IBM Cybersecurity Analyst Professional Certificate • STUDY MODE
PRACTICE QUIZ
QUESTION 1 OF 43
A student's grades should be visible to that student when she logs in to her university account. Her ability to see her grades is an example of which aspect of the CIA Triad?
A
Authorization
B
Integrity
C
Confidentiality
D
AvailabilityCorrect Answer
QUESTION 2 OF 43
A university has implemented practices that ensure all student data are encrypted while stored on university servers. Which aspect of the CIA Triad does this practice support?
A
Availability
B
Authorization
C
ConfidentialityCorrect Answer
D
Integrity
QUESTION 3 OF 43
The Student Portal of a university issues a confirmation code with a hash value each time a student submits an assignment using the portal. This is an example of which aspect of the CIA Triad?
A
Confidentiality
B
Availability
C
IntegrityCorrect Answer
D
Authorization
QUESTION 4 OF 43
True or False. An organization has "air gapped" its small network of critical data servers so they are accessible internally but not to any external system. These systems are now safe from a deliberate attack.
A
True
B
FalseCorrect Answer
QUESTION 5 OF 43
C-level executives face 4 challenges when assuring their organizations maintain a comprehensive, workable data security solution. The proliferation of smartphones used for work would impact which two (2) of these concerns the most? (Select 2)
A
A cybersecurity skills shortage
B
Explosive data growthCorrect Answer
C
Operational complexity
D
New privacy regulationsCorrect Answer
QUESTION 6 OF 43
True or False. An organization is subject to both GDPR and PCI-DSS data security regulations and has dedicated all of its efforts in remaining in compliance with these 2 sets of regulations. They are correct in believing that their data is safe.
A
True
B
FalseCorrect Answer
QUESTION 7 OF 43
True or False. A newly hired CISO made the right choice when he moved the Known Vulnerabilities list to a high priority for his team to resolve even though none of these had ever been exploited on the company)s network to-date.
A
TrueCorrect Answer
B
False
QUESTION 8 OF 43
All industries have their own unique data security challenges. Which of these industries has a particular concern with HIPAA compliance and the highest cost per breached record?
A
Retail
B
Financial
C
Transportation
D
HealthcareCorrect Answer
QUESTION 9 OF 43
All industries have their own unique data security challenges. Which of these industries has a particular concern with being targeted more than any other by cybercriminals "because that is where the money is"?
A
FinancialCorrect Answer
B
Healthcare
C
Transportation
D
Retail
QUESTION 10 OF 43
Which three (3) of these are among the top 12 capabilities that a good data security and protection solution should provide? (Select 3)
A
Data discoveryCorrect Answer
B
Role based access control
C
Data risk analysisCorrect Answer
D
Blocking, masking and quarantiningCorrect Answer
QUESTION 11 OF 43
Parsing discovered data against known patterns or key words is a process known as what?
A
Data risk analysis
B
Data classificationCorrect Answer
C
Vulnerability assessment
D
Data discovery
QUESTION 12 OF 43
Which data protection process takes data activity monitoring output and uses it to generate insights about threats?
A
Data classification
B
Active analyticsCorrect Answer
C
Data discovery
D
Vulnerability assessment
QUESTION 13 OF 43
True or False. The IBM Guardium administrator needs to be someone with the highest level of access to the data being protected?
MOBILE ENDPOINT PROTECTION KNOWLEDGE CHECK
A
True
B
FalseCorrect Answer
QUESTION 14 OF 43
Which mobile operating system runs the majority of smartphones today?
A
iOS
B
AndroidCorrect Answer
C
Blackberry
D
Windows
QUESTION 15 OF 43
Which mobile operating system runs approximately 60% of tablet computers worldwide?
A
iOSCorrect Answer
B
Blackberry
C
Windows
D
Android
QUESTION 16 OF 43
True or False. Security is enhanced on iOS mobile devices because users typically cannot interact directly with the operating system.
A
TrueCorrect Answer
B
False
QUESTION 17 OF 43
Which statement best describes the use of anti-virus software on mobile devices?
A
Mobile devices provide native security that makes additional anti-virus software unnecessary.
B
Antivirus software is very effective on mobile devices because it can inspect the data that is associated with each app that is running.
C
Antivirus software can "see" the apps that are running on a mobile device but cannot see the data that is associated with each app.Correct Answer
D
Antivirus software is very effective on mobile devices because it can inspect the data that is associated with each app but only while the app is not running.
QUESTION 18 OF 43
Which type of threat is Jailbreaking?
DATA LOSS PREVENTION AND MOBILE ENDPOINT PROTECTION GRADED ASSESSMENT
A
External
B
System basedCorrect Answer
C
Internal
D
App based
QUESTION 19 OF 43
Which mobile operating system was originally based on the Linux kernel?
A
AndroidCorrect Answer
B
Blackberry
C
Windows
D
iOS
QUESTION 20 OF 43
Which two (2) mobile operating combined dominate the vast majority of the smartphone market? (Select 2)
A
iOSCorrect Answer
B
Windows
C
Blackberry
D
AndroidCorrect Answer
QUESTION 21 OF 43
True or False. Security is enhanced on Android mobile devices because users interact directly with the operating system.
A
True
B
FalseCorrect Answer
QUESTION 22 OF 43
What is one limitation to the operation of anti-virus software running on mobile devices?
A
Mobile devices provide native security that makes additional anti-virus software unnecessary.
B
Antivirus software is very effective on mobile devices because it can inspect the data that is associated with each app but only while the app is not running.
C
Antivirus software must be granted permission to inspect each app on a device.
D
Antivirus software can "see" the apps that are running on a mobile device but cannot see the data that is associated with each app.Correct Answer
QUESTION 23 OF 43
On a mobile device, which type of threat is a phishing scam?
A
External
B
Internal
C
App basedCorrect Answer
D
System based
QUESTION 24 OF 43
A university uses clustered servers to make sure students will always be able to submit their assignments even if one server is down for maintenance. Server clustering enables which aspect of the CIA Triad?
A
Confidentiality
B
AvailabilityCorrect Answer
C
Integrity
D
Authorization
QUESTION 25 OF 43
A university has enabled WPA2 encryption on its WiFi systems throughout the campus. Which aspect of the CIA Triad is directly supported by this action?
A
Integrity
B
ConfidentialityCorrect Answer
C
Availability
D
Authorization
QUESTION 26 OF 43
A student can see her grades via her school)s Student Portal but is unable to change them. This restriction is in support of which aspect of the CIA Triad?
A
Confidentiality
B
IntegrityCorrect Answer
C
Authorization
D
Availability
QUESTION 27 OF 43
True or False. An operator who corrupts data by mistake is considered an "inadvertent attack" that should be considered when developing data protection plans.
A
TrueCorrect Answer
B
False
QUESTION 28 OF 43
C-level executives face 4 challenges when assuring their organizations maintain a comprehensive and workable data security solution. GDPR, CCPA, and PCC-DSS are concerned with which one of these challenges?
A
A cybersecurity skills shortage
B
Operational complexity
C
Explosive data growth
D
New privacy regulationsCorrect Answer
QUESTION 29 OF 43
True of False. A biotech research company with a very profitable product line has grown so rapidly it has acquired a marketing company, a small IT services company and a company that specializes in pharmaceutical manufacturing and distribution. The CEO of the parent company made a good decision when he decided not to consolidate all data security under a single CISO, believing that each of the new divisions understands its own data security needs better than the parent company possibly could.
A
True
B
FalseCorrect Answer
QUESTION 30 OF 43
Which three (3) of these are among the 5 common pitfalls of data security? (Select 3)
A
Failure to address known vulnerabilitiesCorrect Answer
B
Failure to decentralize the data security function
C
Failure to prioritize and leverage data activity monitoringCorrect Answer
D
Failure to move beyond complianceCorrect Answer
QUESTION 31 OF 43
All industries have their own unique data security challenges. Which of these industries has a particular concern with a widely distributed IT infrastructure that must provide services across a multiple government jurisdictions while not violating the privacy concerns of its users?
A
Healthcare
B
TransportationCorrect Answer
C
Retail
D
Financial
QUESTION 32 OF 43
Which is the data protection process that addresses inappropriate privileges, insecure authentication methods, account sharing, configuration files and missing security patches?
A
Data risk analysis
B
Vulnerability assessmentCorrect Answer
C
Data classification
D
Data discovery
QUESTION 33 OF 43
Which data protection process substitutes key data with a token that is issued by a trusted third-party where the token can be accessed but not redeemed by an untrusted party?
A
Data classification
B
Data discovery
C
TokenizationCorrect Answer
D
Substitution
QUESTION 34 OF 43
IBM Guardium provides heterogeneous data source support. This support results in which capability?
A
Each data repository can maintain a unique security policy
B
Similar security capabilities can be applied to different types of data repositoriesCorrect Answer
C
Different security policies can be applied against data of the same type
D
There is support for both structure and unstructured data sources
QUESTION 35 OF 43
A student’s grades should be visible to that student when she logs in to her university account. Her ability to see her grades is an example of which aspect of the CIA Triad?
A
Authorization
B
Integrity
C
Confidentiality
D
AvailabilityCorrect Answer
QUESTION 36 OF 43
True or False. An organization has “air gapped” its small network of critical data servers so they are accessible internally but not to any external system. These systems are now safe from a deliberate attack.
A
True
B
FalseCorrect Answer
QUESTION 37 OF 43
True or False. A newly hired CISO made the right choice when he moved the Known Vulnerabilities list to a high priority for his team to resolve even though none of these had ever been exploited on the company’s network to-date.
A
TrueCorrect Answer
B
False
QUESTION 38 OF 43
All industries have their own unique data security challenges. Which of these industries has a particular concern with being targeted more than any other by cybercriminals “because that is where the money is”?
A
FinancialCorrect Answer
B
Healthcare
C
Transportation
D
Retail
QUESTION 39 OF 43
True or False. The IBM Guardium administrator needs to be someone with the highest level of access to the data being protected?
A
True
B
FalseCorrect Answer
QUESTION 40 OF 43
Which type of threat is Jailbreaking?
A
External
B
System basedCorrect Answer
C
Internal
D
App based
QUESTION 41 OF 43
A student can see her grades via her school’s Student Portal but is unable to change them. This restriction is in support of which aspect of the CIA Triad?
A
Confidentiality
B
IntegrityCorrect Answer
C
Authorization
D
Availability
QUESTION 42 OF 43
True or False. An operator who corrupts data by mistake is considered an “inadvertent attack” that should be considered when developing data protection plans.
A
TrueCorrect Answer
B
False
QUESTION 43 OF 43
True of False. A biotech research company with a very profitable product line has grown so rapidly it has acquired a marketing company, a small IT services company and a company that specializes in pharmaceutical manufacturing and distribution. The CEO of the parent company made a good decision when he decided not to consolidate all data security under a single CISO, believing that each of the new divisions understands its own data security needs better than the parent company possibly could.
A
True
B
FalseCorrect Answer
Ready to test your recall?
A student's grades should be visible to that student when she logs in to her university account. Her ability to see her grades is an example of which aspect of the CIA Triad?