🌍 All Study Guides📊 Dashboard📰 Blog💡 About
IBM Cybersecurity Analyst Professional Certificate • STUDY MODE

PRACTICE QUIZ

QUESTION 1 OF 27

Which of the bad guys are described as "They are "in" an organization but are human and make mistakes"? Correct, these bad guys typically inadvertently open and email, etc.

A
Malicious Insiders
B
Inadvertant ActorCorrect Answer
C
Employees
D
Outsiders
QUESTION 2 OF 27

Which is NOT one of the security controls? Correct, this is NOT one of the security controls.

A
TestingCorrect Answer
B
Technical
C
Physical
D
Operational
QUESTION 3 OF 27

What year did the European Union start enforcing GDPR? Correct, the GDPR came into effect in May of 2018.

A
2018Correct Answer
B
2017
C
2016
D
2014
QUESTION 4 OF 27

Which three (3) of these obligations are part of the 5 key GDPR obligations? Partially correct, this is one of 3 key GDPR obligations. SYSTEM AND ORGANIZATION CONTROLS REPORT (SOC) OVERVIEW

A
Accountability of ComplianceCorrect Answer
B
Security of Public Data
C
ConsentCorrect Answer
D
Rights of EU Data SubjectCorrect Answer
QUESTION 5 OF 27

Which is the foundational principle that everyone will get during a SOC audit? Correct, this is the single foundational principle everyone will get. INDUSTRY STANDARDS

A
Privacy
B
Availability
C
SecurityCorrect Answer
D
Confidentiality
QUESTION 6 OF 27

The HIPAA security rule requires covered entites to maintain which two (2) reasonable safeguards for protecting e-PHI? Partially correct, this is one of two HIPAA security rule safeguards.

A
Informational
B
TechnicalCorrect Answer
C
Operational
D
PhysicalCorrect Answer
QUESTION 7 OF 27

HIPAA Administrative safeguards include which two (2) of the following? Partially correct, this is one of the administrative safeguards. Partially correct, this is one of the administrative safeguards.

A
Security PersonnelCorrect Answer
B
Workforce Training and ManagementCorrect Answer
C
Access Controls
D
Integrity Controls
QUESTION 8 OF 27

PCI includes 264 requirements grouped under how many main requirements? Correct, PCI includes 12 main requirements. CIS CRITICAL SECURITY CONTROLS

A
5
B
10
C
12Correct Answer
D
20
QUESTION 9 OF 27

If you are a mature organization, which CIS Controls Implementation Group would you use? Correct, Implementation Group 3 is for mature organizations. COMPLIANCE FRAMEWORKS AND INDUSTRY STANDARDS

A
Implementation Group 3Correct Answer
B
Implementation Group 1
C
Do not need a controls implementation group due to maturity of my organization
D
Implementation Group 2
QUESTION 10 OF 27

A security attack is defined as which of the following?

A
An event on a system or network detected by a device.
B
An event that has been reviewed by analysts and deemed worthy of deeper investigation.
C
An event that has been identified by correlation and analytics tools as a malicious activity.Correct Answer
D
All cybersecurity events.
QUESTION 11 OF 27

Which order does a typical compliance process follow?

A
Readiness assessment, establish scope, testing/auditing, management reporting, gap remediation
B
Establish scope, readiness assessment, testing/auditing, management reporting, gap remediation
C
Readiness assessment, establish scope, gap remediation, testing/auditing, management reporting
D
Establish scope, readiness assessment, gap remediation, testing/auditing, management reportingCorrect Answer
QUESTION 12 OF 27

Under GDPR, who determines the purpose and means of processing of personal data?

A
ControllerCorrect Answer
B
Analyst
C
Processor
D
Data Subject
QUESTION 13 OF 27

Under the International Organization for Standardization (ISO), which standard focuses on Privacy?

A
ISO 27003
B
ISO 27018Correct Answer
C
ISO 27017
D
ISO 27001
QUESTION 14 OF 27

Which SOC report is closest to an ISO report?

A
Type 1Correct Answer
B
Type 2
C
Type 1 and Type 2
D
Type 3
QUESTION 15 OF 27

What is an auditor looking for when they test the control for implementation over an entire offering with no gaps?

A
CompletenessCorrect Answer
B
Accuracy
C
Timeliness
D
Consistency
QUESTION 16 OF 27

Who is the governing entity for HIPAA?

A
Cyber Security and Infrastructure Security Agency (CISA)
B
Department of Homeland Security
C
US Department of Health and Human Services Office of Civil RightsCorrect Answer
D
US Legislature
QUESTION 17 OF 27

One PCI Requirement is using an approved scanning vendor to scan at what frequency?

A
Weekly
B
Monthly
C
QuarterlyCorrect Answer
D
Annually
QUESTION 18 OF 27

In which CIS control category will you find Incident Response and Management?

A
Advanced
B
Basic
C
OrganizationalCorrect Answer
D
Foundational
QUESTION 19 OF 27

Which of the bad guys are described as “They are “in” an organization but are human and make mistakes”?

A
Malicious Insiders
B
Inadvertant ActorCorrect Answer
C
Employees
D
Outsiders
QUESTION 20 OF 27

Which is NOT one of the security controls?

A
TestingCorrect Answer
B
Technical
C
Physical
D
Operational
QUESTION 21 OF 27

What year did the European Union start enforcing GDPR?

A
2018Correct Answer
B
2017
C
2016
D
2014
QUESTION 22 OF 27

Which three (3) of these obligations are part of the 5 key GDPR obligations?

A
Accountability of ComplianceCorrect Answer
B
Security of Public Data
C
ConsentCorrect Answer
D
Rights of EU Data SubjectCorrect Answer
QUESTION 23 OF 27

Which is the foundational principle that everyone will get during a SOC audit?

A
Privacy
B
Availability
C
SecurityCorrect Answer
D
Confidentiality
QUESTION 24 OF 27

The HIPAA security rule requires covered entites to maintain which two (2) reasonable safeguards for protecting e-PHI?

A
Informational
B
TechnicalCorrect Answer
C
Operational
D
PhysicalCorrect Answer
QUESTION 25 OF 27

HIPAA Administrative safeguards include which two (2) of the following?

A
Security PersonnelCorrect Answer
B
Workforce Training and ManagementCorrect Answer
C
Access Controls
D
Integrity Controls
QUESTION 26 OF 27

PCI includes 264 requirements grouped under how many main requirements?

A
5
B
10
C
12Correct Answer
D
20
QUESTION 27 OF 27

If you are a mature organization, which CIS Controls Implementation Group would you use?

A
Implementation Group 3Correct Answer
B
Implementation Group 1
C
Do not need a controls implementation group due to maturity of my organization
D
Implementation Group 2

Ready to test your recall?

Which of the bad guys are described as "They are "in" an organization but are human and make mistakes"? Correct, these bad guys typically inadvertently open and email, etc.

A
Malicious Insiders
B
Inadvertant Actor
C
Employees
D
Outsiders

How confident are you in this answer?