QuiztudyPREMIUM
IBM Cybersecurity Analyst Professional Certificate • STUDY MODE
KEY CONCEPTS
QUESTION 1 OF 25
Encrypting your email is an example of addressing which aspect of the CIA Triad? Correct! You are keeping the contents confidential.
A
ConfidentialityCorrect AnswerB
IntegrityC
AvailabilityQUESTION 2 OF 25
You fail to backup your files and then drop your laptop breaking it into many small pieces. You have just failed to address which aspect of the CIA Triad? Correct! A broken laptop with no backup means your data will not be available to you. 3.The use of digital signatures is an example of which concept? Correct! You know who the message came from and she cannot deny it.
A
ConfidentialityB
IntegrityC
AvailabilityCorrect AnswerA
Non-repudiationCorrect AnswerB
ConfidentialityC
IntegrityD
AvailabilityQUESTION 3 OF 25
Trudy forwards a message from Alice to Bob, but changes the timestamp on Alice's message before sending it to make it look like it came in later. This is a violation of which aspect of the CIA Triad? Correct! Integrity assures that your message was not altered. ACCESS MANAGEMENT
A
ConfidentialityB
IntegrityCorrect AnswerC
AvailabilityQUESTION 4 OF 25
Managers in the Singapore office at your company can access documents that managers in other offices cannot access, nor can non-manager employees in the Singapore office. Which two (2) access criteria types were likely involved in setting this up? Partially correct! Location is used as an access control factor. Partially correct! Managers would be in a managers group. INCIDENT RESPONSE
A
TimeframeB
Physical locationCorrect AnswerC
GroupsCorrect AnswerD
Transaction typeQUESTION 5 OF 25
In incident management, an event that has a negative impact on some aspect of the network or data is called what? Correct! An event with an impact is called an Incident.
A
IncidentCorrect AnswerB
AttackC
ThreatD
EventQUESTION 6 OF 25
In incident management, a data inventory, data classification and data management process are part of which key concept? Correct! It is crucial to have an automated inventory of systems and data so you can know if anything changes or does not belong.
A
Automated systemB
Post-Incident ActivitiesC
Business Continuity Plan & Disaster RecoveryD
E-DiscoveryCorrect AnswerQUESTION 7 OF 25
Which phase of the Incident Response Process do steps like Identify cyber security incident, Define objectives and investigate situation and Take appropriate action fall into? Correct! These are all part of the Respond phase. FRAMEWORKS AND THEIR PURPOSE
A
Phase 1: PrepareB
Phase 2: RespondCorrect AnswerC
Phase 3: Follow UpQUESTION 8 OF 25
In the context of security standards and compliance, which two (2) of these items are goals of frameworks and best practices? Partially correct! The goal is improvement. Partially correct! They can guide you in how this was done successfully before or by others.
A
They serve as an enforcement mechanism for government, industry or clients.B
They are rules to follow for a specific industry.C
They seek to improve performance, controls and metrics.Correct AnswerD
They help translate the business needs into technical or operational needs.Correct AnswerQUESTION 9 OF 25
A company document that says employees may not do online shopping while at work would be which of the following? Correct! This rule would be contained in a company’s policy on Internet access.
A
ProcedureB
PolicyCorrect AnswerC
Strategic PlanD
Tactical PlanQUESTION 10 OF 25
Which three (3) of these are compliance standards that must be adhered to by companies is some industries / countries? Partially correct! SOX is short for Sarbanes-Oxley Act, an accounting law in the United States. Partially correct! HIPPA is short for Health Insurance Portability and Accountability Act, a healthcare data privacy law in the United States. Partially correct! PCI/DSS is short for Payment Card Industry Data Security Standard, an information security standard for those processing credit card transactions.
A
SOXCorrect AnswerB
HIPPACorrect AnswerC
OCTAVED
PCI/DSSCorrect AnswerQUESTION 11 OF 25
A method of evaluating computer and network security by simulating an attack on a computer system or network from external or internal threats is know as which of the following? Correct! Ethical (with permission) penetration testing is a very effective way to assess system security.
A
A threatB
A pentestCorrect AnswerC
A hackD
A white hatQUESTION 12 OF 25
The OWASP “Top 10” provides guidance on what? Correct! OWASP stands for Open Web Application Security Project
A
The top 10 malware exploits reported each year.B
The top 10 application vulnerabilities reported each year.Correct AnswerC
The top 10 network vulnerabilities reported each year.D
The top 10 cybercrimes reported each year.QUESTION 13 OF 25
Which is not part of the Sans Institutes Audit process?
A
Feedback based on the findings.B
Define the audit scope and limitations.C
Help to translate the business needs into technical or operational needs.Correct AnswerD
Deliver a report.QUESTION 14 OF 25
Which key concept to understand incident response is defined as "data inventory, helps to understand the current tech status, data classification, data management, we could use automated systems. Understand how you control data retention and backup."
A
Automated SystemsB
Post-IncidentC
E-DiscoveryCorrect AnswerD
BCP & Disaster RecoveryQUESTION 15 OF 25
Which is not included as part of the IT Governance process?
A
ProceduresB
Tactical PlansC
PoliciesD
AuditsCorrect AnswerQUESTION 16 OF 25
Trudy reading Alice’s message to Bob is a violation of which aspect of the CIA Triad?
A
ConfidentialityCorrect AnswerB
IntegrityC
AvailabilityQUESTION 17 OF 25
A hash is a mathematical algorithm that helps assure which aspect of the CIA Triad?
A
ConfidentialityB
IntegrityCorrect AnswerC
AvailabilityQUESTION 18 OF 25
A successful DOS attack against your company’s servers is a violation of which aspect of the CIA Triad?
A
ConfidentialityB
IntegrityC
AvailabilityCorrect AnswerQUESTION 19 OF 25
Which of these is an example of the concept of non-repudiation?
A
Alice sends a message to Bob with certainty that it will be delivered.B
Alice sends a message to Bob and Alice is certain that it was not read by Trudy.C
Alice sends a message to Bob with certainty that it was not altered while in route by Trudy.D
Alice sends a message to Bob and Bob knows for a certainty that it came from Alice and no one else.Correct AnswerQUESTION 20 OF 25
In incident management, an observed change to the normal behavior of a system, environment or process is called what?
A
IncidentB
AttackC
EventCorrect AnswerD
ThreatQUESTION 21 OF 25
In incident management, tools like SIEM, SOA and UBA are part of which key concept?
A
Post-Incident ActivitiesB
E-DiscoveryC
BCP & Disaster RecoveryD
Automated systemCorrect AnswerQUESTION 22 OF 25
Which phase of the Incident Response Process do steps like Carry out a post incident review and Communicate and build on lessons learned fall into?
A
PrepareB
Follow UpCorrect AnswerC
RespondQUESTION 23 OF 25
A company document that details how an employee should request Internet access for her computer would be which of the following?
A
PolicyB
Tactical PlanC
Strategic PlanD
ProcedureCorrect AnswerQUESTION 24 OF 25
Which of these is a methodology by which to conduct audits?
A
SOXB
HIPPAC
PCI/DSSD
OCTAVECorrect AnswerQUESTION 25 OF 25
Mile 2 CPTE Training teaches you how to do what?
A
Conduct a Ransomware attackB
Advanced network management tasksC
Construct a botnetD
Conduct a pentestCorrect AnswerReady to test your recall?
Encrypting your email is an example of addressing which aspect of the CIA Triad? Correct! You are keeping the contents confidential.
A
Confidentiality
B
Integrity
C
Availability
How confident are you in this answer?