wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CySA+ Days 1 - 3

Total questions: 37

Worksheet time: 19mins

Name
Class
Date
1.

What type of Risk Response should be chosen to reduce the likelihood or impact of a risk?

a)

Accept

b)

Mitigate

c)

Transfer

d)

Avoid

2.

What type of Risk Response aligns with purchasing cybersecurity insurance?

a)

Avoid

b)

Accept

c)

Mitigate

d)

Transfer

3.

Gaining unauthorized access into a company's network is considered a (blank).

a)

Tacitc

b)

Technique

c)

Procedure

d)

Good time

4.

What type of Compensating Control refers to day-to-day procedures that maintain security?

a)

Managerial

b)

Operational

c)

Technical

d)

Preventative

5.

Which Security Control is used to identify and alert on security incidents as they happen?

a)

Corrective

b)

Responsive

c)

Detective

d)

Preventive

6.

Footprinting or Fingerprinting? Gathering open-source information about a target system or network to identify potential vulnerabilities.

a)

Footprinting

b)

Fingerprinting

7.

Footprinting or Fingerprinting? Determining the specific details of the target system, such as the OS and application versions, to understand its configuration and potential weaknesses.

a)

Footprinting

b)

Fingerprinting

8.

Penetration Testing or Adversary Emulation? Mimicking/replicating the TTPs of actual, real-world attackers to test an organization's defenses.

a)

Pen Testing

b)

Adversary Emulation

9.

Which is the correct order of the Patching & Configuration Management Process?

a)

Testing, Validation, Implementation, Rollback

b)

Implementation, Testing, Rollback, Validation

c)

Testing, Implementation, Rollback, Validation

d)

Validation, Testing, Implementation, Rollback

10.

What is the term that describes a scheduled timeframe when technicians would perform a backup generator test?

a)

Planned Outage

b)

Unplanned Outage

c)

Maintenance Window

d)

Off-peak hours maintenance

11.

True or False? Patching tools are often cross-platform compatible, meaning you do not need separate patching tools for Windows, Linux, macOS, etc.

a)

True

b)

False

12.

This term describes a specific, measurable target that defines the level of service expected from our coworkers for a particular aspect, such as an uptime rate of 99.99%.

a)

Service Level Objective (SLO)

b)

Service Level Agreement (SLA)

13.

This term describes raising issues to higher authorities or more senior staff members when necessary.

a)

Prioritization

b)

Escalation

c)

Exemption

d)

Transferrence

14.

This term describes a monetary incentive for ethical hackers to find and report vulnerabilities in an organization's systems or software.

a)

Penetration Testing

b)

Adversary Emulation

c)

Bug Bounty

d)

Exploitation

15.

This strategic framework for understanding and preventing cyberattacks was developed by Lockheed Martin, and is a structured approach to breaking down the stages of an attack.

a)

MITRE ATT&CK

b)

MISP

c)

Cyber Kill Chain

d)

OWASP

16.

This intrusion analysis framework focuses on the Adversary, Capability, Victim & Infrastructure.

a)

MITRE ATT&CK

b)

Diamond Model

c)

MISP

d)

Cyber Kill Chain

17.

This framework is a comprehensive knowledge base that contains the tactics and techniques of actual cyber adversaries and real-world attacks that happened in the past.

a)

Cyber Kill Chain

b)

MITRE ATT&CK

c)

OWASP

d)

Diamond Model

18.

True or False? The Open-Source Security Testing Methodology Manual (OSS TMM) is a manual that you can download to help you with security assessments.

a)

True

b)

False

19.

True or False? A user that unintentionally clicked on a fraudulent URL in an email is known as an Insider Threat

a)

True

b)

False

20.

This term refers to the part of the internet that is not indexed (not searchable), such as a password-protected website.

a)

Paid Feed

b)

Deep Web

c)

Dark Web

d)

Dark Net

21.

True or False? The Information Sharing and Analysis Centers (ISACs) are non-profit organizations that provide a central resource for gathering and sharing information on cyber threats that affect the nation's critical infrastructure.

a)

True

b)

False

22.

What metric helps rank or score threat intelligence to indicate the reliability, timeliness and relevance of the data?

a)

Confidence level

b)

Threat reliability level

c)

Quality / Quantity

d)

Relevence

23.

Is a Honeypot a form of active or passive defense?

a)

Active

b)

Passive

24.

Which is the correct order of the Cyber Incident Response Cycle?

a)

Preparation, Identification, Containment, Eradication, Recovery

b)

Identification, Preparation, Containment, Eradication, Recovery

c)

Preparation, Identification, Eradication, Containment, Recovery

d)

IDK... my bacon's burning.

25.

What is the acronym that describes intelligence gathered from publicly available sources, such as social media?

(a)  

26.

Considering Digital Forensics, what term describes detailed, real-time records taken by forensic examiners that document every step of the examination process, including observations, actions taken, and any findings?

a)

Chain of Custody

b)

Field Notes

c)

Forensically sound documentation

d)

Legal hold

27.

If I want to see guidelines for more than 100 secure configurations for 25+ vendor products families, where would I want to look?

a)

DoD/DISA STIGs

b)

MITRE ATT&CK

c)

OWASP

d)

CIS Benchmarks

28.

True or False? Unlike containers, multiple VMs share the host OS, making them more lightweight and faster to start.

a)

True

b)

False

29.

Which type of Hypervisor is known as a "bare metal" device (one big BEEFY server)?

a)

Type I

b)

Type II

c)

Type III

d)

Type IV

30.

Which Cloud Deployment Model states that the CSP handles the most responsibility?

a)

IaaS

b)

PaaS

c)

SaaS

d)

IaC

31.

What is the term to describe a shift in mindset that no longer relies solely on a secure network boundary, but focuses on Zero Trust?

a)

Remote Work Policy

b)

VPN

c)

Deperimeterization

d)

Defense in Depth

32.

Which Logging Level is more severe: WARN or ERROR

a)

ERROR

b)

WARN

33.

Which security mechanism controls and monitors access to accounts that have elevated permissions?

a)

IAM

b)

PAM

c)

PAL

d)

IAC

34.

Which of the following accurately describes penetration testing?

a)

Automated scanning of systems for vulnerabilities

b)

Simulating real-world attacks to identify system weaknesses

c)

Conducting security audits to ensure compliance

d)

Testing the rigidity of direct-bury cables for long-haul communications

35.

Penetration testing involves:

a)

Passive analysis of system vulnerabilities

b)

Active exploitation of vulnerabilities to assess security

c)

Monitoring system logs for suspicious activity

d)

None of the above

36.

A security team investigates a cyberattack on a hospital’s electronic health record (EHR) system. The incident reveals that an attacker gained unauthorized access, exfiltrated sensitive patient data, modified medical records, and then deployed ransomware that locked all user access to the system.

Which security principle(s) has/have been violated?

a)

Loss of confidentiality

b)

All of the above

c)

Loss of integrity

d)

Loss of availability

37.

A security analyst is investigating an anomalous spike in outbound traffic from a database server. Further analysis reveals that an attacker exploited a misconfigured application to escalate privileges, extract sensitive customer data, and exfiltrate it using an encrypted tunnel. The attack was undetected for several days despite SIEM monitoring.

Which of the following is the MOST critical security control that could have mitigated this attack?

a)

Implementing network segmentation to restrict lateral movement

b)

Deploying behavioral-based anomaly detection in SIEM

c)

Enforcing least privilege access and role-based authentication

d)

Using data loss prevention (DLP) to monitor sensitive information movement