wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

CySA+Sy Test 03

Total questions: 43

Worksheet time: 1hrs 26mins

Name
Class
Date
1.

Ty is reviewing the scan report for a Windows system joined to his organization’s domain and finds the vulnerability shown here. What should be Ty’s most significant concern related to this vulnerability?

a)

The presence of this vulnerability indicates that an attacker may have compromised his

network.

b)

The presence of this vulnerability indicates a misconfiguration on the target server.

c)

The presence of this vulnerability indicates that the domain security policy may be lacking

appropriate controls.

d)

The presence of this vulnerability indicates a critical flaw on the target server that must

be addressed immediately.

2.

Heidi runs a vulnerability scan of the management interface of her organization’s virtualization platform and finds the severity 1 vulnerability shown here. What circumstance, if present, should increase the severity level of this vulnerability to Heidi?

a)

Lack of encryption

b)

Missing security patch

c)

Exposure to external networks

d)

Out-of-date antivirus signatures

3.

Rowan ran a port scan against a network switch located on her organization’s internal network and discovered the results shown here. She ran the scan from her workstation on the employee VLAN. Which one of the following results should be of greatest concern to her?

a)

Port 22

b)

Port 23

c)

Port 80

d)

Ports 8192 to 8194

4.

Evan is troubleshooting a vulnerability scan issue on his network. He is conducting an external scan of a website located on the web server shown in the diagram. After checking the web server logs, he saw no sign of the scan requests. Which one of the following causes is the least likely issue for him to troubleshoot?

a)

The scans are being blocked by an intrusion prevention system.

b)

The scans are being blocked by a rule within the web server application.

c)

The scans are being blocked by a network firewall.

d)

The scans are being blocked by a host firewall.

5.

Sam is looking for evidence of software that was installed on a Windows system. He believes that the programs were deleted and that the suspect used both registry and log cleaners to hide evidence. What Windows feature can’t he use to find evidence of the use of these programs?

a)

The MFT

b)

Volume shadow copies

c)

The shim (application compatibility) cache

d)

Prefetch files

6.

Mila is evaluating the security of an application developed within her organization. She would like to assess the application’s security by supplying it with invalid inputs. What technique is Mila planning to use?

a)

Fault injection

b)

Stress testing

c)

Mutation testing

d)

Fuzz testing

7.

A port scan conducted during a security assessment shows the following results. What type of device has most likely been scanned?

--View Image--

a)

A wireless access point

b)

A server

c)

A printer

d)

A switch

8.

Which of the following is not one of the major categories of security event indicators

described by NIST 800-61?

a)

Alerts from IDS, IPS, SIEM, AV, and other security systems

b)

Logs generated by systems, services, and applications

c)

Exploit developers

d)

Internal and external sources

9.

During an nmap scan of a network, Charles receives the following response from nmap:

Starting Nmap 7.80 ( https://nmap.org )

Nmap done: 256 IP addresses (0 hosts up) scanned in 29.74 seconds

What can Charles deduce about the network segment from these results?

a)

There are no active hosts in the network segment.

b)

All hosts on the network segment are firewalled.

c)

The scan was misconfigured.

d)

Charles cannot determine if there are hosts on the network segment from this scan.

10.

Oskar is designing a vulnerability management program for his company, a hosted service

provider. He would like to check all relevant documents for customer requirements that

may affect his scanning. Which one of the following documents is least likely to contain this

information?

a)

BPA

b)

SLA

c)

MOU

d)

BIA

11.

During a port scan of a server, Gwen discovered that the following ports are open on the

internal network:

TCP port 25.

TCP port 80.

TCP port 110.

TCP port 443.

TCP port 1521.

TCP port 3389.

Of the services listed here, for which one does the scan not provide evidence that it is likely

running on the server?

a)

Web

b)

Database

c)

SSH

d)

Email

12.

As part of her forensic analysis of a wiped thumb drive, Selah runs Scalpel to carve data from the image she created. After running Scalpel, she sees the following in the audit.log file created by the program. What should Selah do next?

a)

Run a data recovery program on the drive to retrieve the files.

b)

Run Scalpel in filename recovery mode to retrieve the actual filenames and directory

structures of the files.

c)

Review the contents of the scalpelout folder.

d)

Use the identified filenames to process the file using a full forensic suite.

13.

Lonnie ran a vulnerability scan of a server that he recently detected in his organization that is not listed in the organization’s configuration management database. One of the vulnerabilities detected is shown here. What type of service is most likely running on this server?

a)

Database

b)

Web

c)

Time

d)

Network management

14.

Jorge would like to use a standardized system for evaluating the severity of security

vulnerabilities. What SCAP component offers this capability?

a)

CPE

b)

CVE

c)

CVSS

d)

CCE

15.

When performing threat-hunting activities, what are cybersecurity analysts most directly seeking?

a)

Vulnerabilities

b)

Indicators of compromise

c)

Misconfigurations

d)

Unpatched systems

16.

Taylor is preparing to run vulnerability scans of a web application server that his organization recently deployed for public access. He would like to understand what information is available to a potential external attacker about the system as well as what damage an attacker might be able to cause on the system. Which one of the following scan types would be least likely to provide this type of information?

a)

Internal network vulnerability scan

b)

Port scan

c)

Web application vulnerability scan

d)

External network vulnerability scan

17.

While analyzing a packet capture in Wireshark, Chris finds the packet shown here. Which of the following is he unable to determine from this packet?

a)

That the username used was gnome

b)

That the protocol used was FTP

c)

That the password was gnome123

d)

That the remote system was 137.30.120.40

18.

Cynthia’s review of her network traffic focuses on the graph shown here. What occurred in late June?

a)

Beaconing

b)

High network bandwidth consumption

c)

A denial-of-

service

attack

d)

A link failure

19.

Carlos arrived at the office this morning to find a subpoena on his desk requesting electronic records in his control. What type of procedure should he consult to determine appropriate next steps, including the people he should consult and the technical process he should follow?

a)

Evidence production procedure

b)

Monitoring procedure

c)

Data classification procedure

d)

Patching procedure

20.

Which stage of the incident response process includes activities such as adding IPS signatures to detect new attacks?

a)

Detection and analysis

b)

Containment, eradication, and recovery

c)

Postincident activity

d)

Preparation

21.

Gloria is configuring vulnerability scans for a new web server in her organization. The server is located on the screened subnet (DMZ) network, as shown here. What type of scans should Gloria configure for best results?

--View Image--

a)

Gloria should not scan servers located in the screened subnet (DMZ).

b)

Gloria should perform only internal scans of the server.

c)

Gloria should perform only external scans of the server.

d)

Gloria should perform both internal and external scans of the server.

22.

Pranab is preparing to reuse media that contained data that his organization classifies as having “moderate” value. If he wants to follow NIST SP 800-88’s guidelines, what should he do to the media if the media will not leave his organization’s control?

a)

Reformat it

b)

Clear it

c)

Purge it

d)

Destroy it

23.

Susan is building an incident response program and intends to implement NIST’s recommended actions to improve the effectiveness of incident analysis. Which of the following items is not an NIST-recommended

incident analysis improvement?

a)

Perform behavioral baselining.

b)

Create and implement a logging policy.

c)

Set system BIOS/UEFI clocks regularly.

d)

Maintain an organizationwide system configuration database.

24.

Jim’s nmap port scan of a remote system showed the following list of ports:

--View Image--

What operating system is the remote system most likely running?

a)

Windows

b)

Linux

c)

An embedded OS

d)

macOS

25.

Helen is seeking to protect her organization against attacks that involve the theft of user credentials.

In most organizations, which one of the following threats poses the greatest risk of

credential theft?

a)

DNS poisoning

b)

Phishing

c)

Telephone-based

social engineering

d)

Shoulder surfing

26.

As part of her duties as a security operations center (SOC) analyst, Emily is tasked with monitoring intrusion detection sensors that cover her employer’s corporate headquarters network. During her shift, Emily’s IDS reports that a network scan has occurred from a system with IP address 10.1. 1.19 on the organization’s unauthenticated guest wireless network aimed at systems on an external network. What should Emily’s first step be?

a)

Report the event to the impacted third parties.

b)

Report the event to law enforcement.

c)

Check the system’s MAC address against known assets.

d)

Check authentication logs to identify the logged-in

user.

27.

Sai works in an environment that is subject to the Payment Card Industry Data Security Standard (PCI DSS). He realizes that technical constraints prevent the organization from meeting a specific PCI DSS requirement and wants to implement a compensating control. Which one of the following statements is not true about proper compensating controls?

a)

The control must include a clear audit mechanism.

b)

The control must meet the intent and rigor of the original requirement.

c)

The control must provide a similar level of defense as the original requirement provides.

d)

The control must be above and beyond other requirements.

28.

Lou recently scanned a web server in his environment and received the vulnerability report shown here. What action can Lou take to address this vulnerability?

--View Image--

a)

Configure TLS.

b)

Replace the certificate.

c)

Unblock port 443.

d)

Block port 80.

29.

Which of the following factors is not typically considered when determining whether evidence should be retained?

a)

Media life span

b)

Likelihood of civil litigation

c)

Organizational retention policies

d)

Likelihood of criminal prosecution

30.

Match each of the following with the appropriate element of the CIA triad:

1. A hard drive failure resulting in a service outage

2. A termination letter that is left on a printer and read by others in the department

3. Modification of an email’s content by a third party

a)

1. Integrity,

2. Availability,

3. Confidentiality

b)

1. Integrity,

2. Confidentiality,

3. Availability

c)

1. Availability,

2. Integrity,

3. Confidentiality

d)

1. Availability,

2. Confidentiality,

3. Integrity

31.

Niesha discovered the vulnerability shown here on a server running in her organization. What would be the best way for Niesha to resolve this issue?

--View Image--

a)

Disable the use of AES-GCM.

b)

Upgrade OpenSSH.

c)

Upgrade the operating system.

d)

Update antivirus signatures.

32.

As part of her postincident recovery process, Alicia creates a separate virtual network as shown here to contain compromised systems she needs to investigate. What containment technique is she using?

a)

Segmentation

b)

Isolation

c)

Removal

d)

Reverse engineering

33.

Jennifer is reviewing her network monitoring configurations and sees the following chart for a system she runs remotely in Amazon’s Web Services (AWS) environment more than 400 miles away. What can she use this data for?

a)

Incident response; she needs to determine the issue causing the spikes in response time.

b)

The high packet loss must be investigated, since it may indicate a denial-of-service attack

c)

She can use this data to determine a reasonable response time baseline.

d)

The high response time must be investigated, since it may indicate a denial-of-service attack

34.

The Windows system that Abdul is conducting live forensics on shows a partition map, as shown here. If Abdul believes that a hidden partition was deleted resulting in the unallocated space, which of the following type of tool is best suited to identifying the data found in the unallocated space?

a)

File carving

b)

Wiping

c)

Partitioning

d)

Disk duplication

35.

During a postmortem forensic analysis of a Windows system that was shut down after its user saw strange behavior, Pranab concludes that the system he is reviewing was likely infected with a memory-resident

malware package. What is his best means of finding the malware?

a)

Search for a core dump or hibernation file to analyze.

b)

Review the INDX files and Windows registry for signs of infection.

c)

Boot the system and then use a tool like the Volatility Framework to capture

live memory.

d)

Check volume shadow copies for historic information prior to the reboot.

36.

Juliette’s organization recently suffered a cross-site scripting attack, and she plans to implement input validation to protect against the recurrence of such attacks in the future. Which one of the following HTML tags should be most carefully scrutinized when it appears in user input?

a)

<SCRIPT>

b)

<XSS>

c)

<B>

d)

<EM>

37.

Jessie needs to prevent port scans like the scan shown here. Which of the following is a valid method for preventing port scans?

--View Image--

a)

Not registering systems in DNS

b)

Using a firewall to restrict traffic to only ports required for business purposes

c)

Using a heuristic detection rule on an IPS

d)

Implementing port security

38.

What information can be gathered by observing the distinct default values of the following TCP/IP fields during reconnaissance activities: initial packet size, initial TTL, window size, maximum segment size, and flags?

a)

The target system’s TCP version.

b)

The target system’s operating system.

c)

The target system’s MAC address.

d)

These fields are useful only for packet analysis.

39.

Brooke would like to find a technology platform that automates workflows across a variety of security tools, including the automated response to security incidents. What category of tool best meets this need?

a)

SIEM

b)

NIPS

c)

SOAR

d)

DLP

40.

Miray needs to identify the device or storage type that has the lowest order of volatility.

Which of the following is the least volatile?

a)

Network traffic

b)

A solid-state

drive

c)

A spinning hard drive

d)

A DVD-ROM

41.

After receiving complaints about a system on Anastasia’s network not performing correctly, she decides to investigate the issue by capturing traffic with Wireshark. The captured traffic is shown here. What type of issue is Anastasia most likely seeing?

a)

A link failure

b)

A failed three-way

handshake

c)

A DDoS

d)

A SYN flood

42.

After finishing a forensic case, Lucas needs to wipe the media that he is using to prepare it for the next case. Which of the following methods is best suited to preparing the SSD that he will use?

a)

Degauss the drive.

b)

Zero-write

the drive.

c)

Use a PRNG.

d)

Use the ATA Secure Erase command.

43.

Luis is creating a vulnerability management program for his company. He only has the resources to conduct daily scans of approximately 10 percent of his systems, and the rest will be scheduled for weekly scans. He would like to ensure that the systems containing the most sensitive information receive scans on a more frequent basis. What criterion is Luis using?

a)

Data privacy

b)

Data remanence

c)

Data retention

d)

Data classification