Font size
WorksheetsCySA+ Days 4-6
Total questions: 42
Worksheet time: 1hrs 14mins
This framework is designed to manage digital certificates, keys, and other security credentials to secure communication, verify the authenticity of parties involved in communication, and facilitate the exchange of encrypted data.
PKI
Certificate Authority (CA)
Root CA
Cryptographic Solutions
This term describes the process of intercepting and decrypting TLS-encrypted internet traffic to analyze its contents.
SSL Inspection
Deep Packet Inspection
Packet Sniffing
Packet Analyzing
Print Blocking and Clipboard Privacy Controls are examples of which concept?
RDP
DLP
IAM
PAM
What is the acronym for the 3-digt security code on the back of a Master Card credit card?
CVS
CVE
CVV
PIN
This solution combines security orchestration, automation, and incident response.
SOAR
SIEM
Splunk
WAF
Which tool helps to simplify identifying, analyzing, and responding to security threats, especially for events contained within log data?
SOAR
Wireshark
SIEM
Log Jam
If a technician gathers further details about a piece of threat intelligence to make that intel better, what is this called?
Data Fortification
Data Masking
Data Tokenization
Data Enrichment
SOAR solutions use (blank) to automate routine tasks and ensure consistent procedures.
Gameplans
Playbooks
Automated Rules
Predefined Procedures
Augmented security data is also known as...
Enhanced Data
Enriched Data
Contextual Data
Metadata
A new, extended capability or function of a program or application is known as a... (CHOOSE FOUR!)
Add-on
Extension
Plug-in
Widget
Which protocol(s) do APIs mostly use to allow two or more security tools to share data seamlessly?
FTP
SSL/TLS
HTTP/HTTPS
SSH
This term refers to a centralized platform or interface that allows security professionals to monitor and control various security components and tools from a single location.
Kiosk
Unified Platform
Single Pane of Glass
Network Management System (NMS)
What types of "requests" do APIs use to allow software applications to communicate with each other?
SYN, ACK, SYN-ACK
GET, POST, PUT, DELETE
READ, WRITE, EXECUTE
LINK, SYNC, TERMINATE
What is a Webhook?
A webhook is a user interface design that prompts for administrative credentials when trying to access a CEOs personal files.
A webhook is a type of database that triggers alerts when an attacker attempts to exfiltrate data from it.
A webhook is a programming language that allows one system to receive alerts from ICS devices.
Which control system architecture combines hardware and software to facilitate the centralized monitoring, control, and automation of industrial processes in real-time?
ICS
PLC
SCADA
RTU
(Blank) represents a category of Operational Technology (OT) responsible for managing and controlling industrial processes and critical infrastructure. Hint: it manages processes that involve physical components and machinery.
ICS
PLC
ISACs
IDK
SCADA, PLC, and ICS are all examples of which technology?
Industrial Technology
Strategic Technology
Critical Infrastructure Technology
Operational Technology
This term describes the effort taken to more specifically identify details about a device.
Footprinting
Passive Scanning
Active Scanning
Fingerprinting
This term describes a cybersecurity practice that involves the examination of software or code without executing the application.
Static Scanning
Dynamic Scanning
Reverse Engineering
Fuzzing
A software security analyst wants to see how a new application handles a large volume of random, unexpected, or malicious data input, in an effort to identify vulnerabilities in the source code. What is he/she conducting?
Active Scanning
Dynamic Scanning
Fuzzing
Reverse Engineering
Which types of scanning methods consume more system resources on a target device, and may impact its performance? (Choose two)
Active Scanning
Credentialed Scanning
Passive Scanning
Non-Credentialed Scanning
Big Tom Callahan would like to identify and categorize all devices and equipment connected to his network. He plans on using this information to keep an accurate inventory of hardware assets, and would also like to use it to understand potential security vulnerabilities on them. What should he perform?
Network Sniffing
Deep Packet Inspection
Non-credentialed Scanning
Asset Discovery
Which Vulnerability Report Format would be the best choice if Malik wants to provide a visually appealing, interactive presentation of newly discovered vulnerabilities?
CSV
XML
HTML
This term describes a long-term solution for vulnerabilities that cannot be patched.
Exception
Waiver
Permanent Workaround
Mitigation
This type of Compliance Report is subject to government review and scrutiny.
Certification Report
Annual Compliance Report
Regulatory Filing
Non-compliant Report
This term defines the expected level of service in terms of vulnerability management. Monitoring and reporting on these helps to ensure that the organization's employees meet its security goals.
Service Level Objective (SLO)
Memorandum of Understanding (MOU)
Service Level Agreement (SLA)
Key Performance Indicators (KPIs)
These are measurable values that help an organization gauge how well it is achieving its key business objectives.
Metrics
Key Performance Indicators (KPIs)
Milestones
Business Indicators
During an investigation, an incident response team attempts to understand the source of an incident. Which of the following incident response activities describes this process?
Analysis
Lessons learned
Detection
Containment
What must a user have in order to decrypt a file?
Coin
Key
Token
The Decryptor 5000 found in most toy stores
Which process involves transforming ciphertext into plaintext using a key
What provides direction and focus, enabling organizations to achieve strategic goals and objectives?
KPIs
Metrics
Action Plan
SOP
A security administrator is deploying a DLP solution to prevent the exfiltration of different levels of sensitive customer data. Which of the following should the administrator do first?
Block access to cloud storage websites
Create a rule to block outgoing email attachments
Apply classifications to the data
Remove all user permissions from shares on the file server
Negative Nate sees a vulnerability with a CVSS Base Score of 6.7. What Risk Score range does this fall in?
Low Risk
High Risk
Medium Risk
No Risk
This Configuration Management (CM) function helps track changes to software or hardware components over time, facilitating rollback to previous states if needed.
Change Control
Configuration Baseline
KPIs
Version Control
What is the name of a network protocol that secures web traffic via SSL/TLS encryption?
Which of the following is NOT a version of TLS?
1.0
1.2
1.3
1.4
Which of the following approaches would best support the goal of minimizing human engagement in routine cybersecurity operations?
Manual log review
Implementing SOAR (Security Orchestration, Automation, and Response)
Decreasing security controls
Increasing staff numbers
During an investigation, an incident response team led by Larry attempts to understand the source of an incident. Which of the following incident response activities describes this process?
Analysis
Lessons learned
Detection
Containment
During the infamous Equifax data breach in 2017, it was revealed that a critical patch had not been applied to a vulnerable version of Apache Struts, allowing attackers to exploit the vulnerability. In the aftermath, Equifax implemented additional controls to monitor traffic to and from the servers hosting the vulnerable software. In this context, what kind of incident response activity is Equifax performing?
Eradication
Containment
Implementing compensating controls
Data and log analysis
During a recent security incident, you, as an incident responder, documented each action and decision that took place, from the initial detection to final remediation. This detailed timeline could prove particularly useful for which part of the incident response reporting?
Executive summary
Scope
Lessons learned
Impact
