ISACA Cybersecurity Nexus (CSX) Fundamentals Certificate — Questions and Answers
Question 1: Which threat actor type is typically motivated by financial gain and tends to use ransomware or banking trojans?
- Nation-state actor
- Cybercriminal (Correct answer)
- Insider threat
- Hacktivist
Correct answer: Cybercriminal
Cybercriminals are primarily motivated by financial gain and commonly deploy ransomware, banking malware, and fraud schemes to generate profit.
Question 2: An attacker uses LinkedIn to map reporting structures, employee roles, and technology stacks at a target organization. Which phase of the intelligence lifecycle does this represent?
- Production
- Collection (Correct answer)
- Dissemination
- Analysis
Correct answer: Collection
Harvesting information from social media and professional networks to feed into an intelligence assessment is a collection activity in the intelligence lifecycle.
Question 3: Which practice best ensures report confidentiality during transmission to a client?
- Sending via standard email attachment
- Encrypting the report and transmitting via a secure channel (Correct answer)
- Printing and mailing a physical copy
- Posting to a public file-sharing service with password
Correct answer: Encrypting the report and transmitting via a secure channel
Encrypting the document and using a secure transmission channel (e.g., encrypted email, SFTP) protects report contents from interception.
Question 4: What role does 'active listening' play in a cybersecurity investigative interview?
- It is a legal requirement to show the subject the interview is being fairly conducted
- It is only relevant in victim interviews, not suspect interviews
- It allows the interviewer to plan the next question without appearing distracted
- It demonstrates genuine engagement, builds rapport, and helps the interviewer identify inconsistencies and follow-up opportunities in real time (Correct answer)
Correct answer: It demonstrates genuine engagement, builds rapport, and helps the interviewer identify inconsistencies and follow-up opportunities in real time
Active listening improves rapport, signals respect for the subject, and helps interviewers catch subtle inconsistencies or opportunities for productive follow-up in real time.
Question 5: In the context of the Diamond Model of Intrusion Analysis, which four elements are used to describe a cyber intrusion?
- Source, Vector, Target, Payload
- Actor, Motive, Opportunity, Means
- Threat, Vulnerability, Risk, Impact
- Adversary, Capability, Infrastructure, Victim (Correct answer)
Correct answer: Adversary, Capability, Infrastructure, Victim
The Diamond Model characterizes intrusions using four core elements: Adversary (who), Capability (how), Infrastructure (where), and Victim (target).
Question 6: Under HIPAA's Security Rule, which category of safeguards specifically requires workforce training and access management policies?
- Administrative safeguards (Correct answer)
- Organizational requirements
- Technical safeguards
- Physical safeguards
Correct answer: Administrative safeguards
Administrative safeguards under the HIPAA Security Rule address workforce security, training, access management, and contingency planning through documented policies and procedures.
Question 7: An analyst discovers that an attacker used a legitimate administrative tool already present on the system to move laterally. This technique is known as:
- Living off the land (LotL) (Correct answer)
- Drive-by download
- Watering hole attack
- Zero-day exploitation
Correct answer: Living off the land (LotL)
Living off the land (LotL) techniques use legitimate built-in tools like PowerShell or WMI to conduct attacks, making detection harder since no foreign binaries are introduced.
Question 8: Which hashing algorithm is currently recommended by NIST for producing a 256-bit digest?
- DES
- SHA-1
- MD5
- SHA-256 (Correct answer)
Correct answer: SHA-256
SHA-256, part of the SHA-2 family, is NIST-recommended and produces a 256-bit hash, unlike the deprecated MD5 and SHA-1.
Question 9: What is the primary difference between a logical acquisition and a physical acquisition of a mobile device?
- Physical acquisition is less forensically sound than logical acquisition
- Physical acquisition only captures call logs, while logical captures all data
- Logical acquisition is faster and captures only file system data, while physical acquisition captures a bit-for-bit image of the full storage (Correct answer)
- Logical acquisition requires rooting the device, while physical does not
Correct answer: Logical acquisition is faster and captures only file system data, while physical acquisition captures a bit-for-bit image of the full storage
Logical acquisition extracts data through the OS file system layer, while physical acquisition creates a complete bit-for-bit copy of the storage chip including deleted data and unallocated space.
Question 10: Which NIST framework function is most directly associated with identifying cybersecurity threats before they cause harm?
- Identify (Correct answer)
- Protect
- Recover
- Respond
Correct answer: Identify
The NIST 'Identify' function focuses on developing organizational understanding to manage cybersecurity risk, including asset management and risk assessment.
Question 11: In CSX practice, what is the chain of custody and why is it important?
- A ranking system for officers
- A supply chain management process
- A prisoner transport protocol
- A documented record of evidence handling from collection to court presentation, ensuring admissibility (Correct answer)
Correct answer: A documented record of evidence handling from collection to court presentation, ensuring admissibility
Chain of custody is the chronological documentation of evidence collection, transfer, analysis, and storage. Any break in the chain can make evidence inadmissible in court by creating doubt about its integrity.
Question 12: What is 'dwell time' in the context of cybersecurity incidents?
- The delay between detection and containment
- The time required to patch a vulnerability after disclosure
- The time an analyst spends investigating an alert
- The duration between initial compromise and detection of the breach (Correct answer)
Correct answer: The duration between initial compromise and detection of the breach
Dwell time measures how long an attacker remains undetected in an environment after initial compromise, with shorter dwell times indicating better detection capabilities.
Question 13: What is the primary goal of tokenization in payment card security (PCI DSS)?
- To encrypt card data during network transit
- To digitally sign transaction records for non-repudiation
- To hash cardholder PINs before storage
- To replace sensitive card data with a non-sensitive token, reducing PCI scope (Correct answer)
Correct answer: To replace sensitive card data with a non-sensitive token, reducing PCI scope
Tokenization replaces primary account numbers (PANs) with tokens that have no exploitable value, reducing systems in PCI DSS scope.
Question 14: The Tallinn Manual 2.0 is best described as:
- An ISACA policy framework for corporate cyber use of force
- A binding NATO treaty governing state-sponsored cyberattacks
- A US federal regulation on active cyber defense
- A non-binding scholarly analysis of how international law applies to cyber operations (Correct answer)
Correct answer: A non-binding scholarly analysis of how international law applies to cyber operations
The Tallinn Manual 2.0 is a non-binding academic study produced by international law experts explaining how existing international law applies to cyber operations.
Question 15: What does the Fourth Amendment protect against in CSX operations?
- Freedom of speech
- Right to legal counsel
- Unreasonable searches and seizures by requiring probable cause or warrants (Correct answer)
- Right to bear arms
Correct answer: Unreasonable searches and seizures by requiring probable cause or warrants
The Fourth Amendment protects individuals from unreasonable searches and seizures by the government, generally requiring probable cause and a warrant issued by a neutral judge before searches can be conducted.
Question 16: Why is it important for a cybersecurity investigator to avoid making promises of immunity or leniency during an interview?
- Only law enforcement can offer leniency, making corporate promises redundant
- It is considered unprofessional but has no legal consequence
- Promises of leniency can render any resulting statements inadmissible and expose the organization to legal liability (Correct answer)
- It reduces the likelihood the subject will confess
Correct answer: Promises of leniency can render any resulting statements inadmissible and expose the organization to legal liability
Unauthorized promises of leniency can invalidate confessions or admissions as evidence and create legal liability for the investigator and their organization.
Question 17: When classifying data in a security report, which classification label typically requires the most restrictive handling?
- Confidential
- Top Secret / Restricted (Correct answer)
- Public
- Internal Use Only
Correct answer: Top Secret / Restricted
Top Secret or Restricted classifications impose the most stringent access controls, distribution limits, and handling procedures.
Question 18: What role does 'pivoting on an IOC' play in a threat intelligence investigation?
- Blocking an indicator at the firewall before it can be used
- Sharing an indicator with a trusted partner ISAC
- Patching the vulnerability associated with a known indicator
- Using one indicator to discover related infrastructure, malware, or actor clusters (Correct answer)
Correct answer: Using one indicator to discover related infrastructure, malware, or actor clusters
IOC pivoting uses a known artifact (such as a C2 IP) as a starting point to query threat intelligence platforms and passive DNS databases, uncovering related domains, IPs, and malware families.
Question 19: A government agency's use-of-force policy references 'Title 10' and 'Title 50' authorities. These titles most directly relate to:
- US legal authorities governing military operations vs. intelligence activities (Correct answer)
- NIST cybersecurity framework tiers
- ISACA COBIT control objectives
- GDPR cross-border data transfer rules
Correct answer: US legal authorities governing military operations vs. intelligence activities
In the US, Title 10 governs military operations (Department of Defense), while Title 50 governs intelligence activities, and understanding which authority applies is critical to legally sanctioned cyber operations.
Question 20: Which protocol operates at the network layer and is commonly exploited in IP spoofing attacks?
- IP (Correct answer)
- TCP
- FTP
- HTTP
Correct answer: IP
IP (Internet Protocol) operates at the network layer and lacks built-in authentication, making it vulnerable to spoofing attacks.
Question 21: In CSX practice, what principle guides the use of force continuum?
- Maximum force should always be used initially
- Force must be proportional to the threat and escalated/de-escalated based on the subject's behavior (Correct answer)
- Force is never acceptable under any circumstances
- Only verbal commands are permitted
Correct answer: Force must be proportional to the threat and escalated/de-escalated based on the subject's behavior
The use of force continuum requires that force be proportional and appropriate to the threat level, with officers trained to escalate or de-escalate their response based on the subject's actions and compliance level.
Question 22: What is 'purple teaming' in the context of cyber incident detection?
- A collaborative exercise where red team attackers and blue team defenders work together to improve detection capabilities (Correct answer)
- A compliance framework for financial institutions
- A government classification for top-secret cyber operations
- A vendor-neutral certification program
Correct answer: A collaborative exercise where red team attackers and blue team defenders work together to improve detection capabilities
Purple teaming combines offensive (red team) and defensive (blue team) functions to maximize the feedback loop and measurably improve detection and response capabilities.
Question 23: Which metric indicates how quickly systems must be restored after a disruption?
- Mean Time to Respond
- Recovery Point Objective
- Recovery Time Objective (Correct answer)
- System Uptime Goal
Correct answer: Recovery Time Objective
Recovery Time Objective (RTO) is a critical metric in disaster recovery planning that specifies the maximum acceptable duration of downtime after a disruption. It defines how quickly systems, applications, and data must be restored to an operational state to meet business requirements and minimize impact. RTO dictates the speed at which recovery must occur.
Question 24: What is the FIRST action an incident responder should take upon discovering an active ransomware infection on a corporate workstation?
- Reimage the system from a clean backup
- Contact law enforcement before doing anything else
- Isolate the infected system from the network immediately (Correct answer)
- Pay the ransom to recover files quickly
Correct answer: Isolate the infected system from the network immediately
Immediate network isolation prevents ransomware from spreading to other systems and shared network drives while preserving evidence.
Question 25: What distinguishes a worm from a traditional virus in terms of propagation?
- Worms self-replicate across networks without user interaction; viruses require a host file (Correct answer)
- Worms require a host file to spread; viruses do not
- Worms only affect mobile devices; viruses affect desktops
- Worms encrypt files; viruses delete them
Correct answer: Worms self-replicate across networks without user interaction; viruses require a host file
Unlike viruses that require a host file and user action to spread, worms independently replicate and propagate across networks by exploiting vulnerabilities.
Question 26: An IDS generates 500 alerts per day but only 5 are confirmed malicious. What is this phenomenon called?
- True positive rate degradation
- Baseline drift
- Signature collision
- Alert fatigue due to false positives (Correct answer)
Correct answer: Alert fatigue due to false positives
When security tools generate excessive false positive alerts, analysts experience alert fatigue, reducing their effectiveness at identifying real threats.
Question 27: State breach notification laws in the U.S. generally require notification to affected residents when which type of data is compromised?
- Defined combinations of personal information such as name plus SSN, driver's license, or financial account numbers (Correct answer)
- Only data regulated by federal laws such as HIPAA or GLBA
- Any business-critical data regardless of personal nature
- Any data stored in encrypted form, regardless of exposure
Correct answer: Defined combinations of personal information such as name plus SSN, driver's license, or financial account numbers
State breach notification laws typically trigger when a defined combination of personal data elements (e.g., name plus SSN, financial account, or driver's license number) is compromised.
Question 28: Which framework helps in understanding and classifying cyber threats?
- ITIL
- ISO 27001
- MITRE ATT&CK (Correct answer)
- COBIT
Correct answer: MITRE ATT&CK
The MITRE ATT&CK framework is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations. It provides a structured way to understand and classify how attackers operate, enabling organizations to develop more effective threat detection, prevention, and response strategies. This framework is invaluable for mapping and analyzing cyber threats.
Question 29: An organization identifies that a former employee still has active VPN credentials. In threat assessment terms, this represents:
- A vulnerability that increases the likelihood of an insider threat being realized (Correct answer)
- A threat agent with no access vector
- An acceptable residual risk
- A deterrent control weakness
Correct answer: A vulnerability that increases the likelihood of an insider threat being realized
Active credentials for a former employee create a vulnerability — an exploitable weakness — that could be used by a malicious insider or someone who obtains those credentials.
Question 30: A SOC analyst notices an internal host making connections to 47 different external IPs on port 445 in 10 minutes. What is the MOST likely explanation?
- Normal file sharing activity
- A legitimate vulnerability scanner
- A scheduled backup job running
- The host is infected with a worm scanning for SMB vulnerabilities (Correct answer)
Correct answer: The host is infected with a worm scanning for SMB vulnerabilities
Rapid outbound SMB (port 445) connection attempts to multiple external IPs is characteristic of a worm like WannaCry propagating and scanning for vulnerable hosts.
ISACA Cybersecurity Nexus (CSX) Fundamentals Certificate
The ISACA Cybersecurity Fundamentals Certificate (CSX-F) validates foundational knowledge across information security principles, the threat landscape, asset protection controls, and security operations and incident response. It is an entry-level credential for students and IT professionals entering cybersecurity.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds