CySA+ Test Security Architecture and Tools Flashcards
6 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CySA+ Test Security Architecture and Tools flashcards as text
A CySA+ analyst needs to capture all network traffic on a segment for analysis. Which device should be used to provide a copy of traffic to the monitoring tool without interrupting the data flow?
Answer: Network tap
A network tap passively copies traffic from a link and sends it to a monitoring or analysis tool without affecting the production data flow.
Which type of IDS/IPS detects attacks by comparing traffic patterns against a baseline of normal behavior rather than known attack signatures?
Answer: Anomaly-based detection
Anomaly-based detection identifies deviations from established baselines, allowing it to detect novel or unknown attacks that lack signatures.
Which security architecture component is designed to deceive attackers by mimicking real systems and gathering intelligence on their techniques?
Answer: Honeypot
A honeypot is a decoy system intentionally deployed to lure and observe attackers, gathering TTPs without exposing production assets.
Which tool automates the collection, normalization, and correlation of log data from multiple sources to support security investigations?
Answer: SIEM
A SIEM centralizes log collection and correlation, enabling analysts to detect threats, investigate incidents, and meet compliance requirements.
An analyst wants to detect threats that have already bypassed perimeter defenses by monitoring endpoint processes and file activity. Which tool is BEST suited for this?
Answer: EDR (Endpoint Detection and Response)
EDR tools continuously monitor endpoint activity for suspicious behaviors, enabling detection and response to threats that have bypassed perimeter controls.
Which security tool specifically protects web applications by inspecting and filtering HTTP/HTTPS traffic between clients and the application server?
Answer: WAF (Web Application Firewall)
A WAF inspects HTTP/HTTPS traffic to block web-specific attacks such as SQL injection, XSS, and CSRF before they reach the application.