CYSA UPDATED ACTUAL QUESTIONS AND
CORRECT ANSWERS COMPREHENSIVE
STUDY GUIDE
●● Threats and vulnerabilities.
Answer: Risk exists at the intersection of _______ and _________.
●● Network access control
Answer: What type of system controls access to a network based on
criteria such as time of day, location, device type, and system health?
●● The Internet, an internal network, and a DMZ
Answer: What are the three networks typically connected to a triple-
homed firewall?
●● Packet filters
Stateful inspection firewalls
Next-generation firewalls
Web application firewalls.
Answer: What are the four types of firewalls?
●● Group Policy Objects (GPOs)
,Answer: ______ may be used to apply settings to many different
Windows systems at the same time.
●● Planning, Discovery, Attack, and Reporting
Answer: Four phases of penetration testing
●● Port scanner
Answer: What type of software can you use to enumerate the services
that are accepting network connections on a remote system without
probing that system for vulnerabilities?
●● nmap
Answer: What is the most commonly used port scanner?
●● Traceroute or tracert, depending on the operating system
Answer: What tool can be used to determine the path between two
systems over the Internet?
●● Anomaly analysis
Answer: What type of data analysis looks for differences from expected
behaviors?
●● Trend analysis
, Answer: What type of data analysis predicts threats based on existing
data?
●● Credentialed scan
Answer: What type of vulnerability scan leverages read-only access to
the scan target?
●● Risk appetite
Answer: What term is used to describe an organization's willingness to
tolerate risk?
●● Read-only account
Answer: What type of account should be used to perform credentialed
vulnerability scans?
●● Vulnerability scanning
Answer: What function is performed by QualysGuard, Nessus, Nexpose,
and OpenVAS?
●● Web application scanning
Answer: What is the purpose of Nikto and Acunetix?
●● Criticality
CORRECT ANSWERS COMPREHENSIVE
STUDY GUIDE
●● Threats and vulnerabilities.
Answer: Risk exists at the intersection of _______ and _________.
●● Network access control
Answer: What type of system controls access to a network based on
criteria such as time of day, location, device type, and system health?
●● The Internet, an internal network, and a DMZ
Answer: What are the three networks typically connected to a triple-
homed firewall?
●● Packet filters
Stateful inspection firewalls
Next-generation firewalls
Web application firewalls.
Answer: What are the four types of firewalls?
●● Group Policy Objects (GPOs)
,Answer: ______ may be used to apply settings to many different
Windows systems at the same time.
●● Planning, Discovery, Attack, and Reporting
Answer: Four phases of penetration testing
●● Port scanner
Answer: What type of software can you use to enumerate the services
that are accepting network connections on a remote system without
probing that system for vulnerabilities?
●● nmap
Answer: What is the most commonly used port scanner?
●● Traceroute or tracert, depending on the operating system
Answer: What tool can be used to determine the path between two
systems over the Internet?
●● Anomaly analysis
Answer: What type of data analysis looks for differences from expected
behaviors?
●● Trend analysis
, Answer: What type of data analysis predicts threats based on existing
data?
●● Credentialed scan
Answer: What type of vulnerability scan leverages read-only access to
the scan target?
●● Risk appetite
Answer: What term is used to describe an organization's willingness to
tolerate risk?
●● Read-only account
Answer: What type of account should be used to perform credentialed
vulnerability scans?
●● Vulnerability scanning
Answer: What function is performed by QualysGuard, Nessus, Nexpose,
and OpenVAS?
●● Web application scanning
Answer: What is the purpose of Nikto and Acunetix?
●● Criticality