🌍 All Study Guides📊 Dashboard📰 Blog💡 About
IBM Cybersecurity Analyst Professional Certificate • STUDY MODE

PRACTICE QUIZ

QUESTION 1 OF 70

What are the four (4) main types of actors identified in the video A brief overview of types of actors and their motives? Partially correct! Hactivists may be motivated by money, but more often by political concerns of some sort. Partially correct! Government or "nation-state" actors are becoming increasingly active and are an increasing threat. Partially correct! Hackers definately are prominent actors and are usually motivated by money. Partially correct! Internal actors do cause a lot of damage. They have a head start when it comes to knowledge and access.

A
HactivistsCorrect Answer
B
GovernmentsCorrect Answer
C
Black Hats
D
Security Analysts
E
White Hats
F
HackersCorrect Answer
G
InternalCorrect Answer
QUESTION 2 OF 70

Which of these common motivations is often attributed to a hactivist? Correct! The hactivism movement is often poitically motivated.

A
Money
B
Just playing around
C
Hire me!
D
Political action and movementsCorrect Answer
QUESTION 3 OF 70

In the video Hacking organizations, which three (3) governments were called out as being active hackers? Partially correct! China is very active. Partially correct! Yes, Israel is active among governments with hacking organizations. Partially correct! The NSA is known to be active.

A
Venezuela
B
ChinaCorrect Answer
C
IsraelCorrect Answer
D
United StatesCorrect Answer
E
Canada
QUESTION 4 OF 70

Which four (4) of the following are known hacking organizations?

A
Syrian Electronic ArmyCorrect Answer
B
Fancy BearsCorrect Answer
C
Guardians of PeaceCorrect Answer
D
AnonymousCorrect Answer
E
The Ponemon Institute
QUESTION 5 OF 70

Which of these hacks resulted in over 100 million credit card numbers being stolen? Correct! Over 100 million credit card numbers were stolen. AN ARCHITECT'S PERSPECTIVE ON ATTACK CLASSIFICATIONS

A
2011 Sony Playstation hack
B
2013 Singapore Cyberattacks
C
2014 Ebay hack
D
2015 Target Stores hackCorrect Answer
E
2016 US Election hack
QUESTION 6 OF 70

Which of the following statements is True?

A
Passive attacks are easy to detect because the original message wrapper must be modified by the attacker before it is forwarded on to the intended recipient.
B
Passive attacks are hard to detect because the original message is delivered unchanged and can pass an integrity check.Correct Answer
C
Passive attacks are hard to detect because the original message is never delivered so the receiving does not know they missed anything.
D
Passive attacks are easy to detect because of the latency created by the interception and second forwarding.
QUESTION 7 OF 70

The purpose of security services includes which three (3) of the following?

A
Often replicate functions found in physical documentsCorrect Answer
B
Includes any component of your security infrastructure that has been outsourced to a third-party
C
Enhance security of data processing systems and information transfer.Correct Answer
D
Are intended to counter security attacks.Correct Answer
QUESTION 8 OF 70

Which statement best describes access control?

A
Protection against denial by one of the parties in communication
B
Prevention of unauthorized use of a resourceCorrect Answer
C
Assurance that the communicating entity is the one claimed
D
Protection against the unauthorized disclosure of data
QUESTION 9 OF 70

The International Telecommunication Union (ITU) X.800 standard addresses which three (3) of the following topics? Partially correct! I addresses protecting data from unauthorized access. Partially correct! It addresses the protection of data from unauthorized disclosure. Partially correct! Both peer-entity and data origin authentication.

A
Access ControlCorrect Answer
B
Data transmission speeds
C
Data ConfidentialityCorrect Answer
D
Transmission cost sharing between member countries
E
AuthenticationCorrect Answer
QUESTION 10 OF 70

Protocol suppression, ID and authentication are examples of which? Correct! These are the technical implementation of the Security Policy

A
Security PolicyCorrect Answer
B
Security Mechanism
C
Business Policy
D
Security Architecture
QUESTION 11 OF 70

The motivation for more security in open systems is driven by which three (3) of the following factors? Partially correct! The spread of OSI recommendations brings with it the need for enhanced security. Partially correct! Think GDPR. Partially correct! Especially those that are connected to the Internet.

A
New requirements from the WTO, World Trade Organization
B
The desire by a number of organizations to use OSI recommendations.Correct Answer
C
The appearence of data protection legislation in several countries.Correct Answer
D
Society)s increasing dependance on computers.Correct Answer
QUESTION 12 OF 70

True or False: The accidental disclosure of confidential data by an employee is considered a legitimate organizational threat. Correct! Not all threats are intentional

A
TrueCorrect Answer
B
False
QUESTION 13 OF 70

True or False: The accidental disclosure of confidential information by an employee is considered an attack. Correct. An attack has to be an intentional attempt to violate security.

A
True
B
FalseCorrect Answer
QUESTION 14 OF 70

A replay attack and a denial of service attack are examples of which? Correct! These are both attacks against the security architecture itself.

A
Security architecture attackCorrect Answer
B
Origin attack
C
Passive attack
D
Masquerade attack
QUESTION 15 OF 70

The International Telecommunication Union is an organization that is described by which of the following statements? MALWARE AND AN INTRODUCTION TO THREAT PROTECTION

A
The ITU is an organization charted and staffed by the United Nations to maintain international standards, such as X.800, for telecommunication.Correct Answer
B
The ITU is an industry organization founded by the largest telecommunication companies in the world and focused on lobbying governments on their behalf.
C
The ITU is a partnership of the national telephone companies of most European countries intended to help compete against the largest American telecomms.
D
The ITU is a workers union focused on ensuring the welfare of telecommunication workers.
QUESTION 16 OF 70

True or False: An application that runs on your computer without your authorization but does no damage to the system is not considered malware. Correct! Adware and Spyware often do not damage the host but are definitely considered Malware.

A
True
B
FalseCorrect Answer
QUESTION 17 OF 70

How would you classify a piece of malicious code designed to cause damage and spreads from one computer to another by attaching itself to files but requires human actions in order to replicate? Correct! A virus requires action on the part of the user in order to replicate and spread.

A
VirusCorrect Answer
B
Worms
C
Trojan Horses
D
Spyware
E
Adware
F
Ransomware
QUESTION 18 OF 70

How would you classify a piece of malicious code designed collect data about a computer and its users and then report that back to a malicious actor? Correct! These are designed to spy on the host system and collect data about its users.

A
Virus
B
Worms
C
SpywareCorrect Answer
D
Adware
QUESTION 19 OF 70

A large scale Denial of Service attack usually relies upon which of the following? Correct! Many servers are required to implement an effective DoS attack - far more than could be managed manually.

A
A botnetCorrect Answer
B
A keylogger
C
Logic Bombs
D
Trojan Horses
QUESTION 20 OF 70

Antivirus software can be classified as which form of threat control? Correct! Antivirus software is a technology that can be deployed to help mitigate cyber threats. ADDITIONAL ATTACK EXAMPLES TODAY

A
Technical controlsCorrect Answer
B
Administrative controls
C
Active controls
D
Passive controls
QUESTION 21 OF 70

Which of the following measures can be used to counter a mapping attack? Correct! All 3 of these options can and should be used.

A
Record traffic entering the network
B
Look for suspicious activity like IP addresses or ports being scanned sequentially.
C
Use a host scanner and keep an inventory of hosts on your network.
D
All of the above.Correct Answer
QUESTION 22 OF 70

In order for a network card (NIC) to engage in packet sniffing, it must be running in which mode? Correct, the NIC must be running in promiscuous mode.

A
PromiscuousCorrect Answer
B
Sniffer
C
Inspection
D
Open
QUESTION 23 OF 70

Which countermeasure can be helpful in combating an IP Spoofing attack? Correct! This works but only if all routers use it.

A
Ingress filteringCorrect Answer
B
Enable IP Packet Authentication filtering
C
Keep your certificates up-to-date
D
Enable the IP Spoofing feature available in most commercial antivirus software.
E
All of the above.
QUESTION 24 OF 70

Which two (2) measures can be used to counter a Denial of Service (DOS) attack? Partially correct! The downside here is that the source is most likely innocent but compromised machines. Partially correct! The downside is that you will be filtering out some legitimate packets as well.

A
Enable packet filtering on your firewall.
B
Use traceback to identify the source of the flooded packets.Correct Answer
C
Implement a filter to remove flooded packets before they reach the host.Correct Answer
D
Enable the DOS Filtering option now available on most routers and switches.
QUESTION 25 OF 70

Which countermeasure should be used agains a host insertion attack? Correct! All of these steps are necessary. ATTACKS AND CYBER RESOURCES

A
Maintain an accurate inventory of of computer hosts by MAC address.
B
Use a host scanning tool to match a list of discovered hosts against known hosts.
C
Investigate newly discovered hosts.
D
All of the above.Correct Answer
QUESTION 26 OF 70

Which is not one of the phases of the intrusion kill chain? Correct! Activation is not part if the intrusion kill chain

A
ActivationCorrect Answer
B
Command and Control
C
Installation
D
Delivery
QUESTION 27 OF 70

Which social engineering attack involves a person instead of a system such as an email server? Correct! a vishing attack often is conducted over the phone.

A
Phishing
B
Spectra
C
Cyberwarfare
D
VishingCorrect Answer
QUESTION 28 OF 70

Which of the following is an example of a social engineering attack? Correct! Talking someone into doing something they should not do is social engineering.

A
Setting up a web site offering free games, but infecting the downloads with malware.
B
Calling an employee and telling him you are from IT support and must observe him logging into his corporate account.Correct Answer
C
Logging in to the Army)s missle command computer and launching a nuclear weapon.
D
Sending someone an email with a Trojan Horse attachment.
QUESTION 29 OF 70

True or False: While many countries are preparing their military for a future cyberwar, there have been no "cyber battles" to-date. Correct! There have been hundreds attacks that can be considered acts of cyberwarfare conducted by many countries, includeing the United States, China, Israel, Russia, Iran, etc. A DAY IN THE LIFE OF A SOC ANALYST

A
True
B
FalseCorrect Answer
QUESTION 30 OF 70

Which tool did Javier say was crucial to his work as a SOC analyst? Correct! Tools like QRadar SIEM are crucial to Javier since he can use it to perform advanced corrolations and threat intelligence integration. A BRIEF OVERVIEW OF TYPES OF ACTORS AND THEIR MOTIVES

A
SIEM (Security Information and Event Management)Correct Answer
B
Packet Sniffers
C
Firewalls
D
Intrusion detection software
QUESTION 31 OF 70

Which hacker organization hacked into the Democratic National Convention and released Hillary Clinton's emails?

A
Fancy BearsCorrect Answer
B
Anonymous
C
Syrian Electronic Army
D
Guardians of the Peace
E
All of the above
QUESTION 32 OF 70

What challenges are expected in the future?

A
Enhanced espionage from more countries
B
Far more advanced malware
C
New consumer technology to exploit
D
All of the aboveCorrect Answer
QUESTION 33 OF 70

Why are cyber attacks using SWIFT so dangerous?

A
SWIFT is the protocol used by all banks to transfer moneyCorrect Answer
B
SWIFT is the flight plan and routing system used by all cooperating nations for international commercial flights
C
SWIFT is the protocol used to transmit all diplomatic telegrams between governments around the world
D
SWIFT is the protocol used by all US healthcare providers to encrypt medical records
QUESTION 34 OF 70

Which statement best describes Authentication?

A
Assurance that the communicating entity is the one claimedCorrect Answer
B
Prevention of unauthorized use of a resource
C
Assurance that a resource can be accessed and used
D
Protection against denial by one of the parties in communication
QUESTION 35 OF 70

Trusted functionality, security labels, event detection, security audit trails and security recovery are all examples of which type of security mechanism?

A
Active security mechanism
B
External security mechanism
C
Passive security mechanismCorrect Answer
D
Contingent security mechanism
QUESTION 36 OF 70

If an organization responds to an intentional threat, that threat is now classified as what?

A
An attackCorrect Answer
B
An active threat
C
An open case
D
A malicious threat
QUESTION 37 OF 70

An attack that is developed particularly for a specific customer and occurs over a long period of time is a form of what type of attack?

A
Denial of Service (DOS)
B
Advanced Persistent ThreatCorrect Answer
C
Water Hole
D
Spectra
QUESTION 38 OF 70

A political motivation is often attributed to which type of actor?

A
Security Analysts
B
Internal
C
Hackers
D
HactivistCorrect Answer
QUESTION 39 OF 70

The video Hacking organizations called out several countries with active government sponsored hacking operations in effect. Which one of these was among those named?

A
Canada
B
Egypt
C
IsraelCorrect Answer
D
South Africa
QUESTION 40 OF 70

Which of these is not a known hacking organization?

A
The Ponemon InstituteCorrect Answer
B
Fancy Bears
C
Syrian Electronic Army
D
Anonymous
E
Guardians of the Peace
QUESTION 41 OF 70

Which type of actor hacked the 2016 US Presidential Elections?

A
GovernmentCorrect Answer
B
Internal
C
Hactivists
D
Hackers
QUESTION 42 OF 70

True or False: Passive attacks are easy to detect because the original messages are usually altered or undelivered.

A
FalseCorrect Answer
B
True
QUESTION 43 OF 70

True or False: Authentication, Access Control and Data Confidentiality are all addressed by the ITU X.800 standard.

A
TrueCorrect Answer
B
False
QUESTION 44 OF 70

True or False: Only acts performed with intention to do harm can be classified as Organizational Threats

A
FalseCorrect Answer
B
True
QUESTION 45 OF 70

How would you classify a piece of malicious code designed to cause damage, can self-replicate and spreads from one computer to another by attaching itself to files?

A
Virus
B
WormCorrect Answer
C
Spyware
D
Trojan Horse
E
Adware
F
Ransomware
QUESTION 46 OF 70

Botnets can be used to orchestrate which form of attack?

A
Distribution of Spam
B
DDoS attacks
C
Phishing attacks
D
Distribution of Spyware
E
As a Malware launchpad
F
All of the aboveCorrect Answer
QUESTION 47 OF 70

Policies and training can be classified as which form of threat control?

A
Technical controls
B
Administrative controlsCorrect Answer
C
Passive controls
D
Active controls
QUESTION 48 OF 70

Which type of attack can be addressed using a switched Ethernet gateway and software on every host on your network that makes sure their NICs is not running in promiscuous mode.

A
Packet SniffingCorrect Answer
B
Host Insertion
C
Trojan Horse
D
Ransomware
E
All of the above
QUESTION 49 OF 70

A flood of maliciously generated packets swamp a receiver’s network interface preventing it from responding to legitimate traffic. This is characteristic of which form of attack?

A
A Denial of Service (DOS) attackCorrect Answer
B
A Trojan Horse
C
A Masquerade attack
D
A Ransomware attack
QUESTION 50 OF 70

A person calls you at work and tells you he is a lawyer for your company and that you need to send him specific confidential company documents right away, or else! Assuming the caller is not really a lawyer for your company but a bad actor, what kind of attack is this?

A
A Social Engineering attackCorrect Answer
B
A Trojan Horse
C
A Denial of Service attack
D
A Worm attack
QUESTION 51 OF 70

Which type of actor was not one of the four types of actors mentioned in the video A brief overview of types of actors and their motives?

A
Hactivists
B
Governments
C
Hackers
D
Internal
E
Black HatsCorrect Answer
QUESTION 52 OF 70

Cryptography, digital signatures, access controls and routing controls considered which?

A
Business Policy
B
Security Policy
C
Specific security mechanismsCorrect Answer
D
Pervasive security mechanisms
QUESTION 53 OF 70

Traffic flow analysis is classified as which?

A
An active attack
B
A passive attackCorrect Answer
C
An origin attack
D
A masquerade attack
QUESTION 54 OF 70

True or False: An individual hacks into a military computer and uses it to launch an attack on a target he personally dislikes. This is considered an act of cyberwarfare.

A
FalseCorrect Answer
B
True
QUESTION 55 OF 70

What are the four (4) main types of actors identified in the video A brief overview of types of actors and their motives?

A
HactivistsCorrect Answer
B
GovernmentsCorrect Answer
C
Black Hats
D
Security Analysts
E
White Hats
F
Hackers InternalCorrect Answer
QUESTION 56 OF 70

Which of these common motivations is often attributed to a hacktivist?

A
Money
B
Just playing around
C
Hire me!
D
Political action and movementsCorrect Answer
QUESTION 57 OF 70

In the video Hacking organizations, which three (3) governments were called out as being active hackers?

A
Venezuela
B
ChinaCorrect Answer
C
IsraelCorrect Answer
D
United StatesCorrect Answer
E
Canada
QUESTION 58 OF 70

Which of these hacks resulted in over 100 million credit card numbers being stolen?

A
2011 Sony Playstation hack
B
2013 Singapore Cyberattacks
C
2014 Ebay hack
D
2015 Target Stores hackCorrect Answer
E
2016 US Election hack
QUESTION 59 OF 70

The International Telecommunication Union (ITU) X.800 standard addresses which three (3) of the following topics?

A
Access ControlCorrect Answer
B
Data transmission speeds
C
Data ConfidentialityCorrect Answer
D
Transmission cost sharing between member countries
E
AuthenticationCorrect Answer
QUESTION 60 OF 70

Protocol suppression, ID and authentication are examples of which?

A
Security PolicyCorrect Answer
B
Security Mechanism
C
Business Policy
D
Security Architecture
QUESTION 61 OF 70

The motivation for more security in open systems is driven by which three (3) of the following factors?

A
New requirements from the WTO, World Trade Organization
B
The desire by a number of organizations to use OSI recommendations.Correct Answer
C
The appearence of data protection legislation in several countries.Correct Answer
D
Society’s increasing dependance on computers.Correct Answer
QUESTION 62 OF 70

True or False: The accidental disclosure of confidential data by an employee is considered a legitimate organizational threat.

A
TrueCorrect Answer
B
False
QUESTION 63 OF 70

True or False: The accidental disclosure of confidential information by an employee is considered an attack.

A
True
B
FalseCorrect Answer
QUESTION 64 OF 70

A replay attack and a denial of service attack are examples of which?

A
Security architecture attackCorrect Answer
B
Origin attack
C
Passive attack
D
Masquerade attack
QUESTION 65 OF 70

The International Telecommunication Union is an organization that is described by which of the following statements?

A
The ITU is an organization charted and staffed by the United Nations to maintain international standards, such as X.800, for telecommunication.Correct Answer
B
The ITU is an industry organization founded by the largest telecommunication companies in the world and focused on lobbying governments on their behalf.
C
The ITU is a partnership of the national telephone companies of most European countries intended to help compete against the largest American telecom.
D
The ITU is a workers union focused on ensuring the welfare of telecommunication workers.
QUESTION 66 OF 70

True or False: An application that runs on your computer without your authorization but does no damage to the system is not considered malware.

A
True
B
FalseCorrect Answer
QUESTION 67 OF 70

How would you classify a piece of malicious code designed to cause damage and spreads from one computer to another by attaching itself to files but requires human actions in order to replicate?

A
VirusCorrect Answer
B
Worms
C
Trojan Horses
D
Spyware
E
Adware
F
Ransomware
QUESTION 68 OF 70

How would you classify a piece of malicious code designed collect data about a computer and its users and then report that back to a malicious actor?

A
Virus
B
Worms
C
SpywareCorrect Answer
D
Adware
QUESTION 69 OF 70

A large scale Denial of Service attack usually relies upon which of the following?

A
A botnetCorrect Answer
B
A keylogger
C
Logic  Bombs
D
Trojan Horses
QUESTION 70 OF 70

Antivirus software can be classified as which form of threat control?

A
Technical controlsCorrect Answer
B
Administrative controls
C
Active controls
D
Passive controls

Ready to test your recall?

What are the four (4) main types of actors identified in the video A brief overview of types of actors and their motives? Partially correct! Hactivists may be motivated by money, but more often by political concerns of some sort. Partially correct! Government or "nation-state" actors are becoming increasingly active and are an increasing threat. Partially correct! Hackers definately are prominent actors and are usually motivated by money. Partially correct! Internal actors do cause a lot of damage. They have a head start when it comes to knowledge and access.

💡Select all 4 correct answers before submitting (0 of 4 selected).
A
Hactivists
B
Governments
C
Black Hats
D
Security Analysts
E
White Hats
F
Hackers
G
Internal

How confident are you in this answer?