🌍 All Study Guides📊 Dashboard📰 Blog💡 About
IBM Cybersecurity Analyst Professional Certificate • STUDY MODE

PRACTICE QUIZ

QUESTION 1 OF 20

What type of scan can be conducted to determine what possible exploits exist given the client’s environment?

A
Port Scan
B
Document Scanning
C
Anti-Virus Scan
D
Vulnerability ScanCorrect Answer
QUESTION 2 OF 20

Which three (3) forms of discovery can be conducted offline?

A
Packet Sniffing
B
Shoulder SurfingCorrect Answer
C
Dumpster DivingCorrect Answer
D
Social EngineeringCorrect Answer
QUESTION 3 OF 20

Network Mapping, Port Scanning, and Password Cracking are all forms of what type of discovery?

A
Offline
B
ActiveCorrect Answer
C
Passive
D
Neutral
QUESTION 4 OF 20

True or False: The Planning phase is considered a formality and can be skipped as long as you have the verbal agreement of the client. ATTACK AND REPORTING KNOWLEDGE CHECK

A
True
B
FalseCorrect Answer
QUESTION 5 OF 20

What level of access is ideal for a penetration tester to achieve in order to exploit a system?

A
Standard
B
Admin/RootCorrect Answer
C
Guest
D
Advanced
QUESTION 6 OF 20

Which of the following is NOT a common type of vulnerability?

A
Misconfigurations
B
Race Conditions
C
Incorrect File and Directory Permissions
D
PhishingCorrect Answer
QUESTION 7 OF 20

Which portion of the pentest report gives a step by step account of how and why each exploit was conducted? PENETRATION TESTING TOOLS

A
Executive Summary
B
Rules of Engagement
C
Recommendations for Remediation
D
Technical ReviewCorrect Answer
QUESTION 8 OF 20

Which tool lets you log network traffic and analyze it?

A
Nmap
B
John the Ripper
C
Metasploit
D
WiresharkCorrect Answer
QUESTION 9 OF 20

Which software serves as toolbox, providing access to hundreds of other tools and resources?

A
Wireshark
B
Hack the Box
C
John the Ripper
D
Kali LinuxCorrect Answer
QUESTION 10 OF 20

Which tool is used primarily for password cracking? PENETRATION TEST GRADED QUIZ

A
Kali Linux
B
Nmap
C
John the RipperCorrect Answer
D
Metasploit
QUESTION 11 OF 20

Which of the following is NOT a phase of a penetration test?

A
Discovery
B
Attack
C
Reviewing
D
Planning
QUESTION 12 OF 20

In which phase of penetration testing do you recommend solutions to address any exploited vulnerabilities?

A
Planning
B
Discovery
C
Attack
D
Reporting
QUESTION 13 OF 20

Which portion of the pentest report gives a high level detail of how the test went and what goals were accomplished?

A
Executive Summary
B
Scope Worksheet
C
Technical Report
D
Risk Analysis
QUESTION 14 OF 20

Throughout the attack phase of a pentest, you may need to revisit which other phase as you gain further access into a system?

A
Reporting
B
Discovery
C
Exploitation
D
Planning
QUESTION 15 OF 20

What method of gathering information can be used to get information about a website that is not readily available?

A
Phishing
B
Social Engineering
C
Port Scanning
D
Google Dorking
QUESTION 16 OF 20

Which two (2) privacy laws do you need to take into consideration when potentially gaining access to private customer information?

A
Completely Automated Public Turing Test to Tell Computers and Humans Apart (CAPTCHA)
B
General Data Protection Regulation (GDPR)Correct Answer
C
Health Insurance Portability and Accountability Act (HIPPA)Correct Answer
D
Distributed Denial of Service (DDoS)
QUESTION 17 OF 20

Guessing passwords or running a password cracking software engages in what type of attack to gain access to a system?

A
Brute ForceCorrect Answer
B
Hash
C
Passive Agressive
D
Persistent
QUESTION 18 OF 20

What document would protect the privacy of your client and their customers?

A
Rules of Engagement (RoE)
B
Scope Worksheet
C
Non Disclosure Agreement (NDA)Correct Answer
D
Press Release
QUESTION 19 OF 20

Gaining access to a system can occur in which two phases?

A
Planning and Discovery
B
Discovery and Reporting
C
Discovery and AttackCorrect Answer
D
Planning and Attack
QUESTION 20 OF 20

Conducting a pentest as if you were an external hacker with no resources is known as what type of test?

A
Grey Box
B
Red Hat
C
White Box
D
Black BoxCorrect Answer

Ready to test your recall?

What type of scan can be conducted to determine what possible exploits exist given the client’s environment?

A
Port Scan
B
Document Scanning
C
Anti-Virus Scan
D
Vulnerability Scan

How confident are you in this answer?