CySA+ Exam with all Correct & 100% Verified Answers |
Actual Complete Exam |Already Graded A+
What are the three key objectives of information security? ✔Correct Answer-Confidentiality,
integrity, and availability
Risk exists at the intersection of _______ and _________. ✔Correct Answer-Threats and
vulnerabilities.
What type of system controls access to a network based on criteria such as time of day,
location, device type, and system health? ✔Correct Answer-Network access control
What are the three networks typically connected to a triple-homed firewall? ✔Correct
Answer-The Internet, an internal network, and a DMZ
What are the four types of firewalls? ✔Correct Answer-Packet filters
Stateful inspection firewalls
Next-generation firewalls
Web application firewalls.
______ may be used to apply settings to many different Windows systems at the same time.
✔Correct Answer-Group Policy Objects (GPOs)
Four phases of penetration testing ✔Correct Answer-Planning, Discovery, Attack, and
Reporting
What type of software can you use to enumerate the services that are accepting network
connections on a remote system without probing that system for vulnerabilities? ✔Correct
Answer-Port scanner
What is the most commonly used port scanner? ✔Correct Answer-nmap
What tool can be used to determine the path between two systems over the Internet?
✔Correct Answer-Traceroute or tracert, depending on the operating system
What type of data analysis looks for differences from expected behaviors? ✔Correct Answer-
Anomaly analysis
What type of data analysis predicts threats based on existing data? ✔Correct Answer-Trend
analysis
, What type of vulnerability scan leverages read-only access to the scan target? ✔Correct
Answer-Credentialed scan
What term is used to describe an organization's willingness to tolerate risk? ✔Correct Answer-
Risk appetite
What type of account should be used to perform credentialed vulnerability scans? ✔Correct
Answer-Read-only account
What function is performed by QualysGuard, Nessus, Nexpose, and OpenVAS? ✔Correct
Answer-Vulnerability scanning
What is the purpose of Nikto and Acunetix? ✔Correct Answer-Web application scanning
Remediation Priority ✔Correct Answer-Criticality
Difficulty
Severity
Exposure
What industry-standard system is used to assess the severity of security vulnerabilities?
✔Correct Answer-CVSS
What is the term used to describe when a scanner reports a vulnerability that does not really
exist? ✔Correct Answer-False positive
What type of vulnerability allows an attacker to place more data into an area of memory than is
allocated for a specific purpose? ✔Correct Answer-Buffer overflow
What type of attack seeks to increase the level of access that an attacker has to a targeted
system? ✔Correct Answer-Privilege escalation
What type of attack allows an attacker to run software of his or her choice on the targeted
system? ✔Correct Answer-Arbitrary code execution
What is the current secure standard for providing HTTPS encryption? ✔Correct Answer-TLS
1.2 or later
In what type of attack does the attacker sends spoofed DNS requests to a DNS server that are
carefully designed to elicit responses that are much larger in size than the original requests?
✔Correct Answer-DNS amplification
What term is used to describe any observable occurrence in a system or network that relates to
a security function? ✔Correct Answer-Security event
Actual Complete Exam |Already Graded A+
What are the three key objectives of information security? ✔Correct Answer-Confidentiality,
integrity, and availability
Risk exists at the intersection of _______ and _________. ✔Correct Answer-Threats and
vulnerabilities.
What type of system controls access to a network based on criteria such as time of day,
location, device type, and system health? ✔Correct Answer-Network access control
What are the three networks typically connected to a triple-homed firewall? ✔Correct
Answer-The Internet, an internal network, and a DMZ
What are the four types of firewalls? ✔Correct Answer-Packet filters
Stateful inspection firewalls
Next-generation firewalls
Web application firewalls.
______ may be used to apply settings to many different Windows systems at the same time.
✔Correct Answer-Group Policy Objects (GPOs)
Four phases of penetration testing ✔Correct Answer-Planning, Discovery, Attack, and
Reporting
What type of software can you use to enumerate the services that are accepting network
connections on a remote system without probing that system for vulnerabilities? ✔Correct
Answer-Port scanner
What is the most commonly used port scanner? ✔Correct Answer-nmap
What tool can be used to determine the path between two systems over the Internet?
✔Correct Answer-Traceroute or tracert, depending on the operating system
What type of data analysis looks for differences from expected behaviors? ✔Correct Answer-
Anomaly analysis
What type of data analysis predicts threats based on existing data? ✔Correct Answer-Trend
analysis
, What type of vulnerability scan leverages read-only access to the scan target? ✔Correct
Answer-Credentialed scan
What term is used to describe an organization's willingness to tolerate risk? ✔Correct Answer-
Risk appetite
What type of account should be used to perform credentialed vulnerability scans? ✔Correct
Answer-Read-only account
What function is performed by QualysGuard, Nessus, Nexpose, and OpenVAS? ✔Correct
Answer-Vulnerability scanning
What is the purpose of Nikto and Acunetix? ✔Correct Answer-Web application scanning
Remediation Priority ✔Correct Answer-Criticality
Difficulty
Severity
Exposure
What industry-standard system is used to assess the severity of security vulnerabilities?
✔Correct Answer-CVSS
What is the term used to describe when a scanner reports a vulnerability that does not really
exist? ✔Correct Answer-False positive
What type of vulnerability allows an attacker to place more data into an area of memory than is
allocated for a specific purpose? ✔Correct Answer-Buffer overflow
What type of attack seeks to increase the level of access that an attacker has to a targeted
system? ✔Correct Answer-Privilege escalation
What type of attack allows an attacker to run software of his or her choice on the targeted
system? ✔Correct Answer-Arbitrary code execution
What is the current secure standard for providing HTTPS encryption? ✔Correct Answer-TLS
1.2 or later
In what type of attack does the attacker sends spoofed DNS requests to a DNS server that are
carefully designed to elicit responses that are much larger in size than the original requests?
✔Correct Answer-DNS amplification
What term is used to describe any observable occurrence in a system or network that relates to
a security function? ✔Correct Answer-Security event