QuiztudyPREMIUM
IBM Cybersecurity Analyst Professional Certificate • STUDY MODE
PRACTICE QUIZ
QUESTION 1 OF 70
What are the four (4) main types of actors identified in the video A brief overview of types of actors and their motives? Partially correct! Hactivists may be motivated by money, but more often by political concerns of some sort. Partially correct! Government or "nation-state" actors are becoming increasingly active and are an increasing threat. Partially correct! Hackers definately are prominent actors and are usually motivated by money. Partially correct! Internal actors do cause a lot of damage. They have a head start when it comes to knowledge and access.
A
HactivistsCorrect AnswerB
GovernmentsCorrect AnswerC
Black HatsD
Security AnalystsE
White HatsF
HackersCorrect AnswerG
InternalCorrect AnswerQUESTION 2 OF 70
Which of these common motivations is often attributed to a hactivist? Correct! The hactivism movement is often poitically motivated.
A
MoneyB
Just playing aroundC
Hire me!D
Political action and movementsCorrect AnswerQUESTION 3 OF 70
In the video Hacking organizations, which three (3) governments were called out as being active hackers? Partially correct! China is very active. Partially correct! Yes, Israel is active among governments with hacking organizations. Partially correct! The NSA is known to be active.
A
VenezuelaB
ChinaCorrect AnswerC
IsraelCorrect AnswerD
United StatesCorrect AnswerE
CanadaQUESTION 4 OF 70
Which four (4) of the following are known hacking organizations?
A
Syrian Electronic ArmyCorrect AnswerB
Fancy BearsCorrect AnswerC
Guardians of PeaceCorrect AnswerD
AnonymousCorrect AnswerE
The Ponemon InstituteQUESTION 5 OF 70
Which of these hacks resulted in over 100 million credit card numbers being stolen? Correct! Over 100 million credit card numbers were stolen. AN ARCHITECT'S PERSPECTIVE ON ATTACK CLASSIFICATIONS
A
2011 Sony Playstation hackB
2013 Singapore CyberattacksC
2014 Ebay hackD
2015 Target Stores hackCorrect AnswerE
2016 US Election hackQUESTION 6 OF 70
Which of the following statements is True?
A
Passive attacks are easy to detect because the original message wrapper must be modified by the attacker before it is forwarded on to the intended recipient.B
Passive attacks are hard to detect because the original message is delivered unchanged and can pass an integrity check.Correct AnswerC
Passive attacks are hard to detect because the original message is never delivered so the receiving does not know they missed anything.D
Passive attacks are easy to detect because of the latency created by the interception and second forwarding.QUESTION 7 OF 70
The purpose of security services includes which three (3) of the following?
A
Often replicate functions found in physical documentsCorrect AnswerB
Includes any component of your security infrastructure that has been outsourced to a third-partyC
Enhance security of data processing systems and information transfer.Correct AnswerD
Are intended to counter security attacks.Correct AnswerQUESTION 8 OF 70
Which statement best describes access control?
A
Protection against denial by one of the parties in communicationB
Prevention of unauthorized use of a resourceCorrect AnswerC
Assurance that the communicating entity is the one claimedD
Protection against the unauthorized disclosure of dataQUESTION 9 OF 70
The International Telecommunication Union (ITU) X.800 standard addresses which three (3) of the following topics? Partially correct! I addresses protecting data from unauthorized access. Partially correct! It addresses the protection of data from unauthorized disclosure. Partially correct! Both peer-entity and data origin authentication.
A
Access ControlCorrect AnswerB
Data transmission speedsC
Data ConfidentialityCorrect AnswerD
Transmission cost sharing between member countriesE
AuthenticationCorrect AnswerQUESTION 10 OF 70
Protocol suppression, ID and authentication are examples of which? Correct! These are the technical implementation of the Security Policy
A
Security PolicyCorrect AnswerB
Security MechanismC
Business PolicyD
Security ArchitectureQUESTION 11 OF 70
The motivation for more security in open systems is driven by which three (3) of the following factors? Partially correct! The spread of OSI recommendations brings with it the need for enhanced security. Partially correct! Think GDPR. Partially correct! Especially those that are connected to the Internet.
A
New requirements from the WTO, World Trade OrganizationB
The desire by a number of organizations to use OSI recommendations.Correct AnswerC
The appearence of data protection legislation in several countries.Correct AnswerD
Society)s increasing dependance on computers.Correct AnswerQUESTION 12 OF 70
True or False: The accidental disclosure of confidential data by an employee is considered a legitimate organizational threat. Correct! Not all threats are intentional
A
TrueCorrect AnswerB
FalseQUESTION 13 OF 70
True or False: The accidental disclosure of confidential information by an employee is considered an attack. Correct. An attack has to be an intentional attempt to violate security.
A
TrueB
FalseCorrect AnswerQUESTION 14 OF 70
A replay attack and a denial of service attack are examples of which? Correct! These are both attacks against the security architecture itself.
A
Security architecture attackCorrect AnswerB
Origin attackC
Passive attackD
Masquerade attackQUESTION 15 OF 70
The International Telecommunication Union is an organization that is described by which of the following statements? MALWARE AND AN INTRODUCTION TO THREAT PROTECTION
A
The ITU is an organization charted and staffed by the United Nations to maintain international standards, such as X.800, for telecommunication.Correct AnswerB
The ITU is an industry organization founded by the largest telecommunication companies in the world and focused on lobbying governments on their behalf.C
The ITU is a partnership of the national telephone companies of most European countries intended to help compete against the largest American telecomms.D
The ITU is a workers union focused on ensuring the welfare of telecommunication workers.QUESTION 16 OF 70
True or False: An application that runs on your computer without your authorization but does no damage to the system is not considered malware. Correct! Adware and Spyware often do not damage the host but are definitely considered Malware.
A
TrueB
FalseCorrect AnswerQUESTION 17 OF 70
How would you classify a piece of malicious code designed to cause damage and spreads from one computer to another by attaching itself to files but requires human actions in order to replicate? Correct! A virus requires action on the part of the user in order to replicate and spread.
A
VirusCorrect AnswerB
WormsC
Trojan HorsesD
SpywareE
AdwareF
RansomwareQUESTION 18 OF 70
How would you classify a piece of malicious code designed collect data about a computer and its users and then report that back to a malicious actor? Correct! These are designed to spy on the host system and collect data about its users.
A
VirusB
WormsC
SpywareCorrect AnswerD
AdwareQUESTION 19 OF 70
A large scale Denial of Service attack usually relies upon which of the following? Correct! Many servers are required to implement an effective DoS attack - far more than could be managed manually.
A
A botnetCorrect AnswerB
A keyloggerC
Logic BombsD
Trojan HorsesQUESTION 20 OF 70
Antivirus software can be classified as which form of threat control? Correct! Antivirus software is a technology that can be deployed to help mitigate cyber threats. ADDITIONAL ATTACK EXAMPLES TODAY
A
Technical controlsCorrect AnswerB
Administrative controlsC
Active controlsD
Passive controlsQUESTION 21 OF 70
Which of the following measures can be used to counter a mapping attack? Correct! All 3 of these options can and should be used.
A
Record traffic entering the networkB
Look for suspicious activity like IP addresses or ports being scanned sequentially.C
Use a host scanner and keep an inventory of hosts on your network.D
All of the above.Correct AnswerQUESTION 22 OF 70
In order for a network card (NIC) to engage in packet sniffing, it must be running in which mode? Correct, the NIC must be running in promiscuous mode.
A
PromiscuousCorrect AnswerB
SnifferC
InspectionD
OpenQUESTION 23 OF 70
Which countermeasure can be helpful in combating an IP Spoofing attack? Correct! This works but only if all routers use it.
A
Ingress filteringCorrect AnswerB
Enable IP Packet Authentication filteringC
Keep your certificates up-to-dateD
Enable the IP Spoofing feature available in most commercial antivirus software.E
All of the above.QUESTION 24 OF 70
Which two (2) measures can be used to counter a Denial of Service (DOS) attack? Partially correct! The downside here is that the source is most likely innocent but compromised machines. Partially correct! The downside is that you will be filtering out some legitimate packets as well.
A
Enable packet filtering on your firewall.B
Use traceback to identify the source of the flooded packets.Correct AnswerC
Implement a filter to remove flooded packets before they reach the host.Correct AnswerD
Enable the DOS Filtering option now available on most routers and switches.QUESTION 25 OF 70
Which countermeasure should be used agains a host insertion attack? Correct! All of these steps are necessary. ATTACKS AND CYBER RESOURCES
A
Maintain an accurate inventory of of computer hosts by MAC address.B
Use a host scanning tool to match a list of discovered hosts against known hosts.C
Investigate newly discovered hosts.D
All of the above.Correct AnswerQUESTION 26 OF 70
Which is not one of the phases of the intrusion kill chain? Correct! Activation is not part if the intrusion kill chain
A
ActivationCorrect AnswerB
Command and ControlC
InstallationD
DeliveryQUESTION 27 OF 70
Which social engineering attack involves a person instead of a system such as an email server? Correct! a vishing attack often is conducted over the phone.
A
PhishingB
SpectraC
CyberwarfareD
VishingCorrect AnswerQUESTION 28 OF 70
Which of the following is an example of a social engineering attack? Correct! Talking someone into doing something they should not do is social engineering.
A
Setting up a web site offering free games, but infecting the downloads with malware.B
Calling an employee and telling him you are from IT support and must observe him logging into his corporate account.Correct AnswerC
Logging in to the Army)s missle command computer and launching a nuclear weapon.D
Sending someone an email with a Trojan Horse attachment.QUESTION 29 OF 70
True or False: While many countries are preparing their military for a future cyberwar, there have been no "cyber battles" to-date. Correct! There have been hundreds attacks that can be considered acts of cyberwarfare conducted by many countries, includeing the United States, China, Israel, Russia, Iran, etc. A DAY IN THE LIFE OF A SOC ANALYST
A
TrueB
FalseCorrect AnswerQUESTION 30 OF 70
Which tool did Javier say was crucial to his work as a SOC analyst? Correct! Tools like QRadar SIEM are crucial to Javier since he can use it to perform advanced corrolations and threat intelligence integration. A BRIEF OVERVIEW OF TYPES OF ACTORS AND THEIR MOTIVES
A
SIEM (Security Information and Event Management)Correct AnswerB
Packet SniffersC
FirewallsD
Intrusion detection softwareQUESTION 31 OF 70
Which hacker organization hacked into the Democratic National Convention and released Hillary Clinton's emails?
A
Fancy BearsCorrect AnswerB
AnonymousC
Syrian Electronic ArmyD
Guardians of the PeaceE
All of the aboveQUESTION 32 OF 70
What challenges are expected in the future?
A
Enhanced espionage from more countriesB
Far more advanced malwareC
New consumer technology to exploitD
All of the aboveCorrect AnswerQUESTION 33 OF 70
Why are cyber attacks using SWIFT so dangerous?
A
SWIFT is the protocol used by all banks to transfer moneyCorrect AnswerB
SWIFT is the flight plan and routing system used by all cooperating nations for international commercial flightsC
SWIFT is the protocol used to transmit all diplomatic telegrams between governments around the worldD
SWIFT is the protocol used by all US healthcare providers to encrypt medical recordsQUESTION 34 OF 70
Which statement best describes Authentication?
A
Assurance that the communicating entity is the one claimedCorrect AnswerB
Prevention of unauthorized use of a resourceC
Assurance that a resource can be accessed and usedD
Protection against denial by one of the parties in communicationQUESTION 35 OF 70
Trusted functionality, security labels, event detection, security audit trails and security recovery are all examples of which type of security mechanism?
A
Active security mechanismB
External security mechanismC
Passive security mechanismCorrect AnswerD
Contingent security mechanismQUESTION 36 OF 70
If an organization responds to an intentional threat, that threat is now classified as what?
A
An attackCorrect AnswerB
An active threatC
An open caseD
A malicious threatQUESTION 37 OF 70
An attack that is developed particularly for a specific customer and occurs over a long period of time is a form of what type of attack?
A
Denial of Service (DOS)B
Advanced Persistent ThreatCorrect AnswerC
Water HoleD
SpectraQUESTION 38 OF 70
A political motivation is often attributed to which type of actor?
A
Security AnalystsB
InternalC
HackersD
HactivistCorrect AnswerQUESTION 39 OF 70
The video Hacking organizations called out several countries with active government sponsored hacking operations in effect. Which one of these was among those named?
A
CanadaB
EgyptC
IsraelCorrect AnswerD
South AfricaQUESTION 40 OF 70
Which of these is not a known hacking organization?
A
The Ponemon InstituteCorrect AnswerB
Fancy BearsC
Syrian Electronic ArmyD
AnonymousE
Guardians of the PeaceQUESTION 41 OF 70
Which type of actor hacked the 2016 US Presidential Elections?
A
GovernmentCorrect AnswerB
InternalC
HactivistsD
HackersQUESTION 42 OF 70
True or False: Passive attacks are easy to detect because the original messages are usually altered or undelivered.
A
FalseCorrect AnswerB
TrueQUESTION 43 OF 70
True or False: Authentication, Access Control and Data Confidentiality are all addressed by the ITU X.800 standard.
A
TrueCorrect AnswerB
FalseQUESTION 44 OF 70
True or False: Only acts performed with intention to do harm can be classified as Organizational Threats
A
FalseCorrect AnswerB
TrueQUESTION 45 OF 70
How would you classify a piece of malicious code designed to cause damage, can self-replicate and spreads from one computer to another by attaching itself to files?
A
VirusB
WormCorrect AnswerC
SpywareD
Trojan HorseE
AdwareF
RansomwareQUESTION 46 OF 70
Botnets can be used to orchestrate which form of attack?
A
Distribution of SpamB
DDoS attacksC
Phishing attacksD
Distribution of SpywareE
As a Malware launchpadF
All of the aboveCorrect AnswerQUESTION 47 OF 70
Policies and training can be classified as which form of threat control?
A
Technical controlsB
Administrative controlsCorrect AnswerC
Passive controlsD
Active controlsQUESTION 48 OF 70
Which type of attack can be addressed using a switched Ethernet gateway and software on every host on your network that makes sure their NICs is not running in promiscuous mode.
A
Packet SniffingCorrect AnswerB
Host InsertionC
Trojan HorseD
RansomwareE
All of the aboveQUESTION 49 OF 70
A flood of maliciously generated packets swamp a receiver’s network interface preventing it from responding to legitimate traffic. This is characteristic of which form of attack?
A
A Denial of Service (DOS) attackCorrect AnswerB
A Trojan HorseC
A Masquerade attackD
A Ransomware attackQUESTION 50 OF 70
A person calls you at work and tells you he is a lawyer for your company and that you need to send him specific confidential company documents right away, or else! Assuming the caller is not really a lawyer for your company but a bad actor, what kind of attack is this?
A
A Social Engineering attackCorrect AnswerB
A Trojan HorseC
A Denial of Service attackD
A Worm attackQUESTION 51 OF 70
Which type of actor was not one of the four types of actors mentioned in the video A brief overview of types of actors and their motives?
A
HactivistsB
GovernmentsC
HackersD
InternalE
Black HatsCorrect AnswerQUESTION 52 OF 70
Cryptography, digital signatures, access controls and routing controls considered which?
A
Business PolicyB
Security PolicyC
Specific security mechanismsCorrect AnswerD
Pervasive security mechanismsQUESTION 53 OF 70
Traffic flow analysis is classified as which?
A
An active attackB
A passive attackCorrect AnswerC
An origin attackD
A masquerade attackQUESTION 54 OF 70
True or False: An individual hacks into a military computer and uses it to launch an attack on a target he personally dislikes. This is considered an act of cyberwarfare.
A
FalseCorrect AnswerB
TrueQUESTION 55 OF 70
What are the four (4) main types of actors identified in the video A brief overview of types of actors and their motives?
A
HactivistsCorrect AnswerB
GovernmentsCorrect AnswerC
Black HatsD
Security AnalystsE
White HatsF
Hackers InternalCorrect AnswerQUESTION 56 OF 70
Which of these common motivations is often attributed to a hacktivist?
A
MoneyB
Just playing aroundC
Hire me!D
Political action and movementsCorrect AnswerQUESTION 57 OF 70
In the video Hacking organizations, which three (3) governments were called out as being active hackers?
A
VenezuelaB
ChinaCorrect AnswerC
IsraelCorrect AnswerD
United StatesCorrect AnswerE
CanadaQUESTION 58 OF 70
Which of these hacks resulted in over 100 million credit card numbers being stolen?
A
2011 Sony Playstation hackB
2013 Singapore CyberattacksC
2014 Ebay hackD
2015 Target Stores hackCorrect AnswerE
2016 US Election hackQUESTION 59 OF 70
The International Telecommunication Union (ITU) X.800 standard addresses which three (3) of the following topics?
A
Access ControlCorrect AnswerB
Data transmission speedsC
Data ConfidentialityCorrect AnswerD
Transmission cost sharing between member countriesE
AuthenticationCorrect AnswerQUESTION 60 OF 70
Protocol suppression, ID and authentication are examples of which?
A
Security PolicyCorrect AnswerB
Security MechanismC
Business PolicyD
Security ArchitectureQUESTION 61 OF 70
The motivation for more security in open systems is driven by which three (3) of the following factors?
A
New requirements from the WTO, World Trade OrganizationB
The desire by a number of organizations to use OSI recommendations.Correct AnswerC
The appearence of data protection legislation in several countries.Correct AnswerD
Society’s increasing dependance on computers.Correct AnswerQUESTION 62 OF 70
True or False: The accidental disclosure of confidential data by an employee is considered a legitimate organizational threat.
A
TrueCorrect AnswerB
FalseQUESTION 63 OF 70
True or False: The accidental disclosure of confidential information by an employee is considered an attack.
A
TrueB
FalseCorrect AnswerQUESTION 64 OF 70
A replay attack and a denial of service attack are examples of which?
A
Security architecture attackCorrect AnswerB
Origin attackC
Passive attackD
Masquerade attackQUESTION 65 OF 70
The International Telecommunication Union is an organization that is described by which of the following statements?
A
The ITU is an organization charted and staffed by the United Nations to maintain international standards, such as X.800, for telecommunication.Correct AnswerB
The ITU is an industry organization founded by the largest telecommunication companies in the world and focused on lobbying governments on their behalf.C
The ITU is a partnership of the national telephone companies of most European countries intended to help compete against the largest American telecom.D
The ITU is a workers union focused on ensuring the welfare of telecommunication workers.QUESTION 66 OF 70
True or False: An application that runs on your computer without your authorization but does no damage to the system is not considered malware.
A
TrueB
FalseCorrect AnswerQUESTION 67 OF 70
How would you classify a piece of malicious code designed to cause damage and spreads from one computer to another by attaching itself to files but requires human actions in order to replicate?
A
VirusCorrect AnswerB
WormsC
Trojan HorsesD
SpywareE
AdwareF
RansomwareQUESTION 68 OF 70
How would you classify a piece of malicious code designed collect data about a computer and its users and then report that back to a malicious actor?
A
VirusB
WormsC
SpywareCorrect AnswerD
AdwareQUESTION 69 OF 70
A large scale Denial of Service attack usually relies upon which of the following?
A
A botnetCorrect AnswerB
A keyloggerC
Logic BombsD
Trojan HorsesQUESTION 70 OF 70
Antivirus software can be classified as which form of threat control?
A
Technical controlsCorrect AnswerB
Administrative controlsC
Active controlsD
Passive controlsReady to test your recall?
What are the four (4) main types of actors identified in the video A brief overview of types of actors and their motives? Partially correct! Hactivists may be motivated by money, but more often by political concerns of some sort. Partially correct! Government or "nation-state" actors are becoming increasingly active and are an increasing threat. Partially correct! Hackers definately are prominent actors and are usually motivated by money. Partially correct! Internal actors do cause a lot of damage. They have a head start when it comes to knowledge and access.
💡Select all 4 correct answers before submitting (0 of 4 selected).
A
Hactivists
B
Governments
C
Black Hats
D
Security Analysts
E
White Hats
F
Hackers
G
Internal
How confident are you in this answer?