a cybersecurity wargame exercise. His role is to attempt to break into
adversary systems. What team is he on? ✔Correct Answer-red

Which one of the following techniques might be used to automatically detect and block
malicious software that does not match known malware signatures? ✔Correct Answer-
sandboxing

Kevin would like to implement a specialized firewall that can protect against SQL injection,
cross-site scripting, and similar attacks. What technology should he choose? ✔Correct
Answer-WAF

What method is used to replicate DNS information for DNS servers but is also a tempting exploit
target for attackers? ✔Correct Answer-zone transfers

____________ is a suite of DNS security specifications. ✔Correct Answer-DNSSEC

,What flag does nmap use to enable operating system identification? ✔Correct Answer--o

What command line tool can be used to determine the path that traffic takes to a remote
system? ✔Correct Answer-traceroute

Traceroute is a command-line tool that uses __________ to trace the route that a packet takes
to a host. ✔Correct Answer-ICMP

What type of data can frequently be gathered from images taken on smartphones? ✔Correct
Answer-EXIF

EXIF or Exchangeable Image Format data often includes ________________, allowing the
images to be mapped and identified to a specific device or type of camera. ✔Correct Answer-
location and camera data

Which Cisco log level is the most critical? ✔Correct Answer-0

Which Cisco log level is used for debugging information and is at the bottom of the scale?
✔Correct Answer-7

During passive intelligence gathering, you are able to run netstat on a workstation located at
your target's headquarters. What information would you not be able to find using netstat on a
Windows system? ✔Correct Answer-Active IPX connections

Active TCP connections and the executables that are associated with them, and route table
information are all available via ____________. ✔Correct Answer-Netstat

Which type of Windows log is most likely to contain information about a file being deleted?
✔Correct Answer-security logs

What organization manages the global IP address space? ✔Correct Answer-IANA

Before Ben sends a Word document, he uses the built-in Document Inspector to verify that the
file does not contain hidden content. What is this process called? ✔Correct Answer-metadata
purging

What type of analysis is best suited to identify a previously unknown malware package
operating on a compromised system? ✔Correct Answer-heuristic analysis

Which of the following is not a common DNS anti-harvesting technique? ✔Correct Answer-
registering manually

CAPTCHAs, rate limiting, and blacklisting systems or networks that are gathering data are all
common ___________ techniques. ✔Correct Answer-anti-DNS harvesting

, The __________ flag indicates a zone transfer in both the dig and host utilities. ✔Correct
Answer-axfr

Which of the following is not a reason that penetration testers often perform packet capture
while conducting port and vulnerability scanning? ✔Correct Answer-plausible deniability

A ____________ is often used to document work, including the time that a given scan or
process occurred, and it can also be used to provide additional data for further analysis.
✔Correct Answer-packet capture

What process uses information such as the way that a system's TCP stack responds to queries,
what TCP options it supports, and the initial window size it uses? ✔Correct Answer-OS
detection

What tool would you use to capture IP traffic information to provide flow and volume
information about a network? ✔Correct Answer-netflow

__________ provides information about local connections, which applications have made them,
and other useful local system information. ✔Correct Answer-netstat

What method used to replicate DNS information between DNS servers can also be used to
gather large amounts of information about an organization's systems? ✔Correct Answer-zone
transfer

Selah believes that an organization she is penetration testing may have exposed information
about their systems on their website in the past. What site might help her find an older copy of
their website? ✔Correct Answer-The Internet Archive

During an information gathering exercise, Chris is asked to find out detailed personal
information about his target's employees. What is frequently the best place to find this
information? ✔Correct Answer-social media

Which lookup tool provides information about a domain's registrar and physical location?
✔Correct Answer-Whois

____________ will provide IP address or hostname information. ✔Correct Answer-nslookup

__________ will provide IPv4 and IPv6 information as well as email service information.
✔Correct Answer-host

___________ attempts to identify the path to a remote host as well as the systems along the
route. ✔Correct Answer-traceroute

Información del documento

Subido en
9 de julio de 2026
Número de páginas
47
Escrito en
2025/2026
Tipo
Examen
Contiene
Preguntas y respuestas
$23.99

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
Studyclub
3.6
(14)
Vendido
69
Seguidores
1
Artículos
13351
Última venta
4 días hace



Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes