🌍 All Study Guides📊 Dashboard📰 Blog💡 About
IBM Cybersecurity Analyst Professional Certificate • STUDY MODE

PRACTICE QUIZ

QUESTION 1 OF 26

True or False. There are more successful PoS attacks made against large online retailers than there are against small to medium sized brick-and-mortar businesses.

A
True
B
FalseCorrect Answer
QUESTION 2 OF 26

Which is the standard regulating credit card transactions and processing?

A
PCI-DSSCorrect Answer
B
Sarbanes-Oxley (SOX)
C
GDPR
D
NIST SP-800
QUESTION 3 OF 26

Which three (3) of these are PCI-DSS requirements for any company handling, processing or transmitting credit card data? (Select 3)

A
Cardholder data may not reside on local PoS devices for more than 48 hours
B
Protect stored cardholder dataCorrect Answer
C
Install and maintain a firewall configuration to protect cardholder dataCorrect Answer
D
Do not use vendor-supplied defaults for system passwords and other security parametersCorrect Answer
QUESTION 4 OF 26

True or False. A study conducted by the Ingenico Group found that credit card transactions were sufficiently secure as long as all participants were in strict compliance with PCI-DSS standards.

A
True
B
FalseCorrect Answer
QUESTION 5 OF 26

What are the two (2) most common operating systems for PoS devices? (Select 2)

A
WindowsCorrect Answer
B
Mac i/OS
C
LinuxCorrect Answer
D
POSOS
QUESTION 6 OF 26

If your credit card is stolen from a PoS system, what is the first thing the thief is likely to do with your card data?

A
Use it as part of a larger identity theft scheme
B
Use it to buy merchandise
C
Sell it to a carder
D
Sell it to a distributorCorrect Answer
QUESTION 7 OF 26

PCI-DSS can best be described how? POINT OF SALE BREACH GRADED ASSESSMENT

A
A voluntary payment card industry data security standardCorrect Answer
B
A provision of the European GDPR that covers payment card data privacy regulations
C
A financial regulation in the United States covering the payment card industry that replaced Sarbanes-Oxley
D
A financial regulation in the United States that supplements Sarbanes-Oxley with missing provisions covering the payment card industry
QUESTION 8 OF 26

Which group suffers from the most PoS attacks?

A
Restaurants and small retail stores.Correct Answer
B
Large online retailers like Amazon.com
C
Social media companies like Facebook and Instagram.
D
Government agencies.
QUESTION 9 OF 26

Which three (3) of these control processes are included in the PCI-DSS standard? (Select 3)

A
Build and maintain a secure network and systemsCorrect Answer
B
Maintain a vulnerability management programCorrect Answer
C
Protect cardholder dataCorrect Answer
D
Require use of multi-factor authentication for new card holders
QUESTION 10 OF 26

Which three (3) additional requirements did the Ingenico Group recommend be used to enhance credit card transactions above and beyond the requirements found in PCI-DSS? (Select 3)

A
Mobile Device Management (MDM)Correct Answer
B
Employee EducationCorrect Answer
C
TokenizationCorrect Answer
D
Discontinue use of magnetic strip readers and cards
QUESTION 11 OF 26

When is credit card data most vulnerable to PoS malware?

A
While stored on the PoS device hard drive
B
While in RAMCorrect Answer
C
After the card data has been received by the credit card processor
D
While in transit between the PoS device and the credit card processing center
QUESTION 12 OF 26

Which scenario best describes how a stolen credit card number is used to enrich the thief?

A
Credit card thieves use stolen credit cards to buy merchandise that is then returned to the store in exchange for store credit that is sold at a discount for profit
B
Credit card thieves resell stolen card numbers to dark web companies that use call-center style operations to purchase goods on behalf of customers who pay for them at discounted rates using real credit cards
C
Credit card thieves sell stolen credit cards directly to carders using weekly dark web auctions. The carders then encode credit card blanks with the stolen numbers and resell the cards
D
Stolen credit card numbers are sold to brokers who resell them to carders who use them to buy prepaid credit cards that are then used to buy gift cards that will be used to buy merchandise for resaleCorrect Answer
QUESTION 13 OF 26

Some of the earliest known phishing attacks were carried out against which company?

A
Google
B
Facebook
C
Yahoo
D
America Online (AOL)Correct Answer
QUESTION 14 OF 26

You have banked at "MyBank" for many years when you receive an urgent email telling you to log in to verify your security credentials or your account would be frozen. You are not wealthy but what little you have managed to save is in this bank. The email is addressed to "Dear Customer" and upon closer inspection you see it was sent from "security@mybank.yahoo.com". What kind of attack are you under?

A
As a phishing attack.Correct Answer
B
No attack, this is a legitimate note from the security department of your bank.
C
A spear phishing attack.
D
A whale attack.
QUESTION 15 OF 26

True or False. HTTPS assures passwords and other data that is sent across the Internet is encrypted. Links in email that use HTTPS will protect you against phishing attacks.

A
True
B
FalseCorrect Answer
QUESTION 16 OF 26

Which feature of this email is a red flag, indicating that it may be a phishing attack and not a legitimate account warning from PayPal? ( Image S1Q4 )

A
Suspicious sender)s address.Correct Answer
B
Suspicious attachments.
C
There is a hyperlink in the body of the email.
D
Poor quality layout.
QUESTION 17 OF 26

Which three (3) of these statistics about phishing attacks are real? (Select 3)

A
The average cost of a data breach is $3.86 million.Correct Answer
B
15% of people successfully phished will be targeted at least one more time within a year.Correct Answer
C
12% of businesses reported being the victim of a phishing attack in 2018.
D
Phishing accounts for 90% of data breaches.Correct Answer
QUESTION 18 OF 26

Which range best represents the number of unique phishing web sites reported to the Anti-Phishing Working Group (apwg.org) in Q4 2019? PHISHING CASE STUDY KNOWLEDGE CHECK

A
Between 100 and 200.
B
Between 1500 and 1800.
C
Between 130,000 and 140,000.Correct Answer
D
Between 1.3 million and 1.4 million.
QUESTION 19 OF 26

Which three (3) techniques are commonly used in a phishing attack? (Select 3)

A
Breaking in to an office at night and installing a key logging device on the victim)s computer.
B
Make an urgent request to cause the recipient to take quick action before thinking carefully.Correct Answer
C
Send an email from an address that very closely resembles a legitimate address.Correct Answer
D
Sending an email with a fake invoice that is overdue.Correct Answer
QUESTION 20 OF 26

You are working as an engineer on the design of a new product your company hopes will be a big seller when you receive an email from someone you do not personally know. The email is addressed to you and was sent by someone who identifies herself as the VP of your Product division. She wants you to send her a zip file of your design documents so she can review them. While her name is that of the real VP, she explains that she is using her personal email system since her company account is having problems. You suspect fraud. What kind of attack are you likely under?

A
A man in the middle attack.
B
A phishing attack.
C
A spear phishing attack.Correct Answer
D
A whale attack.
QUESTION 21 OF 26

Phishing attacks are often sent from spoofed domains that look just like popular real domains. Which brand has been spoofed the most in phishing attacks?

A
Microsoft
B
GoogleCorrect Answer
C
IBM
D
Apple
QUESTION 22 OF 26

Which feature of this email is a red flag, indicating that it may be a phishing attack and not a legitimate account warning from PayPal? ( Image S2Q4 )

A
Suspicious attachments
B
There is a hyperlink in the body of the email
C
Poor quality layout
D
There are spelling errors.Correct Answer
QUESTION 23 OF 26

Which is the most common type of identity theft?

A
Credit card fraudCorrect Answer
B
Phone or utility fraud
C
Loan or lease fraud
D
Government documents or benefits fraud
QUESTION 24 OF 26

You have banked at “MyBank” for many years when you receive an urgent email telling you to log in to verify your security credentials or your account would be frozen. You are not wealthy but what little you have managed to save is in this bank. The email is addressed to “Dear Customer” and upon closer inspection you see it was sent from “security@mybank.yahoo.com”. What kind of attack are you under?

A
As a phishing attack.Correct Answer
B
No attack, this is a legitimate note from the security department of your bank.
C
A spear phishing attack.
D
A whale attack.
QUESTION 25 OF 26

Which feature of this email is a red flag, indicating that it may be a phishing attack and not a legitimate account warning from PayPal?

A
Suspicious sender’s address.Correct Answer
B
Suspicious attachments.
C
There is a hyperlink in the body of the email.
D
Poor quality layout.
QUESTION 26 OF 26

Which range best represents the number of unique phishing web sites reported to the Anti-Phishing Working Group (apwg.org) in Q4 2019?

A
Between 100 and 200.
B
Between 1500 and 1800.
C
Between 130,000 and 140,000.Correct Answer
D
Between 1.3 million and 1.4 million.

Ready to test your recall?

True or False. There are more successful PoS attacks made against large online retailers than there are against small to medium sized brick-and-mortar businesses.

A
True
B
False

How confident are you in this answer?