• ¿Documento equivocado? Cámbialo gratis
  • Escrito por estudiantes que aprobaron
  • Inmediatamente disponible después del pago
  • Leer en línea o como PDF
Vender
¿Dónde estudias?
Tu idioma
Document preview thumbnail
Vista previa 3 fuera de 16 páginas
Examen

Cysa Evaluation Test 2026 Questions And Answers Sure A.pdf

Document preview thumbnail
Vista previa 3 fuera de 16 páginas

CYSA EVALUATION TEST 2026 QUESTIONS AND ANSWERS SURE A.pdf

Vista previa del contenido

CYSA EVALUATION TEST 2026 QUESTIONS AND
ANSWERS SURE A+
✔✔Allan is developing a document that lists the acceptable mechanisms for securely
obtaining remote administrative access to servers in his organization. What type of
document is Allan writing? - ✔✔standard

✔✔______________ describe specific security controls that must be in place for an
organization. - ✔✔Standards

✔✔Which one of the following is not a common use of the NIST Cybersecurity
Framework? - ✔✔create specific technology requirements for an organization

✔✔The ______________ is designed to help organizations describe their current
cybersecurity posture, describe their target state for cybersecurity, identify and prioritize
opportunities for improvement, assess progress, and communicate with stakeholders
about risk. - ✔✔NIST Cybersecurity Framework

✔✔Shelly is writing a document that describes the steps that incident response teams
will follow upon first notice of a potential incident. What type of document is she
creating? - ✔✔procedure

✔✔______________ provide checklist-style sets of step-by-step instructions guiding
how employees should react in a given circumstance and commonly guide the early
stages of incident response. - ✔✔Procedures

✔✔Sue is a manager of a group of system administrators and is in charge of approving
all requests for administrative rights. In her role, she files a change request to grant a
staff member administrative rights and then approves it. What personnel control would
best help to prevent this abuse of her role? - ✔✔separation of duties

,✔✔Ben wants to ensure that a single person cannot independently access his
organization's secure vault. What personnel control is best suite to this need? - ✔✔dual
control

✔✔Lauren's departure from her organization leaves her team without a Linux systems
administrator and means they no longer have in-depth knowledge of a critical business
system. What should her manager have done to ensure that this issue did not have a
significant impact? - ✔✔succession planning

✔✔Rick is reviewing his organization's network design and is concerned that a known
flaw in the border router could let an attacker disable their Internet connectivity. Which
of the following is an appropriate compensatory control? - ✔✔an alternate Internet
connectivity method using a different router type

✔✔Fred has been assigned to review his organization's host security policies due to a
recent theft of a workstation that contained sensitive data. Which of the following
controls would best help to prevent a stolen machine from causing a data breach? -
✔✔full disk encryption

✔✔_________________ is useful for reporting machine state and might even help
locate a machine if it was reconnect to a network, but it does not protect the data a
machine contains. - ✔✔Central management

✔✔Full disk encryption protects sensitive data on a workstation in the event of theft
occurring. _________________ would provide helpful additional capabilities, but both
rely on the system connecting to a network after it is stolen. - ✔✔remote wipe
capabilities and machine tracking software

✔✔A member of Susan's team recently fell for a phishing scam and provided his
password and personal information to a scammer. What layered security approach is
not an appropriate layer for Susan to implement to protect her organization from future
issues? - ✔✔multi-tiered firewalls

✔✔In the event a scammer acquired passwords and personal information,
_________________ would require the attacker to have the second factor in addition to
the password. - ✔✔multifactor authentication

✔✔Chris is in charge of his organization's Windows security standard, including their
Windows XP security standard, and has recently decommissioned the organization's
last Windows XP system. What is the next step in his security standard's life cycle? -
✔✔retiring the Windows XP standard

, ✔✔Retirement is the last step at the end of the life cycle for a standard or process. This
means that if the process is retired, a _________________ is not needed. - ✔✔final
update

✔✔Example Corporation has split their network into network zones that include sales,
HR, research and development, and guest networks, each separated from the others
using network security devices. What concept is Example Corporation using for their
security network? - ✔✔segmentation

✔✔Zoned routing is a _________________. - ✔✔made up term

✔✔Which of the following layered security controls is commonly used at the WAN, LAN,
and host layer in a security design? - ✔✔firewalls

✔✔_________________ are commonly used to create network protection zones, to
protect network borders, and at the host level to help armor the host against attacks. -
✔✔Firewalls

✔✔_________________ at rest is most frequently used at the host layer. -
✔✔Encryption

✔✔_________________ are typically used at the edge of a network for publicly
accessible services. - ✔✔DMZs

✔✔In Lauren's initial design for a secure network, she applied the same security
controls to every system and network. After reviewing her design, she decided to isolate
systems based on their functions and to apply controls to protected network segments
for more sensitive data and systems. What two design models did she apply? -
✔✔uniform protection and protected enclaves

✔✔An _________________ design would have applied protections based on
information classification or control requirements. - ✔✔information-based

✔✔Michelle has been asked to review her corporate network's design for single points
of failure that would impact the core network operations. This is a redundant network
design with a critical fault: a single point of failure that could take the network offline if it
failed. What could be the single point of failure? - ✔✔the internet access connected
directly to the ISP

✔✔During a penetration test of Anna's company, the penetration testers were able to
compromise the company's web servers and deleted their log files, preventing analysis
of their attacks. What compensating control is best suited to prevent this issue in the
future? - ✔✔sending logs to a syslog server or bastion host

Información del documento

Subido en
10 de julio de 2026
Número de páginas
16
Escrito en
2025/2026
Tipo
Examen
Contiene
Preguntas y respuestas
$16.99

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
BOARDWALKer
3.4
(19)
Vendido
158
Seguidores
7
Artículos
26594
Última venta
3 días hace



Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes