Font size
WorksheetsCySA+ Day 1-4
Total questions: 35
Worksheet time: 35mins
Arthur is working at a company and he is looking at a vulnerability. This vulnerability, if exploited, would give the threat actor access to a file server on a honeynet. Arthur decides that he wants to keep the vulnerability as it does not lead to any more issues. What is Arthur's risk response?
Accept
Avoid
Mitigate
Transfer
Which risk response means to eliminate risks by not engaging in activities that pose the risk?
(a)
Which of the following best describe Mitigate and Transfer?
Transferring risk means to shift the risk on to a coworker
Mitigate risk means to buy insurance to prevent the risk
Transferring risk means to shift the risk to a third party like insurance
Mitigate risk means to control or reduce risk through security measures
None of the above
Cloudflare hired a new intern, Alvin, and his saw a bunch of machines needed updates. He decided to update everything. Once the updates started, he locked his computer, and went to lunch.
What did Alvin forget to do? (Select Multiple)
Testing
Rollback Plan
Validation
None of the options
A security analyst plans to deploy a critical patch across 200 production servers. The operations team insists that business applications must remain available during peak hours. Which of the following is the best action for the analyst to take?
Push the patch immediately to reduce vulnerability exposure
Schedule the patch deployment during the approved maintenance window
Apply the patch to half the servers during peak hours to avoid full downtime
Delay patching until the next quarterly update cycle
During an investigation, an analyst sees the attacker scanned ports 21, 22, 80, 443, and 3389. What phase of the attack does this activity most closely represent?
Fingerprinting
Footprinting
Obfuscation
Gaining access
A security analyst wants to build an inventory of all systems on the network without sending packets to end devices. Which technique should the analyst use?
Active Scanning
Passive Discovery
Edge Discovery
Credentialed Scan
A company wants to evaluate whether the SOC can detect lateral movement and privilege escalation techniques used by real-world attackers. Which engagement is MOST appropriate?
Vulnerability scan
Pen Testing
Adversary Emulation
Bug Bounty
A monitoring dashboard shows that a web application maintained 99.4% availability over the last 30 days. What does this metric represent?
SLA
SLO
SLI
MOU
An internal IT team commits to keeping authentication latency below 200 ms for internal apps. This is not legally binding but is used for performance tracking. What is this commitment called?
SLA
SLO
SLI
QoS requirement
A developer modifies a login page so that the username field only accepts letters and numbers. If the user enters symbols like " ; " or " ' ", the request is rejected. What security control is being used?
Output encoding
Blacklist filtering
Input Validation
Encoding at runtime
A security team identifies the attacker’s infrastructure, including their C2 servers and VPN exit nodes. Which Diamond Model component does this describe?
Victim
Adversary
Infrastructure
Capability
If you want to a manual on security testing and assessment, which of the following would offer you a systematic approach?
Cyber Kill Chain
OSSTMM
OWASP Testing Guide
MITRE ATT&CK Framework
A SOC analyst receives threat intelligence indicating that a phishing campaign is targeting the company. The report assigns a high confidence level to the indicators. Which of the following BEST describes what this confidence level indicates?
The analyst must block all traffic related to the indicators immediately
The source believes the indicators are very likely accurate, based on corroborated evidence
The indicators are legally binding for enforcement
The intelligence can be ignored because confidence is subjective
A SOC analyst collects IP addresses, domains, and malware hashes from publicly available blogs, Twitter feeds, and threat forums. Which type of intelligence is this?
OSINT
Closed-Source intelligence
Dark web intelligence
Tactical intelligence
Analysts are searching Tor forums and underground marketplaces for indicators of compromised credentials or leaked customer data. Which type of intelligence are they gathering?
OSINT
Closed-source Intelligence
Deep/dark web intelligence
None
A SOC analyst receives a report indicating a new ransomware variant targeting financial institutions. The analyst uses this report to update detection rules and monitor systems. What activity is this?
Threat Hunting
Threat Intelligence
Incident Response
Vulnerability scanning
A SOC analyst notices unusual lateral movement in the network that has not been previously reported. They proactively investigate endpoints and logs to find hidden malware. What activity is this?
(a)
A SOC team deploys honeypots to attract attackers and learn their methods before they reach production systems. Which type of active defense is this?
Reactive
Proactive
Detective
Complaince
After detecting ransomware encrypting files, the SOC team immediately isolates the infected host and restores backups. What type of defense is this?
Proactive
Reactive
Detective
Preventive
A SOC team configures endpoints to send logs to a central SIEM for analysis. Which term BEST describes this process?
Log Aggregation
Log Parsing
Log Ingestion
Log Correlation
An analyst notices that logs from multiple servers show inconsistent timestamps. Which configuration must be verified to correct this issue?
Syslog levels
NTP server setting
Log retention policy
SIEM parsing rules
A company implements a policy where users must authenticate and be authorized every time they access any resource, regardless of network location. Which security model does this describe?
Traditional Perimeter Security
ZTA
Defense in Depth
Role-based access control
Which of the following is typically included in a SUSE deployment?
CASB
SWG
FWaaS
None of the above
CASB, SWG and FWaaS are correct
Luke Skyrunner was able to log in once this morning and access his email, VPN, and HR system without entering credentials again. What is this an example of?
Federation
SSO
MFA
PAM
Becky was using her corporate credentials to log in to third-party SaaS applications without creating a separate account. Which technology is being used?
PAM
Federation
MFA
Passwordless authentication
A company wants to monitor and enforce security policies for employees using multiple cloud applications. Which solution BEST fits this requirement?
SIEM
CASB
VPN
Firewall
Which of the following actions is not typically performed by a DLP system?
Blocking emails containing credit card numbers
Encrypting sensitive files at rest
Detecting unauthorized cloud uploads
Performing vulnerability scans on endpoints
Which of the following characteristics makes a task a good candidate for automation?
Complex decision-making, requiring judgement
Repetitive, rule-based, and high coluume
Unique, one-off investigative tasks
Strategic planning
A company integrates its SIEM, endpoint detection system, and firewall on a platform. When an alert triggers, the platform automatically collects logs, enriches the alert with TI data, and blocks malicious IPs. This is an example of:
SIEM
SOAR
NGFW
CASB
A SOC analyst receives an alert about a suspicious IP. The security system automatically queries threat intelligence feeds, malware databases, and related domains to provide additional context. What is this process called?
OSINT
Log aggregation
Data enrichment
Patch Management
A webhook is MOST useful in which of the following cases?
When a system needs to request updates on a schedule
When immediate, event-driven notifications are required
When a security product needs additional parsing features
When data must be transferred using an agent
A security team wants to identify all devices on its network, including unauthorized IoT devices that employees may have connected without approval. Which technique is MOST appropriate?
External Vulnerability scan
Asset Discovery scan
Patch Management scan
SIEM alert correlation
A vulnerability scanner logs into a Linux server using SSH keys and examines configuration files, patch levels, and installed software versions. This is an example of:
Non-credentialed scan
Credentialed scan
Agentless
Stealth Scan
True or False: Agentless Scanning requires the installation of software or network devices in order to complete the scan.
True
False
