CYSA COMPLETE EXAMINATION TEST
QUESTIONS WITH VERIFIED SOLUTIONS
●● An organization seeks to improve its threat intelligence capabilities
by leveraging the MITRE ATT&CK matrices. How can this resource's
unique IDs and tactic categories help the organization recognize and
protect against specific attacks?
Answer: By identifying patterns in TTPs used by threat groups and
developing defense strategies
●● A network administrator reviews the logs in the security information
and event management (SIEM) system and notices an alert for
anomalous behavior in a relevant log. What should be the next step in
the incident response activities, specifically related to Indicators of
Compromise (IoCs)?
Answer: Investigate the alert further to determine the cause of the
anomalous behavior
●● A financial company has experienced a security breach, and
cybersecurity professionals need to analyze data to prioritize
vulnerabilities and identify the attack vectors used by cybercriminals.
How can the Common Vulnerability Scoring System (CVSS) aid in this
process?
Answer: It can help to prioritize remediation steps to prevent security
incidents.
,●● Which of the following scenarios is the most accurate example of a
stack overflow?
Answer: A program tries to store more data in the stack than it can
handle.
●● A large company is considering using virtualization technology to
isolate and protect critical systems from potential cyberattacks. What is
the benefit of this technology in cybersecurity?
Answer: It makes it harder for attackers to breach the network by
creating multiple virtual machines secured independently.
●● An unauthenticated attacker exploited a company's web portal that
contains customer information, where customers can view their account
profile, such as their name, email address, and account balance. Each
customer has a unique ID used to retrieve their information from the
database. However, the attacker changed the customer ID parameter in
the URL to access customers' information. What kind of web application
vulnerability did the attacker exploit?
Answer: Broken access control
●● During an investigation into a cybersecurity incident, what steps
should the organization take to ensure that host devices and media taken
from the crime scene are properly labeled, bagged, and sealed?
,Answer: Label the devices and media with tamper-evident, antistatic
shielding bags, and record evidence collection details on a chain of
custody form
●● A network administrator receives an alert that the system has
detected a cyberattack on the organization's network. The administrator
needs to quickly identify the type of attack and take appropriate action to
mitigate the threat. What methodology framework can the administrator
use to analyze the stages of a cyberattack and understand how to defend
against it?
Answer: Cyber kill chain
●● An organization has tasked a business leader with writing an
executive summary for a cybersecurity incident report that they recently
experienced. What key information should the executive include in the
summary to provide a clear and concise overview of the incident?
Answer: A brief description of the incident, including the date, time, and
scope of the attack
●● A network administrator for a healthcare organization receives an
alert from their security information and event management (SIEM)
system indicating a potential breach. Upon further investigation, the
administrator discovers that access to patient data has occurred and is
potentially exfiltrated. As a result, the network administrator begins to
perform incident response activities, including detection and analysis,
evidence acquisition, and legal hold. What is the purpose of evidence
acquisition in this scenario?
, Answer: To preserve findings for use in legal proceedings
●● A company has recently discovered that its network has become slow
and unreliable, with frequent outages and disruptions. An IT staff
member suspects that rogue devices on the network could be causing
these issues. What is the best way to identify rogue devices on a
network? (Select the three best options.)
Answer: Conduct network scans using tools like Nmap to identify active
devices on the network.
Use intrusion detection systems (IDS) to monitor network traffic and
identify devices that do not belong on the network.
Utilize Network Access Control (NAC) solutions to authenticate and
validate devices before granting network access.
●● A security manager is responsible for identifying and mitigating
insider threats within the organization. The manager has concerns about
the potential for intentional insider threats. Which scenario best
describes this type of threat?
Answer: An employee deliberately causes damage to the organization
●● A web application that allows users to upload images to their profile
has a security vulnerability. An attacker can upload a specially crafted
image, causing the web application to try to write data beyond the end of
a dynamically allocated portion of memory allocated during run
QUESTIONS WITH VERIFIED SOLUTIONS
●● An organization seeks to improve its threat intelligence capabilities
by leveraging the MITRE ATT&CK matrices. How can this resource's
unique IDs and tactic categories help the organization recognize and
protect against specific attacks?
Answer: By identifying patterns in TTPs used by threat groups and
developing defense strategies
●● A network administrator reviews the logs in the security information
and event management (SIEM) system and notices an alert for
anomalous behavior in a relevant log. What should be the next step in
the incident response activities, specifically related to Indicators of
Compromise (IoCs)?
Answer: Investigate the alert further to determine the cause of the
anomalous behavior
●● A financial company has experienced a security breach, and
cybersecurity professionals need to analyze data to prioritize
vulnerabilities and identify the attack vectors used by cybercriminals.
How can the Common Vulnerability Scoring System (CVSS) aid in this
process?
Answer: It can help to prioritize remediation steps to prevent security
incidents.
,●● Which of the following scenarios is the most accurate example of a
stack overflow?
Answer: A program tries to store more data in the stack than it can
handle.
●● A large company is considering using virtualization technology to
isolate and protect critical systems from potential cyberattacks. What is
the benefit of this technology in cybersecurity?
Answer: It makes it harder for attackers to breach the network by
creating multiple virtual machines secured independently.
●● An unauthenticated attacker exploited a company's web portal that
contains customer information, where customers can view their account
profile, such as their name, email address, and account balance. Each
customer has a unique ID used to retrieve their information from the
database. However, the attacker changed the customer ID parameter in
the URL to access customers' information. What kind of web application
vulnerability did the attacker exploit?
Answer: Broken access control
●● During an investigation into a cybersecurity incident, what steps
should the organization take to ensure that host devices and media taken
from the crime scene are properly labeled, bagged, and sealed?
,Answer: Label the devices and media with tamper-evident, antistatic
shielding bags, and record evidence collection details on a chain of
custody form
●● A network administrator receives an alert that the system has
detected a cyberattack on the organization's network. The administrator
needs to quickly identify the type of attack and take appropriate action to
mitigate the threat. What methodology framework can the administrator
use to analyze the stages of a cyberattack and understand how to defend
against it?
Answer: Cyber kill chain
●● An organization has tasked a business leader with writing an
executive summary for a cybersecurity incident report that they recently
experienced. What key information should the executive include in the
summary to provide a clear and concise overview of the incident?
Answer: A brief description of the incident, including the date, time, and
scope of the attack
●● A network administrator for a healthcare organization receives an
alert from their security information and event management (SIEM)
system indicating a potential breach. Upon further investigation, the
administrator discovers that access to patient data has occurred and is
potentially exfiltrated. As a result, the network administrator begins to
perform incident response activities, including detection and analysis,
evidence acquisition, and legal hold. What is the purpose of evidence
acquisition in this scenario?
, Answer: To preserve findings for use in legal proceedings
●● A company has recently discovered that its network has become slow
and unreliable, with frequent outages and disruptions. An IT staff
member suspects that rogue devices on the network could be causing
these issues. What is the best way to identify rogue devices on a
network? (Select the three best options.)
Answer: Conduct network scans using tools like Nmap to identify active
devices on the network.
Use intrusion detection systems (IDS) to monitor network traffic and
identify devices that do not belong on the network.
Utilize Network Access Control (NAC) solutions to authenticate and
validate devices before granting network access.
●● A security manager is responsible for identifying and mitigating
insider threats within the organization. The manager has concerns about
the potential for intentional insider threats. Which scenario best
describes this type of threat?
Answer: An employee deliberately causes damage to the organization
●● A web application that allows users to upload images to their profile
has a security vulnerability. An attacker can upload a specially crafted
image, causing the web application to try to write data beyond the end of
a dynamically allocated portion of memory allocated during run