wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CySA+ Days 4-6

Total questions: 42

Worksheet time: 1hrs 14mins

Name
Class
Date
1.

This framework is designed to manage digital certificates, keys, and other security credentials to secure communication, verify the authenticity of parties involved in communication, and facilitate the exchange of encrypted data.

a)

PKI

b)

Certificate Authority (CA)

c)

Root CA

d)

Cryptographic Solutions

2.

This term describes the process of intercepting and decrypting TLS-encrypted internet traffic to analyze its contents.

a)

SSL Inspection

b)

Deep Packet Inspection

c)

Packet Sniffing

d)

Packet Analyzing

3.

Print Blocking and Clipboard Privacy Controls are examples of which concept?

a)

RDP

b)

DLP

c)

IAM

d)

PAM

4.

What is the acronym for the 3-digt security code on the back of a Master Card credit card?

a)

CVS

b)

CVE

c)

CVV

d)

PIN

5.

This solution combines security orchestration, automation, and incident response.

a)

SOAR

b)

SIEM

c)

Splunk

d)

WAF

6.

Which tool helps to simplify identifying, analyzing, and responding to security threats, especially for events contained within log data?

a)

SOAR

b)

Wireshark

c)

SIEM

d)

Log Jam

7.

If a technician gathers further details about a piece of threat intelligence to make that intel better, what is this called?

a)

Data Fortification

b)

Data Masking

c)

Data Tokenization

d)

Data Enrichment

8.

SOAR solutions use (blank) to automate routine tasks and ensure consistent procedures.

a)

Gameplans

b)

Playbooks

c)

Automated Rules

d)

Predefined Procedures

9.

Augmented security data is also known as...

a)

Enhanced Data

b)

Enriched Data

c)

Contextual Data

d)

Metadata

10.

A new, extended capability or function of a program or application is known as a... (CHOOSE FOUR!)

a)

Add-on

b)

Extension

c)

Plug-in

d)

Widget

11.

Which protocol(s) do APIs mostly use to allow two or more security tools to share data seamlessly?

a)

FTP

b)

SSL/TLS

c)

HTTP/HTTPS

d)

SSH

12.

This term refers to a centralized platform or interface that allows security professionals to monitor and control various security components and tools from a single location.

a)

Kiosk

b)

Unified Platform

c)

Single Pane of Glass

d)

Network Management System (NMS)

13.

What types of "requests" do APIs use to allow software applications to communicate with each other?

a)

SYN, ACK, SYN-ACK

b)

GET, POST, PUT, DELETE

c)

READ, WRITE, EXECUTE

d)

LINK, SYNC, TERMINATE

14.

What is a Webhook?

a)

A webhook is a user interface design that prompts for administrative credentials when trying to access a CEOs personal files.

b)

A webhook is a type of database that triggers alerts when an attacker attempts to exfiltrate data from it.

c)

A webhook is a programming language that allows one system to receive alerts from ICS devices.

d)
A webhook is a mechanism that allows one system to send real-time data to another system via HTTP requests when certain events occur.
15.

Which control system architecture combines hardware and software to facilitate the centralized monitoring, control, and automation of industrial processes in real-time?

a)

ICS

b)

PLC

c)

SCADA

d)

RTU

16.
What electronically verifies the ownership of a website, server, or individual?
a)
Digital Certificate
b)
Certificate Authority
c)
CRL
d)
OCSP
17.

(Blank) represents a category of Operational Technology (OT) responsible for managing and controlling industrial processes and critical infrastructure. Hint: it manages processes that involve physical components and machinery.

a)

ICS

b)

PLC

c)

ISACs

d)

IDK

18.

SCADA, PLC, and ICS are all examples of which technology?

a)

Industrial Technology

b)

Strategic Technology

c)

Critical Infrastructure Technology

d)

Operational Technology

19.

This term describes the effort taken to more specifically identify details about a device.

a)

Footprinting

b)

Passive Scanning

c)

Active Scanning

d)

Fingerprinting

20.

This term describes a cybersecurity practice that involves the examination of software or code without executing the application.

a)

Static Scanning

b)

Dynamic Scanning

c)

Reverse Engineering

d)

Fuzzing

21.

A software security analyst wants to see how a new application handles a large volume of random, unexpected, or malicious data input, in an effort to identify vulnerabilities in the source code. What is he/she conducting?

a)

Active Scanning

b)

Dynamic Scanning

c)

Fuzzing

d)

Reverse Engineering

22.

Which types of scanning methods consume more system resources on a target device, and may impact its performance? (Choose two)

a)

Active Scanning

b)

Credentialed Scanning

c)

Passive Scanning

d)

Non-Credentialed Scanning

23.

Big Tom Callahan would like to identify and categorize all devices and equipment connected to his network. He plans on using this information to keep an accurate inventory of hardware assets, and would also like to use it to understand potential security vulnerabilities on them. What should he perform?

a)

Network Sniffing

b)

Deep Packet Inspection

c)

Non-credentialed Scanning

d)

Asset Discovery

24.

Which Vulnerability Report Format would be the best choice if Malik wants to provide a visually appealing, interactive presentation of newly discovered vulnerabilities?

a)

CSV

b)

XML

c)

PDF

d)

HTML

25.

This term describes a long-term solution for vulnerabilities that cannot be patched.

a)

Exception

b)

Waiver

c)

Permanent Workaround

d)

Mitigation

26.

This type of Compliance Report is subject to government review and scrutiny.

a)

Certification Report

b)

Annual Compliance Report

c)

Regulatory Filing

d)

Non-compliant Report

27.

This term defines the expected level of service in terms of vulnerability management. Monitoring and reporting on these helps to ensure that the organization's employees meet its security goals.

a)

Service Level Objective (SLO)

b)

Memorandum of Understanding (MOU)

c)

Service Level Agreement (SLA)

d)

Key Performance Indicators (KPIs)

28.

These are measurable values that help an organization gauge how well it is achieving its key business objectives.

a)

Metrics

b)

Key Performance Indicators (KPIs)

c)

Milestones

d)

Business Indicators

29.

During an investigation, an incident response team attempts to understand the source of an incident. Which of the following incident response activities describes this process?

a)

Analysis

b)

Lessons learned

c)

Detection

d)

Containment

30.

What must a user have in order to decrypt a file?

a)

Coin

b)

Key

c)

Token

d)

The Decryptor 5000 found in most toy stores

31.

Which process involves transforming ciphertext into plaintext using a key

a)
encryption
b)
scrambling
c)
decryption
d)
encoding
32.

What provides direction and focus, enabling organizations to achieve strategic goals and objectives?

a)

KPIs

b)

Metrics

c)

Action Plan

d)

SOP

33.
What is a CA?
a)
A trusted third party that validates information.
b)
A database used to verify the status of a certificate
c)
A database used for real-time verification
d)
An established trust by linking certificates back to the root.
34.

A security administrator is deploying a DLP solution to prevent the exfiltration of different levels of sensitive customer data. Which of the following should the administrator do first?

a)

Block access to cloud storage websites

b)

Create a rule to block outgoing email attachments

c)

Apply classifications to the data

d)

Remove all user permissions from shares on the file server

35.

Negative Nate sees a vulnerability with a CVSS Base Score of 6.7. What Risk Score range does this fall in?

a)

Low Risk

b)

High Risk

c)

Medium Risk

d)

No Risk

36.

This Configuration Management (CM) function helps track changes to software or hardware components over time, facilitating rollback to previous states if needed.

a)

Change Control

b)

Configuration Baseline

c)

KPIs

d)

Version Control

37.

What is the name of a network protocol that secures web traffic via SSL/TLS encryption?

a)
SFTP
b)
HTTPS
c)
FTPS
d)
SNMP
38.

Which of the following is NOT a version of TLS?

a)

1.0

b)

1.2

c)

1.3

d)

1.4

39.

Which of the following approaches would best support the goal of minimizing human engagement in routine cybersecurity operations?

a)

Manual log review

b)

Implementing SOAR (Security Orchestration, Automation, and Response)

c)

Decreasing security controls

d)

Increasing staff numbers

40.

During an investigation, an incident response team led by Larry attempts to understand the source of an incident. Which of the following incident response activities describes this process?

a)

Analysis

b)

Lessons learned

c)

Detection

d)

Containment

41.

During the infamous Equifax data breach in 2017, it was revealed that a critical patch had not been applied to a vulnerable version of Apache Struts, allowing attackers to exploit the vulnerability. In the aftermath, Equifax implemented additional controls to monitor traffic to and from the servers hosting the vulnerable software. In this context, what kind of incident response activity is Equifax performing?

a)

Eradication

b)

Containment

c)

Implementing compensating controls

d)

Data and log analysis

42.

During a recent security incident, you, as an incident responder, documented each action and decision that took place, from the initial detection to final remediation. This detailed timeline could prove particularly useful for which part of the incident response reporting?

a)

Executive summary

b)

Scope

c)

Lessons learned

d)

Impact