Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 2 fuera de 8 páginas
Examen

CYSA EXAM 2023LATEST UPDATE VERIFIED SOLUTIONS

Document preview thumbnail
Vista previa 2 fuera de 8 páginas

CYSA EXAM 2023LATEST UPDATE VERIFIED SOLUTIONS What are the three key objectives of information security? - ANSWER Confidentiality, integrity, and availability Risk exists at the intersection of _______ and _________. - ANSWER Threats and vulnerabilities. What is the overall risk rating for a risk that has medium likelihood and high impact? - ANSWER High What type of system controls access to a network based on criteria such as time of day, location, device type, and system - ANSWER Network access control What are the three networks typically connected to a triple-homed firewall? - ANSWER The Internet, an internal network, and a DMZ What is the TCP port for the HTTP protocol? - ANSWER 80 What is the TCP port for the HTTPS protocol? - ANSWER 443 What are the four types of firewalls? - ANSWER Packet filters, stateful inspection firewalls, next-generation firewalls, and web application firewalls. ______ may be used to apply settings to many different Windows systems at the same time. - ANSWER Group Policy Objects (GPOs) What are the four phases of penetration testing? - ANSWER Planning, Discovery, Attack, and Reporting What type of software can you use to enumerate the services that are accepting network connections on a remote system - ANSWER Port scanner What is the range of well-known ports? - ANSWER 0-1023 What is the range of registered ports? - ANSWER What is the most commonly used port scanner? - ANSWER nmap What Cisco logging level indicates a critical event? - ANSWER 2 What service is responsible for resolving domain names to IP addresses? - ANSWER DNS What tool can be used to determine the path between two systems over the Internet? - ANSWER Traceroute or tracert, depending on the operating system What service allows you to look up the registered owner of a domain name? - ANSWER Whois What type of data analysis looks for differences from expected behaviors? - ANSWER Anomaly analysis What type of data analysis predicts threats based on existing data? - ANSWER Trend analysis What regulation requires vulnerability scans for organizations involved in credit card processing? - ANSWER PCI DSS What regulation requires vulnerability scanning for federal government agencies? - ANSWER FISMA What type of vulnerability scan leverages read-only access to the scan target? - ANSWER Credentialed scan What term is used to describe an organization's willingness to tolerate risk? - ANSWER Risk appetite What type of account should be used to perform credentialed vulnerability scans? - ANSWER Read-only account What function is performed by QualysGuard, Nessus, Nexpose, and OpenVAS? - ANSWER Vulnerability scanning What is the purpose of Nikto and Acunetix? - ANSWER Web application scanning What criteria should be used in prioritizing the remediation of vulnerabilities? - ANSWER Criticality, difficulty, severity, and exposure What industry-standard system is used to assess the severity of security vulnerabilities? - ANSWER CVSS What are the CVSS score ranges? - ANSWER Under 4.0 is low, 4.0-5.9 is medium, 6.0-9.9 is high, and 10.0 is critical. What is the term used to describe when a scanner reports a vulnerability that does not really exist? - ANSWER False positive What type of vulnerability allows an attacker to place more data into an area of memory than is allocated for a specific purpose? - ANSWER Buffer overflow What type of attack seeks to increase the level of access that an attacker has to a targeted system? - ANSWER Privilege escalation What type of attack allows an attacker to run software of his or her choice on the targeted system? - ANSWER Arbitrary cod

Vista previa del contenido

CYSA EXAM 2023 LATEST UPDATE VERIFIED SOLUTIONS What are the three key objectives of information security? - ANSWER Con fidentiality, integrity, and availability Risk exists at the intersection of _______ and _________. - ANSWER Threats and vulnerabilities. What is the overall risk rating for a risk that has medium likelihood and high impact? - ANSWER High What type of system controls access to a network based on criteria such as time of day, location, device type, and system - ANSWER Network access control What are the three networks typically connected to a triple -homed firewall? - ANSWER The Internet, an internal network, and a DMZ What is the TCP port for the HTTP protocol? - ANSWER 80 What is the TCP port for the HTTPS protocol? - ANSWER 443 What are the four types of firewalls? - ANSWER Packet filters, stateful inspection firewalls, next -generation firewal ls, and web application firewalls. ______ may be used to apply settings to many different Windows systems at the same time. - ANSWER Group Policy Objects (GPOs) What are the four phases of penetration testing? - ANSWER Planning, Discovery, Attack, and Reporting What type of software can you use to enumerate the services that are accepting network connections on a remote system - ANSWER Port scanner What is the range of well -known ports? - ANSWER 0 -1023 What is the range of registered ports? - ANSWER 1024 -49151 What is the most commonly used port scanner? - ANSWER nmap What Cisco logging level indicates a critical event? - ANSWER 2 What service is responsible for resolving domain names to IP addresses? - ANSWER DNS What tool can be used t o determine the path between two systems over the Internet? - ANSWER Traceroute or tracert, depending on the operating system What service allows you to look up the registered owner of a domain name? - ANSWER Whois What type of data analysis looks for differences from expected behaviors? - ANSWER Anomaly analysis What type of data analysis predicts threats based on existing data? - ANSWER Trend analysis What regulation requires vulnerability scans for organizations involved in credit card processing ? - ANSWER PCI DSS What regulation requires vulnerability scanning for federal government agencies? - ANSWER FISMA What type of vulnerability scan leverages read -only access to the scan target? - ANSWER Credentialed scan What term is used to describe an organization's willingness to tolerate risk? - ANSWER Risk appetite What type of account should be used to perform credentialed vulnerability scans? - ANSWER Read -only account What function is performed by QualysGuard, Nessus, Nexpose, and OpenVAS? - ANSWER Vulnerability scanning What is the purpose of Nikto and Acunetix? - ANSWER Web application scanning

Información del documento

Subido en
22 de marzo de 2024
Número de páginas
8
Escrito en
2023/2024
Tipo
Examen
Contiene
Preguntas y respuestas
$13.99

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
STUDENTSCORE
4.3
(3)
Vendido
13
Seguidores
6
Artículos
1379
Última venta
1 mes hace



Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes