QuiztudyPREMIUM
IBM Cybersecurity Analyst Professional Certificate • STUDY MODE
PRACTICE QUIZ
QUESTION 1 OF 27
Which of the bad guys are described as "They are "in" an organization but are human and make mistakes"? Correct, these bad guys typically inadvertently open and email, etc.
A
Malicious InsidersB
Inadvertant ActorCorrect AnswerC
EmployeesD
OutsidersQUESTION 2 OF 27
Which is NOT one of the security controls? Correct, this is NOT one of the security controls.
A
TestingCorrect AnswerB
TechnicalC
PhysicalD
OperationalQUESTION 3 OF 27
What year did the European Union start enforcing GDPR? Correct, the GDPR came into effect in May of 2018.
A
2018Correct AnswerB
2017C
2016D
2014QUESTION 4 OF 27
Which three (3) of these obligations are part of the 5 key GDPR obligations? Partially correct, this is one of 3 key GDPR obligations. SYSTEM AND ORGANIZATION CONTROLS REPORT (SOC) OVERVIEW
A
Accountability of ComplianceCorrect AnswerB
Security of Public DataC
ConsentCorrect AnswerD
Rights of EU Data SubjectCorrect AnswerQUESTION 5 OF 27
Which is the foundational principle that everyone will get during a SOC audit? Correct, this is the single foundational principle everyone will get. INDUSTRY STANDARDS
A
PrivacyB
AvailabilityC
SecurityCorrect AnswerD
ConfidentialityQUESTION 6 OF 27
The HIPAA security rule requires covered entites to maintain which two (2) reasonable safeguards for protecting e-PHI? Partially correct, this is one of two HIPAA security rule safeguards.
A
InformationalB
TechnicalCorrect AnswerC
OperationalD
PhysicalCorrect AnswerQUESTION 7 OF 27
HIPAA Administrative safeguards include which two (2) of the following? Partially correct, this is one of the administrative safeguards. Partially correct, this is one of the administrative safeguards.
A
Security PersonnelCorrect AnswerB
Workforce Training and ManagementCorrect AnswerC
Access ControlsD
Integrity ControlsQUESTION 8 OF 27
PCI includes 264 requirements grouped under how many main requirements? Correct, PCI includes 12 main requirements. CIS CRITICAL SECURITY CONTROLS
A
5B
10C
12Correct AnswerD
20QUESTION 9 OF 27
If you are a mature organization, which CIS Controls Implementation Group would you use? Correct, Implementation Group 3 is for mature organizations. COMPLIANCE FRAMEWORKS AND INDUSTRY STANDARDS
A
Implementation Group 3Correct AnswerB
Implementation Group 1C
Do not need a controls implementation group due to maturity of my organizationD
Implementation Group 2QUESTION 10 OF 27
A security attack is defined as which of the following?
A
An event on a system or network detected by a device.B
An event that has been reviewed by analysts and deemed worthy of deeper investigation.C
An event that has been identified by correlation and analytics tools as a malicious activity.Correct AnswerD
All cybersecurity events.QUESTION 11 OF 27
Which order does a typical compliance process follow?
A
Readiness assessment, establish scope, testing/auditing, management reporting, gap remediationB
Establish scope, readiness assessment, testing/auditing, management reporting, gap remediationC
Readiness assessment, establish scope, gap remediation, testing/auditing, management reportingD
Establish scope, readiness assessment, gap remediation, testing/auditing, management reportingCorrect AnswerQUESTION 12 OF 27
Under GDPR, who determines the purpose and means of processing of personal data?
A
ControllerCorrect AnswerB
AnalystC
ProcessorD
Data SubjectQUESTION 13 OF 27
Under the International Organization for Standardization (ISO), which standard focuses on Privacy?
A
ISO 27003B
ISO 27018Correct AnswerC
ISO 27017D
ISO 27001QUESTION 14 OF 27
Which SOC report is closest to an ISO report?
A
Type 1Correct AnswerB
Type 2C
Type 1 and Type 2D
Type 3QUESTION 15 OF 27
What is an auditor looking for when they test the control for implementation over an entire offering with no gaps?
A
CompletenessCorrect AnswerB
AccuracyC
TimelinessD
ConsistencyQUESTION 16 OF 27
Who is the governing entity for HIPAA?
A
Cyber Security and Infrastructure Security Agency (CISA)B
Department of Homeland SecurityC
US Department of Health and Human Services Office of Civil RightsCorrect AnswerD
US LegislatureQUESTION 17 OF 27
One PCI Requirement is using an approved scanning vendor to scan at what frequency?
A
WeeklyB
MonthlyC
QuarterlyCorrect AnswerD
AnnuallyQUESTION 18 OF 27
In which CIS control category will you find Incident Response and Management?
A
AdvancedB
BasicC
OrganizationalCorrect AnswerD
FoundationalQUESTION 19 OF 27
Which of the bad guys are described as “They are “in” an organization but are human and make mistakes”?
A
Malicious InsidersB
Inadvertant ActorCorrect AnswerC
EmployeesD
OutsidersQUESTION 20 OF 27
Which is NOT one of the security controls?
A
TestingCorrect AnswerB
TechnicalC
PhysicalD
OperationalQUESTION 21 OF 27
What year did the European Union start enforcing GDPR?
A
2018Correct AnswerB
2017C
2016D
2014QUESTION 22 OF 27
Which three (3) of these obligations are part of the 5 key GDPR obligations?
A
Accountability of ComplianceCorrect AnswerB
Security of Public DataC
ConsentCorrect AnswerD
Rights of EU Data SubjectCorrect AnswerQUESTION 23 OF 27
Which is the foundational principle that everyone will get during a SOC audit?
A
PrivacyB
AvailabilityC
SecurityCorrect AnswerD
ConfidentialityQUESTION 24 OF 27
The HIPAA security rule requires covered entites to maintain which two (2) reasonable safeguards for protecting e-PHI?
A
InformationalB
TechnicalCorrect AnswerC
OperationalD
PhysicalCorrect AnswerQUESTION 25 OF 27
HIPAA Administrative safeguards include which two (2) of the following?
A
Security PersonnelCorrect AnswerB
Workforce Training and ManagementCorrect AnswerC
Access ControlsD
Integrity ControlsQUESTION 26 OF 27
PCI includes 264 requirements grouped under how many main requirements?
A
5B
10C
12Correct AnswerD
20QUESTION 27 OF 27
If you are a mature organization, which CIS Controls Implementation Group would you use?
A
Implementation Group 3Correct AnswerB
Implementation Group 1C
Do not need a controls implementation group due to maturity of my organizationD
Implementation Group 2Ready to test your recall?
Which of the bad guys are described as "They are "in" an organization but are human and make mistakes"? Correct, these bad guys typically inadvertently open and email, etc.
A
Malicious Insiders
B
Inadvertant Actor
C
Employees
D
Outsiders
How confident are you in this answer?