wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CySA+ Day 1-4

Total questions: 35

Worksheet time: 35mins

Name
Class
Date
1.

Arthur is working at a company and he is looking at a vulnerability. This vulnerability, if exploited, would give the threat actor access to a file server on a honeynet. Arthur decides that he wants to keep the vulnerability as it does not lead to any more issues. What is Arthur's risk response?

a)

Accept

b)

Avoid

c)

Mitigate

d)

Transfer

2.

Which risk response means to eliminate risks by not engaging in activities that pose the risk?

(a)  

3.

Which of the following best describe Mitigate and Transfer?

a)

Transferring risk means to shift the risk on to a coworker

b)

Mitigate risk means to buy insurance to prevent the risk

c)

Transferring risk means to shift the risk to a third party like insurance

d)

Mitigate risk means to control or reduce risk through security measures

e)

None of the above

4.

Cloudflare hired a new intern, Alvin, and his saw a bunch of machines needed updates. He decided to update everything. Once the updates started, he locked his computer, and went to lunch.

What did Alvin forget to do? (Select Multiple)

a)

Testing

b)

Rollback Plan

c)

Validation

d)

None of the options

5.

A security analyst plans to deploy a critical patch across 200 production servers. The operations team insists that business applications must remain available during peak hours. Which of the following is the best action for the analyst to take?

a)

Push the patch immediately to reduce vulnerability exposure

b)

Schedule the patch deployment during the approved maintenance window

c)

Apply the patch to half the servers during peak hours to avoid full downtime

d)

Delay patching until the next quarterly update cycle

6.

During an investigation, an analyst sees the attacker scanned ports 21, 22, 80, 443, and 3389. What phase of the attack does this activity most closely represent?

a)

Fingerprinting

b)

Footprinting

c)

Obfuscation

d)

Gaining access

7.

A security analyst wants to build an inventory of all systems on the network without sending packets to end devices. Which technique should the analyst use?

a)

Active Scanning

b)

Passive Discovery

c)

Edge Discovery

d)

Credentialed Scan

8.

A company wants to evaluate whether the SOC can detect lateral movement and privilege escalation techniques used by real-world attackers. Which engagement is MOST appropriate?

a)

Vulnerability scan

b)

Pen Testing

c)

Adversary Emulation

d)

Bug Bounty

9.

A monitoring dashboard shows that a web application maintained 99.4% availability over the last 30 days. What does this metric represent?

a)

SLA

b)

SLO

c)

SLI

d)

MOU

10.

An internal IT team commits to keeping authentication latency below 200 ms for internal apps. This is not legally binding but is used for performance tracking. What is this commitment called?

a)

SLA

b)

SLO

c)

SLI

d)

QoS requirement

11.

A developer modifies a login page so that the username field only accepts letters and numbers. If the user enters symbols like " ; " or " ' ", the request is rejected. What security control is being used?

a)

Output encoding

b)

Blacklist filtering

c)

Input Validation

d)

Encoding at runtime

12.

A security team identifies the attacker’s infrastructure, including their C2 servers and VPN exit nodes. Which Diamond Model component does this describe?

a)

Victim

b)

Adversary

c)

Infrastructure

d)

Capability

13.

If you want to a manual on security testing and assessment, which of the following would offer you a systematic approach?

a)

Cyber Kill Chain

b)

OSSTMM

c)

OWASP Testing Guide

d)

MITRE ATT&CK Framework

14.

A SOC analyst receives threat intelligence indicating that a phishing campaign is targeting the company. The report assigns a high confidence level to the indicators. Which of the following BEST describes what this confidence level indicates?

a)

The analyst must block all traffic related to the indicators immediately

b)

The source believes the indicators are very likely accurate, based on corroborated evidence

c)

The indicators are legally binding for enforcement

d)

The intelligence can be ignored because confidence is subjective

15.

A SOC analyst collects IP addresses, domains, and malware hashes from publicly available blogs, Twitter feeds, and threat forums. Which type of intelligence is this?

a)

OSINT

b)

Closed-Source intelligence

c)

Dark web intelligence

d)

Tactical intelligence

16.

Analysts are searching Tor forums and underground marketplaces for indicators of compromised credentials or leaked customer data. Which type of intelligence are they gathering?

a)

OSINT

b)

Closed-source Intelligence

c)

Deep/dark web intelligence

d)

None

17.

A SOC analyst receives a report indicating a new ransomware variant targeting financial institutions. The analyst uses this report to update detection rules and monitor systems. What activity is this?

a)

Threat Hunting

b)

Threat Intelligence

c)

Incident Response

d)

Vulnerability scanning

18.

A SOC analyst notices unusual lateral movement in the network that has not been previously reported. They proactively investigate endpoints and logs to find hidden malware. What activity is this?

(a)  

19.

A SOC team deploys honeypots to attract attackers and learn their methods before they reach production systems. Which type of active defense is this?

a)

Reactive

b)

Proactive

c)

Detective

d)

Complaince

20.

After detecting ransomware encrypting files, the SOC team immediately isolates the infected host and restores backups. What type of defense is this?

a)

Proactive

b)

Reactive

c)

Detective

d)

Preventive

21.

A SOC team configures endpoints to send logs to a central SIEM for analysis. Which term BEST describes this process?

a)

Log Aggregation

b)

Log Parsing

c)

Log Ingestion

d)

Log Correlation

22.

An analyst notices that logs from multiple servers show inconsistent timestamps. Which configuration must be verified to correct this issue?

a)

Syslog levels

b)

NTP server setting

c)

Log retention policy

d)

SIEM parsing rules

23.

A company implements a policy where users must authenticate and be authorized every time they access any resource, regardless of network location. Which security model does this describe?

a)

Traditional Perimeter Security

b)

ZTA

c)

Defense in Depth

d)

Role-based access control

24.

Which of the following is typically included in a SUSE deployment?

a)

CASB

b)

SWG

c)

FWaaS

d)

None of the above

e)

CASB, SWG and FWaaS are correct

25.

Luke Skyrunner was able to log in once this morning and access his email, VPN, and HR system without entering credentials again. What is this an example of?

a)

Federation

b)

SSO

c)

MFA

d)

PAM

26.

Becky was using her corporate credentials to log in to third-party SaaS applications without creating a separate account. Which technology is being used?

a)

PAM

b)

Federation

c)

MFA

d)

Passwordless authentication

27.

A company wants to monitor and enforce security policies for employees using multiple cloud applications. Which solution BEST fits this requirement?

a)

SIEM

b)

CASB

c)

VPN

d)

Firewall

28.

Which of the following actions is not typically performed by a DLP system?

a)

Blocking emails containing credit card numbers

b)

Encrypting sensitive files at rest

c)

Detecting unauthorized cloud uploads

d)

Performing vulnerability scans on endpoints

29.

Which of the following characteristics makes a task a good candidate for automation?

a)

Complex decision-making, requiring judgement

b)

Repetitive, rule-based, and high coluume

c)

Unique, one-off investigative tasks

d)

Strategic planning

30.

A company integrates its SIEM, endpoint detection system, and firewall on a platform. When an alert triggers, the platform automatically collects logs, enriches the alert with TI data, and blocks malicious IPs. This is an example of:

a)

SIEM

b)

SOAR

c)

NGFW

d)

CASB

31.

A SOC analyst receives an alert about a suspicious IP. The security system automatically queries threat intelligence feeds, malware databases, and related domains to provide additional context. What is this process called?

a)

OSINT

b)

Log aggregation

c)

Data enrichment

d)

Patch Management

32.

A webhook is MOST useful in which of the following cases?

a)

When a system needs to request updates on a schedule

b)

When immediate, event-driven notifications are required

c)

When a security product needs additional parsing features

d)

When data must be transferred using an agent

33.

A security team wants to identify all devices on its network, including unauthorized IoT devices that employees may have connected without approval. Which technique is MOST appropriate?

a)

External Vulnerability scan

b)

Asset Discovery scan

c)

Patch Management scan

d)

SIEM alert correlation

34.

A vulnerability scanner logs into a Linux server using SSH keys and examines configuration files, patch levels, and installed software versions. This is an example of:

a)

Non-credentialed scan

b)

Credentialed scan

c)

Agentless

d)

Stealth Scan

35.

True or False: Agentless Scanning requires the installation of software or network devices in order to complete the scan.

a)

True

b)

False