WorksheetsCySA+ Days 1 - 3
Total questions: 37
Worksheet time: 19mins
What type of Risk Response should be chosen to reduce the likelihood or impact of a risk?
Accept
Mitigate
Transfer
Avoid
What type of Risk Response aligns with purchasing cybersecurity insurance?
Avoid
Accept
Mitigate
Transfer
Gaining unauthorized access into a company's network is considered a (blank).
Tacitc
Technique
Procedure
Good time
What type of Compensating Control refers to day-to-day procedures that maintain security?
Managerial
Operational
Technical
Preventative
Which Security Control is used to identify and alert on security incidents as they happen?
Corrective
Responsive
Detective
Preventive
Footprinting or Fingerprinting? Gathering open-source information about a target system or network to identify potential vulnerabilities.
Footprinting
Fingerprinting
Footprinting or Fingerprinting? Determining the specific details of the target system, such as the OS and application versions, to understand its configuration and potential weaknesses.
Footprinting
Fingerprinting
Penetration Testing or Adversary Emulation? Mimicking/replicating the TTPs of actual, real-world attackers to test an organization's defenses.
Pen Testing
Adversary Emulation
Which is the correct order of the Patching & Configuration Management Process?
Testing, Validation, Implementation, Rollback
Implementation, Testing, Rollback, Validation
Testing, Implementation, Rollback, Validation
Validation, Testing, Implementation, Rollback
What is the term that describes a scheduled timeframe when technicians would perform a backup generator test?
Planned Outage
Unplanned Outage
Maintenance Window
Off-peak hours maintenance
True or False? Patching tools are often cross-platform compatible, meaning you do not need separate patching tools for Windows, Linux, macOS, etc.
True
False
This term describes a specific, measurable target that defines the level of service expected from our coworkers for a particular aspect, such as an uptime rate of 99.99%.
Service Level Objective (SLO)
Service Level Agreement (SLA)
This term describes raising issues to higher authorities or more senior staff members when necessary.
Prioritization
Escalation
Exemption
Transferrence
This term describes a monetary incentive for ethical hackers to find and report vulnerabilities in an organization's systems or software.
Penetration Testing
Adversary Emulation
Bug Bounty
Exploitation
This strategic framework for understanding and preventing cyberattacks was developed by Lockheed Martin, and is a structured approach to breaking down the stages of an attack.
MITRE ATT&CK
MISP
Cyber Kill Chain
OWASP
This intrusion analysis framework focuses on the Adversary, Capability, Victim & Infrastructure.
MITRE ATT&CK
Diamond Model
MISP
Cyber Kill Chain
This framework is a comprehensive knowledge base that contains the tactics and techniques of actual cyber adversaries and real-world attacks that happened in the past.
Cyber Kill Chain
MITRE ATT&CK
OWASP
Diamond Model
True or False? The Open-Source Security Testing Methodology Manual (OSS TMM) is a manual that you can download to help you with security assessments.
True
False
True or False? A user that unintentionally clicked on a fraudulent URL in an email is known as an Insider Threat
True
False
This term refers to the part of the internet that is not indexed (not searchable), such as a password-protected website.
Paid Feed
Deep Web
Dark Web
Dark Net
True or False? The Information Sharing and Analysis Centers (ISACs) are non-profit organizations that provide a central resource for gathering and sharing information on cyber threats that affect the nation's critical infrastructure.
True
False
What metric helps rank or score threat intelligence to indicate the reliability, timeliness and relevance of the data?
Confidence level
Threat reliability level
Quality / Quantity
Relevence
Is a Honeypot a form of active or passive defense?
Active
Passive
Which is the correct order of the Cyber Incident Response Cycle?
Preparation, Identification, Containment, Eradication, Recovery
Identification, Preparation, Containment, Eradication, Recovery
Preparation, Identification, Eradication, Containment, Recovery
IDK... my bacon's burning.
What is the acronym that describes intelligence gathered from publicly available sources, such as social media?
(a)
Considering Digital Forensics, what term describes detailed, real-time records taken by forensic examiners that document every step of the examination process, including observations, actions taken, and any findings?
Chain of Custody
Field Notes
Forensically sound documentation
Legal hold
If I want to see guidelines for more than 100 secure configurations for 25+ vendor products families, where would I want to look?
DoD/DISA STIGs
MITRE ATT&CK
OWASP
CIS Benchmarks
True or False? Unlike containers, multiple VMs share the host OS, making them more lightweight and faster to start.
True
False
Which type of Hypervisor is known as a "bare metal" device (one big BEEFY server)?
Type I
Type II
Type III
Type IV
Which Cloud Deployment Model states that the CSP handles the most responsibility?
IaaS
PaaS
SaaS
IaC
What is the term to describe a shift in mindset that no longer relies solely on a secure network boundary, but focuses on Zero Trust?
Remote Work Policy
VPN
Deperimeterization
Defense in Depth
Which Logging Level is more severe: WARN or ERROR
ERROR
WARN
Which security mechanism controls and monitors access to accounts that have elevated permissions?
IAM
PAM
PAL
IAC
Which of the following accurately describes penetration testing?
Automated scanning of systems for vulnerabilities
Simulating real-world attacks to identify system weaknesses
Conducting security audits to ensure compliance
Testing the rigidity of direct-bury cables for long-haul communications
Penetration testing involves:
Passive analysis of system vulnerabilities
Active exploitation of vulnerabilities to assess security
Monitoring system logs for suspicious activity
None of the above
A security team investigates a cyberattack on a hospital’s electronic health record (EHR) system. The incident reveals that an attacker gained unauthorized access, exfiltrated sensitive patient data, modified medical records, and then deployed ransomware that locked all user access to the system.
Which security principle(s) has/have been violated?
Loss of confidentiality
All of the above
Loss of integrity
Loss of availability
A security analyst is investigating an anomalous spike in outbound traffic from a database server. Further analysis reveals that an attacker exploited a misconfigured application to escalate privileges, extract sensitive customer data, and exfiltrate it using an encrypted tunnel. The attack was undetected for several days despite SIEM monitoring.
Which of the following is the MOST critical security control that could have mitigated this attack?
Implementing network segmentation to restrict lateral movement
Deploying behavioral-based anomaly detection in SIEM
Enforcing least privilege access and role-based authentication
Using data loss prevention (DLP) to monitor sensitive information movement
