CySA+ 231 More Questions with 100% Correct
Answers
An organization has recently recovered from an incident where a managed switch had
been accessed and reconfigured without authorization by an insider. The incident
r
...
CySA+ 231 More Questions with 100% Correct
Answers
An organization has recently recovered from an incident where a managed switch had
been accessed and reconfigured without authorization by an insider. The incident
response team is working on developing a lessons learned report with
recommendations. Which of the following recommendations will BEST prevent the
same attack from occurring in the future?
A. Remove and replace the managed switch with an unmanaged one.
B. Implement a separate logical network segment for management interfaces.
C. Install and configure NAC services to allow only authorized devices to connect to the
network.
D. Analyze normal behavior on the network and configure the IDS to alert on deviations
from normal. -Answer- B
A cybersecurity analyst is reviewing the current BYOD security posture. The users must
be able to synchronize their calendars, email, and contacts to a smartphone
or other personal device. The recommendation must provide the most flexibility to
users. Which of the following recommendations would meet both the mobile data
protection efforts and the business requirements described in this scenario?
A. Develop a minimum security baseline while restricting the type of data that can be
accessed.
B. Implement a single computer configured with USB access and monitored by sensors.
C. Deploy a kiosk for synchronizing while using an access list of approved users.
D. Implement a wireless network configured for mobile device access and monitored by
sensors. -Answer- D
A security analyst received a compromised workstation. The workstation's hard drive
may contain evidence of criminal activities. Which of the following is the FIRST
thing the analyst must do to ensure the integrity of the hard drive while performing the
analysis?
A. Make a copy of the hard drive.
B. Use write blockers.
C. Run rm -R command to create a hash.
D. Install it on a different machine and explore the content. -Answer- B
File integrity monitoring states the following files have been changed without a written
request or approved change. The following change has been made:
chmod 777 -Rv /usr
Which of the following may be occurring?
A. The ownership pf /usr has been changed to the current user.
B. Administrative functions have been locked from users.C. Administrative commands have been made world readable/ -Answer- C
A security analyst has created an image of a drive from an incident. Which of the
following describes what the analyst should do NEXT?
A. The analyst should create a backup of the drive and then hash the drive.
B. The analyst should begin analyzing the image and begin to report findings.
C. The analyst should create a hash of the image and compare it to the original drive's
hash.
D. The analyst should create a chain of custody document and notify stakeholders. -
Answer- C
A cybersecurity analyst is currently investigating a server outage. The analyst has
discovered the following value was entered for the username: 0xbfff601a. Which of
the following attacks may be occurring?
A. Buffer overflow attack
B. Man-in-the-middle attack
C. Smurf attack
D. Format string attack -Answer- D
External users are reporting that a web application is slow and frequently times out
when attempting to submit information. Which of the following software
development best practices would have helped prevent this issue?
A. Stress testing
B. Regression testing
C. Input validation
D. Fuzzing -Answer- A
An analyst has initiated an assessment of an organization's security posture. As a part
of this review, the analyst would like to determine how much information about
the organization is exposed externally. Which of the following techniques would BEST
help the analyst accomplish this goal? (Select two.)
A. Fingerprinting
B. DNS query log reviews
C. Banner grabbing
D. Internet searches
E. Intranet portal reviews
F. Sourcing social network sites
G. Technical control audits -Answer- DF
A cybersecurity professional typed in a URL and discovered the admin panel for the ecommerce application is accessible over the open web with the default
password. Which of the following is the MOST secure solution to remediate this
vulnerability?
A. Rename the URL to a more obscure name, whitelist all corporate IP blocks, and
require two-factor authentication.B. Change the default password, whitelist specific source IP addresses, and require
two-factor authentication.
C. Whitelist all corporate IP blocks, require an alphanumeric passphrase for the default
password, and require two-factor authentication.
D. Change the username and default password, whitelist specific source IP addresses,
and require two-factor authentication. -Answer- D
An organization is requesting the development of a disaster recovery plan. The
organization has grown and so has its infrastructure. Documentation, policies, and
procedures do not exist. Which of the following steps should be taken to assist in the
development of the disaster recovery plan?
A. Conduct a risk assessment.
B. Develop a data retention policy.
C. Execute vulnerability scanning.
D. Identify assets. -Answer- D
A company wants to update its acceptable use policy (AUP) to ensure it relates to the
newly implemented password standard, which requires sponsored
authentication of guest wireless devices. Which of the following is MOST likely to be
incorporated in the AUP?
A. Sponsored guest passwords must be at least ten characters in length and contain a
symbol.
B. The corporate network should have a wireless infrastructure that uses open
authentication standards.
C. Guests using the wireless network should provide valid identification when
registering their wireless devices.
D. The network should authenticate all guest users using 802.1x backed by a RADIUS
or LDAP server. -Answer- C
An analyst was tasked with providing recommendations of technologies that are PKI
X.509 compliant for a variety of secure functions. Which of the following
technologies meet the compatibility requirement? (Select three.)
A. 3DES
B. AES
C. IDEA
D. PKCS
E. PGP
F. SSL/TLS
G. TEMPEST -Answer- BDF
After completing a vulnerability scan, the following output was noted:
Which of the following vulnerabilities has been identified?
A. PKI transfer vulnerability.
B. Active Directory encryption vulnerability.
C. Web application cryptography vulnerability.
D. VPN tunnel vulnerability. -Answer- CA security analyst is adding input to the incident response communication plan. A
company officer has suggested that if a data breach occurs, only affected parties
should be notified to keep an incident from becoming a media headline. Which of the
following should the analyst recommend to the company officer?
A. The first responder should contact law enforcement upon confirmation of a security
incident in order for a forensics team to preserve chain of custody.
B. Guidance from laws and regulations should be considered when deciding who must
be notified in order to avoid fines and judgements from non-compliance.
C. An externally hosted website should be prepared in advance to ensure that when an
incident occurs victims have timely access to notifications from a noncompromised
recourse.
D. The HR department should have information security personnel who are involved in
the investigation of the incident sign non-disclosure agreements so the
company cannot be held liable for customer data that might be viewed during an
investigation. -Answer- A
A company has recently launched a new billing invoice website for a few key vendors.
The cybersecurity analyst is receiving calls that the website is performing
slowly and the pages sometimes time out. The analyst notices the website is receiving
millions of requests, causing the service to become unavailable. Which of the
following can be implemented to maintain the availability of the website?
A. VPN
B. Honeypot
C. Whitelisting
D. DMZ
E. MAC filtering -Answer- C
A security audit revealed that port 389 has been used instead of 636 when connecting
to LDAP for the authentication of users. The remediation recommended by the
audit was to switch the port to 636 wherever technically possible. Which of the following
is the BEST response?
A. Correct the audit. This finding is a well-known false positive; the services that
typically run on 389 and 636 are identical.
B. Change all devices and servers that support it to 636, as encrypted services run by
default on 636.
C. Change all devices and servers that support it to 636, as 389 is a reserved port that
requires root access and can expose the server to privilege escalation
attacks.
D. Correct the audit. This finding is accurate, but the correct remediation is to update
encryption keys on each of the servers to match port 636. -Answer- B
A company that is hiring a penetration tester wants to exclude social engineering from
the list of authorized activities. Which of the following documents should
include these details?A. Acceptable use policy
B. Service level agreement
C. Rules of engagement
D. Memorandum of understanding
E. Master service agreement -Answer- C
A reverse engineer was analyzing malware found on a retailer's network and found
code extracting track data in memory. Which of the following threats did the
engineer MOST likely uncover?
A. POS malware
B. Rootkit
C. Key logger
D. Ransomware -Answer- A
Due to new regulations, a company has decided to institute an organizational
vulnerability management program and assign the function to the security team. Which
of the following frameworks would BEST support the program? (Select two.)
A. COBIT
B. NIST
C. ISO 27000 series
D. ITIL
E. OWASP -Answer- BD
A system administrator recently deployed and verified the installation of a critical patch
issued by the company's primary OS vendor. This patch was supposed to
remedy a vulnerability that would allow an adversary to remotely execute code from
over the network. However, the administrator just ran a vulnerability assessment
of networked systems, and each of them still reported having the same vulnerability.
Which of the following is the MOST likely explanation for this?
A. The administrator entered the wrong IP range for the assessment.
B. The administrator did not wait long enough after applying the patch to run the
assessment.
C. The patch did not remediate the vulnerability.
D. The vulnerability assessment returned false positives. -Answer- C
A security analyst is creating baseline system images to remediate vulnerabilities found
in different operating systems. Each image needs to be scanned before it is
deployed. The security analyst must ensure the configurations match industry standard
benchmarks and the process can be repeated frequently. Which of the
following vulnerability options would BEST create the process requirements?
A. Utilizing an operating system SCAP plugin
B. Utilizing an authorized credential scan
C. Utilizing a non-credential scan
D. Utilizing a known malware plugin -Answer- AA cybersecurity analyst is retained by a firm for an open investigation. Upon arrival, the
cybersecurity analyst reviews several security logs.
Given the following snippet of code:
Which of the following combinations BEST describes the situation and
recommendations to be made for this situation?
A. The cybersecurity analyst has discovered host 192.168.0.101 using Windows Task
Scheduler at 13:30 to runnc.exe; recommend proceeding with the next step of
removing the host from the network.
B. The cybersecurity analyst has discovered host 192.168.0.101 to be running
thenc.exe file at 13:30 using the auto cron job remotely, there are no
recommendations since this is not a threat currently.
C. The cybersecurity analyst has discovered host 192.168.0.101 is beaconing every day
at 13:30 using thenc.exe file; recommend proceeding with the next step of
removing the host from the network.
D. The security analyst has discovered host 192.168.0.101 is a rogue device on the
network, recommend proceeding with the next step of removing the host from
the network. -Answer- A
An analyst wants to use a command line tool to identify open ports and running services
on a host along with the application that is associated with those services
and port. Which of the following should the analyst use?
A. Wireshark
B. Qualys
C. netstat
D. nmap
E. ping -Answer- nmap
In order to meet regulatory compliance objectives for the storage of PHI, vulnerability
scans must be conducted on a continuous basis. The last completed scan of
the network returned 5,682 possible vulnerabilities. The Chief Information Officer (CIO)
would like to establish a remediation plan to resolve all known issues. Which
of the following is the BEST way to proceed?
A. Attempt to identify all false positives and exceptions, and then resolve all remaining
items.
B. Hold off on additional scanning until the current list of vulnerabilities have been
resolved.
C. Place assets that handle PHI in a sandbox environment, and then resolve all
vulnerabilities.
D. Reduce the scan to items identified as critical in the asset inventory, and resolve
these issues first. -Answer- D
An administrator has been investigating the way in which an actor had been exfiltrating
confidential data from a web server to a foreign host. After a thorough forensic
review, the administrator determined the server's BIOS had been modified by rootkit
installation. After removing the rootkit and flashing the BIOS to a known goodstate, which of the following would BEST protect against future adversary access to the
BIOS, in case another rootkit is installed?
A. Anti-malware application
B. Host-based IDS
C. TPM data sealing
D. File integrity monitoring -Answer- C
A security analyst is reviewing the following log after enabling key-based authentication.
Given the above information, which of the following steps should be performed NEXT to
secure the system?
A. Disable anonymous SSH logins.
B. Disable password authentication for SSH.
C. Disable SSHv1.
D. Disable remote root SSH logins. -Answer- B
A cybersecurity analyst has received a report that multiple systems are experiencing
slowness as a result of a DDoS attack. Which of the following would be the
BEST action for the cybersecurity analyst to perform?
A. Continue monitoring critical systems.
B. Shut down all server interfaces.
C. Inform management of the incident.
D. Inform users regarding the affected systems. -Answer- C
A security analyst has been asked to remediate a server vulnerability. Once the analyst
has located a patch for the vulnerability, which of the following should happen
NEXT?
A. Start the change control process.
B. Rescan to ensure the vulnerability still exists.
C. Implement continuous monitoring.
D. Begin the incident response process. -Answer- A
A software assurance lab is performing a dynamic assessment on an application by
automatically generating and inputting different, random data sets to attempt to
cause an error/failure condition. Which of the following software assessment capabilities
is the lab performing AND during which phase of the SDLC should this
occur? (Select two.)
A. Fuzzing
B. Behavior modeling
C. Static code analysis
D. Prototyping phase
E. Requirements phase
F. Planning phase -Answer- AD
Law enforcement has contacted a corporation's legal counsel because correlated data
from a breach shows the organization as the common denominator from allindicators of compromise. An employee overhears the conversation between legal
counsel and law enforcement, and then posts a comment about it on social media.
The media then starts contacting other employees about the breach. Which of the
following steps should be taken to prevent further disclosure of information about
the breach?
A. Perform security awareness training about incident communication.
B. Request all employees verbally commit to an NDA about the breach.
C. Temporarily disable employee access to social media
D. Have law enforcement meet with employees. -Answer- A
A recent vulnerability scan found four vulnerabilities on an organization's public Internetfacing IP addresses. Prioritizing in order to reduce the risk of a breach to the
organization, which of the following should be remediated FIRST?
A. A cipher that is known to be cryptographically weak.
B. A website using a self-signed SSL certificate.
C. A buffer overflow that allows remote code execution.
D. An HTTP response that reveals an internal IP address. -Answer- C
A cybersecurity analyst has several SIEM event logs to review for possible APT activity.
The analyst was given several items that include lists of indicators for both IP
addresses and domains. Which of the following actions is the BEST approach for the
analyst to perform?
A. Use the IP addresses to search through the event logs.
B. Analyze the trends of the events while manually reviewing to see if any of the
indicators match.
C. Create an advanced query that includes all of the indicators, and review any of the
matches.
D. Scan for vulnerabilities with exploits known to have been used by an APT. -AnswerB
A system administrator has reviewed the following output:
Which of the following can a system administrator infer from the above output?
A. The company email server is running a non-standard port.
B. The company email server has been compromised.
C. The company is running a vulnerable SSH server.
D. The company web server has been compromised. -Answer- A
An analyst finds that unpatched servers have undetected vulnerabilities because the
vulnerability scanner does not have the latest set of signatures. Management
directed the security team to have personnel update the scanners with the latest
signatures at least 24 hours before conducting any scans, but the outcome is
unchanged. Which of the following is the BEST logical control to address the failure?
A. Configure a script to automatically update the scanning tool.
B. Manually validate that the existing update is being performed.
C. Test vulnerability remediation in a sandbox before deploying.
D. Configure vulnerability scans to run in credentialed mode. -Answer- AA cybersecurity analyst has received an alert that well-known "call home" messages are
continuously observed by network sensors at the network boundary. The
proxy firewall successfully drops the messages. After determining the alert was a true
positive, which of the following represents the MOST likely cause?
A. Attackers are running reconnaissance on company resources.
B. An outside command and control system is attempting to reach an infected system.
C. An insider is trying to exfiltrate information to a remote network.
D. Malware is running on a company sy
[Show More]