IBM Cybersecurity Analyst Professional Certificate • STUDY MODE
PRACTICE QUIZ
QUESTION 1 OF 20
What type of scan can be conducted to determine what possible exploits exist given the client’s environment?
A
Port Scan
B
Document Scanning
C
Anti-Virus Scan
D
Vulnerability ScanCorrect Answer
QUESTION 2 OF 20
Which three (3) forms of discovery can be conducted offline?
A
Packet Sniffing
B
Shoulder SurfingCorrect Answer
C
Dumpster DivingCorrect Answer
D
Social EngineeringCorrect Answer
QUESTION 3 OF 20
Network Mapping, Port Scanning, and Password Cracking are all forms of what type of discovery?
A
Offline
B
ActiveCorrect Answer
C
Passive
D
Neutral
QUESTION 4 OF 20
True or False: The Planning phase is considered a formality and can be skipped as long as you have the verbal agreement of the client.
ATTACK AND REPORTING KNOWLEDGE CHECK
A
True
B
FalseCorrect Answer
QUESTION 5 OF 20
What level of access is ideal for a penetration tester to achieve in order to exploit a system?
A
Standard
B
Admin/RootCorrect Answer
C
Guest
D
Advanced
QUESTION 6 OF 20
Which of the following is NOT a common type of vulnerability?
A
Misconfigurations
B
Race Conditions
C
Incorrect File and Directory Permissions
D
PhishingCorrect Answer
QUESTION 7 OF 20
Which portion of the pentest report gives a step by step account of how and why each exploit was conducted?
PENETRATION TESTING TOOLS
A
Executive Summary
B
Rules of Engagement
C
Recommendations for Remediation
D
Technical ReviewCorrect Answer
QUESTION 8 OF 20
Which tool lets you log network traffic and analyze it?
A
Nmap
B
John the Ripper
C
Metasploit
D
WiresharkCorrect Answer
QUESTION 9 OF 20
Which software serves as toolbox, providing access to hundreds of other tools and resources?
A
Wireshark
B
Hack the Box
C
John the Ripper
D
Kali LinuxCorrect Answer
QUESTION 10 OF 20
Which tool is used primarily for password cracking?
PENETRATION TEST GRADED QUIZ
A
Kali Linux
B
Nmap
C
John the RipperCorrect Answer
D
Metasploit
QUESTION 11 OF 20
Which of the following is NOT a phase of a penetration test?
A
Discovery
B
Attack
C
Reviewing
D
Planning
QUESTION 12 OF 20
In which phase of penetration testing do you recommend solutions to address any exploited vulnerabilities?
A
Planning
B
Discovery
C
Attack
D
Reporting
QUESTION 13 OF 20
Which portion of the pentest report gives a high level detail of how the test went and what goals were accomplished?
A
Executive Summary
B
Scope Worksheet
C
Technical Report
D
Risk Analysis
QUESTION 14 OF 20
Throughout the attack phase of a pentest, you may need to revisit which other phase as you gain further access into a system?
A
Reporting
B
Discovery
C
Exploitation
D
Planning
QUESTION 15 OF 20
What method of gathering information can be used to get information about a website that is not readily available?
A
Phishing
B
Social Engineering
C
Port Scanning
D
Google Dorking
QUESTION 16 OF 20
Which two (2) privacy laws do you need to take into consideration when potentially gaining access to private customer information?
A
Completely Automated Public Turing Test to Tell Computers and Humans Apart (CAPTCHA)
B
General Data Protection Regulation (GDPR)Correct Answer
C
Health Insurance Portability and Accountability Act (HIPPA)Correct Answer
D
Distributed Denial of Service (DDoS)
QUESTION 17 OF 20
Guessing passwords or running a password cracking software engages in what type of attack to gain access to a system?
A
Brute ForceCorrect Answer
B
Hash
C
Passive Agressive
D
Persistent
QUESTION 18 OF 20
What document would protect the privacy of your client and their customers?
A
Rules of Engagement (RoE)
B
Scope Worksheet
C
Non Disclosure Agreement (NDA)Correct Answer
D
Press Release
QUESTION 19 OF 20
Gaining access to a system can occur in which two phases?
A
Planning and Discovery
B
Discovery and Reporting
C
Discovery and AttackCorrect Answer
D
Planning and Attack
QUESTION 20 OF 20
Conducting a pentest as if you were an external hacker with no resources is known as what type of test?
A
Grey Box
B
Red Hat
C
White Box
D
Black BoxCorrect Answer
Ready to test your recall?
What type of scan can be conducted to determine what possible exploits exist given the client’s environment?