🌍 All Study Guides📊 Dashboard📰 Blog💡 About
IBM Cybersecurity Analyst Professional Certificate • STUDY MODE

PRACTICE QUIZ

QUESTION 1 OF 64

Jeff Crume described 5 challenges in security today. Which three (3) of these are challenges because their numbers are increasing rapidly? Partially correct! A cybersecurity analyst can never know enough as new systems come online and new vulnerabilities are exposed. Partially correct! The number of alerts that must be analysed is rising rapidly. Partially correct! The number of threats facing a cybersecurity analyst is rising rapidly.

A
Needed knowledgeCorrect Answer
B
AlertsCorrect Answer
C
Available analysts
D
Available time
E
ThreatsCorrect Answer
QUESTION 2 OF 64

About how many unfilled cybersecurity jobs are expected by the year 2022? Correct! There will be many jobs available to those with the right skills. WHAT ARE WE TALKING ABOUT WHEN WE TALK ABOUT CYBERSECURITY?

A
180,000
B
1.8 millionCorrect Answer
C
180 million
D
There is expected to be a surplus of available skills by 2022.
QUESTION 3 OF 64

Which is the National Institute of Standards’ (NIST) definition of cybersecurity? Correct! This is the NIST definition of cyber or information security.

A
The protection of information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide confidentiality, integrity, and availability.Correct Answer
B
The state of being protected against the criminal or unauthorized use of electronic data, or the measures taken to achieve this.
C
The measures taken to protect governmental and military computer and weapons systems from unauthorized use, alteration, disruption or destruction.
QUESTION 4 OF 64

Which three (3) are components of the CIA Triad? Partially correct! Availability is the "A" in CIA. Partially correct! Confidentiality is the "C" in CIA. Partially correct! Integrity is the "I" in CIA.

A
Information
B
AvailabilityCorrect Answer
C
Access
D
ConfidentialityCorrect Answer
E
IntegrityCorrect Answer
F
Cyber
QUESTION 5 OF 64

“A flaw, loophole, oversight, or error that can be exploited to violate system security policy.” Is the definition of which key cybersecurity term? Correct! This is the definition of a cybersecurity vulnerability.

A
Threat
B
VulnerabilityCorrect Answer
C
Risk
D
Exploit
QUESTION 6 OF 64

“An event, natural or man-made, able to cause a negative impact to an organization.” Is the definition of which key cybersecurity term? Correct! This is the definition of a cybersecurity threat.

A
ThreatCorrect Answer
B
Vulnerability
C
Exploit
D
Risk
QUESTION 7 OF 64

Most cyber attacks come from which one of the following sources? Correct! Most cyber attacks originate with inside actors.

A
Natural factors, such as hurricanes, lightning and tornados.
B
External threats, such as hackers, malware and viruses.
C
Malicious events, such as an attack orchestrated by a foreign government.
D
Internal factors, such as current and former employees.Correct Answer
QUESTION 8 OF 64

Vulnerabilities are weaknesses in a system that can be exploited. Which are the two (2) most common ways in which vulnerabilities are introduced to a system? Partially correct! Many vulnerabilities are introduced by inexperienced administrators who leave security holes open to exploition. Partially correct! Many systems are shipped with known and unknown vulnerabilities to worry about... right out of the box!

A
Many vulnerabilities are introduced to a system by malware such as Trojan horses.
B
Many vulnerabilities occur as a result of misconfiguration by the system administrator.Correct Answer
C
Many vulnerabilities are inherent in a systems operating system and cannot be patched, only monitored.
D
Many systems are shipped with known and unknown security holes, such as insecure default settings.Correct Answer
QUESTION 9 OF 64

Which security role would be responsible for conducting information security assessments for organizations, including analyzing events, alerts and alarms? Correct! It is the Information Security Analyst who conducts security assessments and analyzes all security events. FROM RONALD REAGAN TO WHERE WE ARE TODAY

A
Information Security AnalystCorrect Answer
B
Chief Information Security Officer
C
Information Security Auditor
D
Information Security Architect
QUESTION 10 OF 64

Which American president first recognized the need for a national policy on cybersecurity? Correct, it was President Ronald Reagan!

A
George W Bush
B
Ronald ReaganCorrect Answer
C
Gerald Ford
D
Barack Obama
QUESTION 11 OF 64

In addition to specific events, what other factor has led to an enhanced need for strong cybersecurity? Correct! There are many more computing devices of all sizes used by many more people than ever before.

A
There is nothing illegal about accessing any computer you wish, as long as you do not do harm.
B
To save money, common operating systems have paid little attention to security and are easily hacked.
C
Computing devices like PCs and smartphones are now used by a large majority of people.Correct Answer
D
Weapons systems are now fully automated and can be controlled remotely.
QUESTION 12 OF 64

Between 2010 and 2016 the number of new software vulnerabilities discovered during this 7-year period was in what range? Correct! Between 7000 and 10,000 new software vulnerabilities were discovered in this 7-year period.

A
50 to 100
B
1000 to 2000
C
7000 to 10,000Correct Answer
D
35,000 to 40,000
QUESTION 13 OF 64

An example of weaponizing a cybervulnerability is the use of the Stuxnet virus. Which attack by a government actor successfully used this virus? Correct! Stuxnet is credited with damaging thousands of highly-sensitive uranium separation centrafuges. CYBERSECURITY PROGRAMS

A
Stuxnet was used by agents acting on behalf of the Russian government to hack Hillary Clinton)s email server.
B
Stuxnet was used by Edward Snowden to hack US intelligence agency servers and download classified information about secret surveillance programs.
C
Stuxnet was used to steal an estimated $100M from various banks in the United States and the UK.
D
Stuxnet was used to disable uranium processing equipment in an Iranian nuclear facility.Correct Answer
QUESTION 14 OF 64

Which three (3) factors make cybersecurity far more difficult now than it was in the past when you only needed to protect the computer? Partially correct! Smartphones are computers that contain massive amounts of data and link us to our bank accounts, credit cards and shopping accounts, to name a few. Partially correct! We have our data spread across far more online accounts and resources than ever before. Partially correct! There is not one standard that all vendor)s support so a cybersecurity analyst must address vulnerabilities from all.

A
Mobile technology - everyone has a smartphoneCorrect Answer
B
Data protection - your data is everywhereCorrect Answer
C
Local nature of business
D
Multiple different vendors, each supporting different technology and protocolsCorrect Answer
QUESTION 15 OF 64

Which aspect of a comprehensive approach to cybersecurity includes these items: classification, implementation steps, asset control and documentation? Correct, these are all aspects of asset management

A
Security program
B
Asset managementCorrect Answer
C
Administrative controls
D
Technical controls
QUESTION 16 OF 64

Which aspect of a comprehensive approach to cybersecurity includes these items: policies, procedures, standards, user education, incident response, disaster recovery, compliance and physical security? Correct, these are all aspects of administrative controls

A
Security program
B
Asset management
C
Administrative controlsCorrect Answer
D
Technical controls
QUESTION 17 OF 64

Which aspect of a comprehensive approach to cybersecurity includes these items: network infrastructure, endpoints, servers, identity management, vulnerability management, monitoring and logging? Correct, these are all aspects of technical controls CYBERSECURITY - A SECURITY ARCHITECT)S PERSPECTIVE

A
Security program
B
Asset management
C
Administrative controls
D
Technical controlsCorrect Answer
QUESTION 18 OF 64

Which three (3) security challenges face today)s organizations? Partially correct. This is a case of the guards needing guards. Partially correct. An effective attack often starts by disabling the defense. Partially correct. Good security is far from simple.

A
Protectors have to be right just once
B
Protection of enforcement structure can complicate solutionsCorrect Answer
C
Solutions can be attacked themselvesCorrect Answer
D
Security is not as simple as it seemsCorrect Answer
QUESTION 19 OF 64

In John)s example of friends and enemies, what is the name used to refer to the intruder? Correct. Trudy (intruder) may intercept, delete, add messages

A
Bob
B
TrudyCorrect Answer
C
Boris
D
Alice
QUESTION 20 OF 64

Only the sender and intended receiver of a message can "understand" the message contents is an example of which basic security concept? Correct! The message is confidential if only the sender and intended receiver can read its contents.

A
Authentication
B
ConfidentialityCorrect Answer
C
Integrity
D
Availability
QUESTION 21 OF 64

The sender and receiver of a message can positively identity each other)s identity is an example of which basic security concept? Correct! Authentication means that the sender and receiver can positively confirm each other)s identity. WHAT IS CRITICAL THINKING?

A
AuthenticationCorrect Answer
B
Integrity
C
Availability
D
Confidentiality
QUESTION 22 OF 64

Which is the presenter, Kristin Dahl's definition of Critical Thinking? Correct! Critical thinking involves the controlled and purposeful thinking directed toward a goal.

A
Critical thinking is a mode the brain goes into during critical or emergency situations.
B
Critical thinking is the controlled, purposeful thinking directed toward a goal.Correct Answer
C
Critical thinking is taking on the mindset of your opponent (the hacker for example) and trying to think like him/her.
D
Critical thinking involves always looking for the flaw or weakness in any given situation.
QUESTION 23 OF 64

The Critical Thinking Model presented places critical thinking at the overlap of which four (4) competencies? Partially correct! this is one of the 4 components of critical thinking.

A
Critical thinking characteristics (attitudes & behaviors).Correct Answer
B
The strength necessary to be critical of others who are advocating unsafe practices.
C
Technical skills and competencies.Correct Answer
D
Theoretical and experimental knowledge, intellectual skills and competencies.Correct Answer
E
Interpersonal skills and competencies.Correct Answer
F
The ability to place yourself in the mindset of an adversary or attacker.
QUESTION 24 OF 64

Put yourself in others' shoes - reframe the problem is an example of which of the 5 Key Skills of Critical Thinking? Correct! It is important to be able to see the points of views of others in order to understand the full context of a situation. HISTORY OF CYBERSECURITY

A
Understand ContextCorrect Answer
B
Identify Key Drivers
C
Consider Alternatives
D
Challenge Assumptions
QUESTION 25 OF 64

What was shown in the movie War Games that concerned President Reagan?

A
The movie gave an accurate portayal of the Iran-Contra scandle that could have only come from inside sources.
B
A teenager hacked into a Pentagon computer that was capable of launching nuclear weapons.Correct Answer
C
US Army generals did not know how to use the advanced weapons systems they were responsible for.
D
KGB agents from the USSR were able to hack into Pentagon computer systems and steal plans for advanced US weapons.
QUESTION 26 OF 64

In addition to the movie War Games, what other event made the need for advanced cybersecurity apparent?

A
The failed Bay of Pigs invasion.
B
Confirmed reports of Al Qaeda operatives hacking the E-mail servers of US Government agencies.
C
The attack against the USS Cole while it was in port in Yeman.
D
9/11Correct Answer
QUESTION 27 OF 64

According to a Forbes Magazine study, the annual cost of cybercrime in the United States alone has reached how much?

A
$100M
B
$1B
C
$10B
D
$100BCorrect Answer
QUESTION 28 OF 64

Who are Alice, Bob and Trudy?

A
They are fictional characters used to illustrate how cryptography works.Correct Answer
B
They were members of British Navel Intelligence who did pioneering work in secure communications that later became known as cryptography.
C
They are the founders of modern cryptography.
D
They are the pseudonyms (false names) used by members of the hacktivist group Anonymous.
QUESTION 29 OF 64

Which of the following is considered a legitimate challenge to implementing a comprehensive cybersecurity solution?

A
Security practices are viewed as being "in the way".
B
Security architectures require constant effort.
C
Security is often an after-thought; something that is added at the end of a project rather than baked into the project from the start.
D
All of the aboveCorrect Answer
QUESTION 30 OF 64

“A defined way to breach the security of an IT system through a vulnerability” is the definition of which key cybersecurity term?

A
Risk
B
Vulnerability
C
Threat
D
ExploitCorrect Answer
QUESTION 31 OF 64

“A situation involving exposure to a danger.” Is the definition of which key cybersecurity term?

A
Threat
B
Exploit
C
Vulnerability
D
RiskCorrect Answer
QUESTION 32 OF 64

Which aspect of a comprehensive approach to cybersecurity includes these items: evaluate, create teams, establish baselines, identify and model threats, identify use cases, identify risks, establish monitoring and control requirements?

A
Security programCorrect Answer
B
Technical controls
C
Asset management
D
Administrative controls
QUESTION 33 OF 64

In the examples using Bob, Alice and Trudy, what aspect of cybersecurity is being illustrated?

A
The availability of communication that needs to be shared between the 3 friends.
B
The complexity of communication between people who use different protocols.
C
The positioning of firewalls that assure the integrity of communication between the 3 friends.
D
The security of communication between Alice and Bob that risks interception by Trudy.Correct Answer
QUESTION 34 OF 64

Alice sends an unencrypted message to Bob but it is intercepted by Trudy. Trudy reads the message but does not in any way interfere with its content or delivery. Which precept of the CIA Triad would have been violated?

A
ConfidentialityCorrect Answer
B
Integrity
C
Availability
D
All of the above.
QUESTION 35 OF 64

Alice sends an encrypted message to Bob but it is intercepted by Trudy. Trudy cannot read it so, in anger, she deletes it without allowing its delivery to Bob. Which precept of the CIA Triad would have been violated?

A
Confidentiality
B
Integrity
C
AvailabilityCorrect Answer
D
All of the above
QUESTION 36 OF 64

Alice sends an encrypted message to Bob but it is intercepted by Trudy. Trudy cannot read it but forwards it on to Bob from an anonymous address she controls. Which precept of the CIA Triad would have been violated?

A
Confidentiality
B
IntegrityCorrect Answer
C
Availability
D
All of the above
QUESTION 37 OF 64

According to the Vulnerability Assessment Methodology, Vulnerabilities are determined by which 2 factors?

A
Exposure and Sensitivity
B
Identify Indicators and Exposure
C
Sensitivity and Adaptive Capacity
D
Potential Impacts and Adaptive CapacityCorrect Answer
QUESTION 38 OF 64

According to a 2018 report by Domo, over what period of time do the following things occur: 49,380 videos are uploaded to Instagram, 25,000 gifs are sent on Facebook Messenger, 4.2 million videos are viewed on Snapchat and 473,400 tweets are sent on Twitter?

A
Every 1 minuteCorrect Answer
B
Every 1 Second
C
Every 10 minutes
D
Every 10 seconds
QUESTION 39 OF 64

Jeff Crume described 5 challenges in security today. Which three (3) of these are challenges because their numbers are increasing rapidly?

A
Needed knowledge (CORRECT­)
B
Alerts (CORRECT­)
C
Available analysts
D
Available time
E
Threats (CORRECT­)
QUESTION 40 OF 64

About how many unfilled cybersecurity jobs are expected by the year 2022?

A
180,000
B
1.8 million (CORRECT­)
C
180 million
D
There is expected to be a surplus of available skills by 2022.
QUESTION 41 OF 64

Which is the National Institute of Standards’ (NIST) definition of cybersecurity?

A
The protection of information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide confidentiality, integrity, and availability. (CORRECT­)
B
The state of being protected against the criminal or unauthorized use of electronic data, or the measures taken to achieve this.
C
The measures taken to protect governmental and military computer and weapons systems from unauthorized use, alteration, disruption or destruction.
QUESTION 42 OF 64

Which three (3) are components of the CIA Triad?

A
Information
B
Availability (CORRECT­)
C
Access
D
Confidentiality (CORRECT­)
E
Integrity (CORRECT­)
F
Cyber
QUESTION 43 OF 64

“A flaw, loophole, oversight, or error that can be exploited to violate system security policy.” Is the definition of which key cybersecurity term?

A
Threat
B
Vulnerability (CORRECT­)
C
Risk
D
Exploit
QUESTION 44 OF 64

“An event, natural or man-made, able to cause a negative impact to an organization.” Is the definition of which key cybersecurity term?

A
Threat (CORRECT­)
B
Vulnerability
C
Exploit
D
Risk
QUESTION 45 OF 64

 Most cyber attacks come from which one of the following sources?

A
Natural factors, such as hurricanes, lightning and tornados.
B
External threats, such as hackers, malware and viruses.
C
Malicious events, such as an attack orchestrated by a foreign government.
D
Internal factors, such as current and former employees.Correct Answer
QUESTION 46 OF 64

Vulnerabilities are weaknesses in a system that can be exploited. Which are the two (2) most common ways in which vulnerabilities are introduced to a system?

A
Many vulnerabilities are introduced to a system by malware such as Trojan horses.
B
Many vulnerabilities occur as a result of misconfiguration by the system administrator.Correct Answer
C
Many vulnerabilities are inherent in a systems operating system and cannot be patched, only monitored.
D
Many systems are shipped with known and unknown security holes, such as insecure default settings.Correct Answer
QUESTION 47 OF 64

Which security role would be responsible for conducting information security assessments for organizations, including analyzing events, alerts and alarms?

A
Information Security AnalystCorrect Answer
B
Chief Information Security Officer
C
Information Security Auditor
D
Information Security Architect
QUESTION 48 OF 64

Which American president first recognized the need for a national policy on cybersecurity?

A
George W Bush
B
Ronald ReaganCorrect Answer
C
Gerald Ford
D
Barack Obama
QUESTION 49 OF 64

In addition to specific events, what other factor has led to an enhanced need for strong cybersecurity?

A
There is nothing illegal about accessing any computer you wish, as long as you do not do harm.
B
To save money, common operating systems have paid little attention to security and are easily hacked.
C
Computing devices like PCs and smartphones are now used by a large majority of people.Correct Answer
D
Weapons systems are now fully automated and can be controlled remotely.
QUESTION 50 OF 64

Between 2010 and 2016 the number of new software vulnerabilities discovered during this 7-year period was in what range?

A
50 to 100
B
1000 to 2000
C
7000 to 10,000Correct Answer
D
35,000 to 40,000
QUESTION 51 OF 64

An example of weaponizing a cybervulnerability is the use of the Stuxnet virus. Which attack by a government actor successfully used this virus?

A
Stuxnet was used by agents acting on behalf of the Russian government to hack Hillary Clinton’s email server.
B
Stuxnet was used by Edward Snowden to hack US intelligence agency servers and download classified information about secret surveillance programs.
C
Stuxnet was used to steal an estimated $100M from various banks in the United States and the UK.
D
Stuxnet was used to disable uranium processing equipment in an Iranian nuclear facility.Correct Answer
QUESTION 52 OF 64

Which three (3) factors make cybersecurity far more difficult now than it was in the past when you only needed to protect the computer?

A
Mobile technology – everyone has a smartphoneCorrect Answer
B
Data protection – your data is everywhereCorrect Answer
C
Local nature of business
D
Multiple different vendors, each supporting different technology and protocolsCorrect Answer
QUESTION 53 OF 64

Which aspect of a comprehensive approach to cybersecurity includes these items: classification, implementation steps, asset control and documentation?

A
Security program
B
Asset managementCorrect Answer
C
Administrative controls
D
Technical controls
QUESTION 54 OF 64

Which aspect of a comprehensive approach to cybersecurity includes these items: policies, procedures, standards, user education, incident response, disaster recovery, compliance and physical security?

A
Security program
B
Asset management
C
Administrative controlsCorrect Answer
D
Technical controls
QUESTION 55 OF 64

Which aspect of a comprehensive approach to cybersecurity includes these items: network infrastructure, endpoints, servers, identity management, vulnerability management, monitoring and logging?

A
Security program
B
Asset management
C
Administrative controls
D
Technical controlsCorrect Answer
QUESTION 56 OF 64

Which three (3) security challenges face today’s organizations?

A
Protectors have to be right just once
B
Protection of enforcement structure can complicate solutionsCorrect Answer
C
Solutions can be attacked themselvesCorrect Answer
D
Security is not as simple as it seemsCorrect Answer
QUESTION 57 OF 64

In John’s example of friends and enemies, what is the name used to refer to the intruder?

A
Bob
B
TrudyCorrect Answer
C
Boris
D
Alice
QUESTION 58 OF 64

Only the sender and intended receiver of a message can “understand” the message contents is an example of which basic security concept?

A
Authentication
B
ConfidentialityCorrect Answer
C
Integrity
D
Availability
QUESTION 59 OF 64

The sender and receiver of a message can positively identity each other’s identity is an example of which basic security concept?

A
AuthenticationCorrect Answer
B
Integrity
C
Availability
D
Confidentiality
QUESTION 60 OF 64

Which is the presenter, Kristin Dahl’s definition of Critical Thinking?

A
Critical thinking is a mode the brain goes into during critical or emergency situations.
B
Critical thinking is the controlled, purposeful thinking directed toward a goal.Correct Answer
C
Critical thinking is taking on the mindset of your opponent (the hacker for example) and trying to think like him/her.
D
Critical thinking involves always looking for the flaw or weakness in any given situation.
QUESTION 61 OF 64

The Critical Thinking Model presented places critical thinking at the overlap of which four (4) competencies?

A
Critical thinking characteristics (attitudes & behaviors).Correct Answer
B
The strength necessary to be critical of others who are advocating unsafe practices.
C
Technical skills and competencies.Correct Answer
D
Theoretical and experimental knowledge, intellectual skills and competencies.Correct Answer
E
Interpersonal skills and competencies.Correct Answer
F
The ability to place yourself in the mindset of an adversary or attacker.
QUESTION 62 OF 64

Put yourself in others’ shoes – reframe the problem is an example of which of the 5 Key  Skills of Critical Thinking?

A
Understand ContextCorrect Answer
B
Identify Key Drivers
C
Consider Alternatives
D
Challenge Assumptions
QUESTION 63 OF 64

Alice sends an encrypted message to Bob but it is intercepted by Trudy.  Trudy cannot read it so, in anger, she deletes it without allowing its delivery to Bob. Which precept of the CIA Triad would have been violated?

A
Confidentiality
B
Integrity
C
AvailabilityCorrect Answer
D
All of the above
QUESTION 64 OF 64

According to a 2018 report by Domo, over what period of time do the following things occur: 49,380 videos are uploaded to Instagram, 25,000 gifs are sent on Facebook Messenger, 4.2 million videos are viewed on Snapchat and 473,400 tweets are sent on Twitter? 

A
Every 1 minuteCorrect Answer
B
Every 1 Second
C
Every 10 minutes
D
Every 10 seconds
E
Google Advanced Data Analytics
F
Google Cybersecurity Professional Certificate
G
Meta Marketing Analytics Professional Certificate
H
Google Digital Marketing & E-commerce Professional Certificate
I
Google UX Design Professional Certificate
J
Meta Social Media Marketing Professional Certificate
K
Google Project Management Professional Certificate
L
Meta Front-End Developer Professional Certificate

Ready to test your recall?

Jeff Crume described 5 challenges in security today. Which three (3) of these are challenges because their numbers are increasing rapidly? Partially correct! A cybersecurity analyst can never know enough as new systems come online and new vulnerabilities are exposed. Partially correct! The number of alerts that must be analysed is rising rapidly. Partially correct! The number of threats facing a cybersecurity analyst is rising rapidly.

💡Select all 3 correct answers before submitting (0 of 3 selected).
A
Needed knowledge
B
Alerts
C
Available analysts
D
Available time
E
Threats

How confident are you in this answer?