Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 4 fuera de 45 páginas
Examen

CompTIA CySA+ (CS0-003) Practice Exam #1

Document preview thumbnail
Vista previa 4 fuera de 45 páginas

1. Which of the following is a technique used in Secure Disposal? Zero-fill Clearing Degaussing Erasing: Degaussing Secure Disposal involves the physical destruction of media. This can be done by mechanical shredding, incineration, or degaussing. Degaussing, should be used for media containing top secret or highly confidential information. Clearing data prevents data from being retrieved without the use of state of the art laboratory techniques. Clearing often involves overwriting data one or more times with repetitive or randomized data. It is not part of Secure Disposal because the media isn't destroyed. Zero-fill overwrites the media with bits to eliminate information. It allows the media to be reused. It doesn't destroy the media, so it isn't part of Secure Disposal.

Vista previa del contenido

CompTIA CySA+ (CS0-003) Practice Exam #1
Study online at https://quizlet.com/_e7ugr1
1. Which of the following is a technique used in Secure Disposal?

Zero-fill
Clearing
Degaussing
Erasing: Degaussing

Secure Disposal involves the physical destruction of media. This can be done by
mechanical shredding, incineration, or degaussing. Degaussing, should be used
for media containing top secret or highly confidential information. Clearing data
prevents data from being retrieved without the use of state of the art laboratory
techniques. Clearing often involves overwriting data one or more times with repetitive
or randomized data. It is not part of Secure Disposal because the media isn't
destroyed. Zero-fill overwrites the media with bits to eliminate information. It allows
the media to be reused. It doesn't destroy the media, so it isn't part of Secure
Disposal.
2. Which of the following is a characteristic of the Deep Web?

Contains information not indexed by standard search engines

Accessible through standard browsers

Only includes encrypted data

Predominantly used for illegal activities: Contains information not indexed by
standard search engines

The Deep Web contains information that is not indexed by standard search engines,
making it invisible to conventional searches. The Deep Web does not only include
encrypted data. It includes all data not indexed by search engines, whether encrypt-
ed or not. The Deep Web is not typically accessible through standard browsers. It
requires specific software (like Tor) for access. While some illegal activities do occur
on the Deep Web, it is also used for many legitimate purposes.
3. An organization's security team has recently discovered several vulner-
abilities within its systems. Why is it crucial for these vulnerabilities to be
thoroughly reported and communicated within the organization?

It ensures that the organization maintains compliance with required security
standards and protocols


, CompTIA CySA+ (CS0-003) Practice Exam #1
Study online at https://quizlet.com/_e7ugr1


It eliminates the need for regular system audits

It guarantees that the organization will not experience a data breach

It reduces the need for employee cybersecurity training: It ensures that the
organization maintains compliance with required security standards and protocols

Detailed reporting and communication about vulnerabilities help the organization
remain in line with required compliance standards by demonstrating proactive risk
management. Various regulations mandate vulnerability management reporting,
and these requirements may vary based on factors such as organization location,
industry, and size. Common regulations include the Payment Card Industry Data
Security Standard (PCI DSS), which mandates reporting vulnerabilities to the PCI
Security Standards Council. The Health Insurance Portability and Accountability
Act (HIPAA) requires healthcare organizations to report security breaches to the
Department of Health and Human Services. Additionally, the Sarbanes-Oxley Act
(SOX) mandates public companies to report vulnerabilities to the Securities and
Exchange Commission, while the National Institute of Standards and Technology
(NIST) Special Publication 800-53 stipulates reporting vulnerabilities to the appro-
priate authorities. Organizations should consult their legal team for guidance on
applicable regulations. Employee training remains essential as human error is a
common source of security risks, independent of specific system vulnerabilities.
While effective vulnerability management reduces the risk of data breaches, it
cannot completely guarantee prevention due to the evolving nature of cyber threats.
Regular audits are still necessary as they provide an ongoing review of the organi-
zation's security posture, beyond identified vulnerabilities.
4. What is the primary goal of the OWASP Testing Guide?

Understanding the relationships between the elements of a cyber attack

Providing a knowledge base of tactics, techniques, and procedures used by
attackers

Providing a framework for web application security testing

Describing the linear progression of a cyber attack: Providing a framework for
web application security testing



, CompTIA CySA+ (CS0-003) Practice Exam #1
Study online at https://quizlet.com/_e7ugr1
The OWASP Testing Guide provides a comprehensive framework for testing the
security of web applications. This is the main focus of the Cyber Kill Chain, not the
OWASP Testing Guide. This is a primary focus of the Diamond Model of Intrusion
Analysis, not the OWASP Testing Guide. This is a primary purpose of the MITRE
ATT&CK framework, not the OWASP Testing Guide.
5. As part of your organization's proactive threat hunting, you're considering
gathering threat intelligence from the deep web and dark web. What could be
a significant benefit of this approach?

Discovering potential threats before they impact your organization

Avoiding the need for other security measures

Eliminating all cyber threats

Increasing the organization's web presence: Discovering potential threats before
they impact your organization

Gathering threat intelligence from the deep web and dark web can help your
organization identify emerging threats or planned attacks before they affect your
network. While gathering intelligence can help identify and mitigate threats, it does
not guarantee the elimination of all cyber threats. Gathering threat intelligence is
a part of a broader security strategy and should be used in conjunction with other
security measures, not in lieu of them. Gathering threat intelligence from the deep
web and dark web is not related to increasing an organization's web presence; it's
about identifying potential cyber threats.
6. Which tool should a malware analyst utilize to track the registry's changes
and the file system while running a suspicious executable on a Windows
system?

DiskMon
Autoruns
Process Monitor
ProcDump: Process Monitor

Process Monitor is an advanced monitoring tool for Windows that shows real-time file
system, Registry, and process/thread activity. Autoruns shows you what programs
are configured to run during system bootup or login. ProcDump is a command-line
utility whose primary purpose is monitoring an application for CPU spikes and


, CompTIA CySA+ (CS0-003) Practice Exam #1
Study online at https://quizlet.com/_e7ugr1
generating crash dumps during a spike that an administrator or developer can use to
determine the cause of the spike. DiskMon is an application that logs and displays
all hard disk activity on a Windows system. This question may seem beyond the
scope of the exam. Still, the objectives allow for "other examples of technologies,
processes, or tasks about each objective may also be included on the exam although
not listed or covered" in the objectives' bulletized lists. The exam tests the equivalent
of 4 years of hands-on experience in a technical cybersecurity job role. The content
examples listed in the objectives are meant to clarify the test objectives and should
not be construed as a comprehensive listing of this examination's content. Therefore,
questions like this are fair game on test day. That said, your goal isn't to score 100%
on the exam; it is to pass it. Don't let questions like this throw you off on test day. If
you aren't sure, take your best guess and move on!
7. Which of the following is NOT a valid reason to conduct reverse engineer-
ing?

To commit industrial espionage

To allow an attacker to spot vulnerabilities in an executable

To allow the software developer to spot flaws in their source code

To determine how a piece of malware operates: To allow the software developer
to spot flaws in their source code

If a software developer has a copy of their source code, there is no need to reverse
engineer it since they can directly examine the code. Doing this is known as static
code analysis, not reverse engineering. Reverse engineering is the process of
analyzing a system's or application's structure to reveal more about how it functions.
In malware, examining the code that implements its functionality can provide you
with information as to how the malware propagates and what its primary directives
are. Reverse engineering is also used to conduct industrial espionage since it can
allow a company to figure out how a competitor's application works and develop
its own version. An attacker might use reverse engineering of an application or
executable to identify a flaw or vulnerability in its operation and then exploit that flaw
as part of their attack.
8. The incident response team leader has asked you to perform a forensic
examination on a workstation suspected of being infected with malware. You
remember from your training that you must collect digital evidence in the
proper order to protect it from being changed during your evidence collection

Libro relacionado
 image
Mike Chapple, David Seidl CompTIA CySA+ Practice Tests
Editorial: 2023 ISBN: 9781394182947 Edición: Desconocido

Información del documento

Subido en
13 de diciembre de 2024
Número de páginas
45
Escrito en
2024/2025
Tipo
Examen
Contiene
Preguntas y respuestas
$10.49

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
Exammate
2.7
(10)
Vendido
64
Seguidores
8
Artículos
3191
Última venta
3 semanas hace



Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes