🌍 All Study Guides📊 Dashboard📰 Blog💡 About
IBM Cybersecurity Analyst Professional Certificate • STUDY MODE

PRACTICE QUIZ

QUESTION 1 OF 40

A cyber attack originating from which three (3) of the following would be considered a supply-chain attack? (Select 3)

A
An environmental activist group
B
E-mail providersCorrect Answer
C
SubcontractorsCorrect Answer
D
Web hosting companiesCorrect Answer
QUESTION 2 OF 40

Which three (3) of these were cited as the top 3 sources of third-party breach? (Select 3)

A
Cloud-based storage or hosting providersCorrect Answer
B
Online payment or credit card processing servicesCorrect Answer
C
JavaScript on websites used for web analyticsCorrect Answer
D
Security vulnerabilities in operating systems
QUESTION 3 OF 40

True or False. While data loss from a third-party breach can be expensive, third-party breaches account for less than 22% of all breaches.

A
True
B
FalseCorrect Answer
QUESTION 4 OF 40

According to a 2019 Ponemon study, what percent of consumers say they will defect from a business if their personal information is compromised in a breach? THIRD-PARTY BREACH GRADED ASSESSMENT

A
10%
B
51%
C
80%Correct Answer
D
92%
QUESTION 5 OF 40

True or False. According to a 2018 Ponemon study, organizations surveyed cited "A third-party misused or shared confidential information..." as their top cyber security concern for the coming year.

A
TRUECorrect Answer
B
False
QUESTION 6 OF 40

How effective were the processes for vetting third-parties as reported by the majority (64%) of the companies surveyed?

A
Highly effective
B
Effective
C
Somewhat or not effectiveCorrect Answer
D
Not effective at all
QUESTION 7 OF 40

In the first few months of 2020 data breaches were reported from Instagram, Carson City, Amazon, GE, T-Mobile, radio.com, MSU, and Marriot. While different data were stolen from each organization, which two data elements were stolen from all of them? (Select 2)

A
Corporate financial data
B
Personal informationCorrect Answer
C
Customer financial informationCorrect Answer
D
Confidential corporate strategy data
QUESTION 8 OF 40

True or False. More than 63% of data breaches can be linked to a third-party.

A
TrueCorrect Answer
B
False
QUESTION 9 OF 40

According to a 2019 Ponemon study, which is the most common course of action for a consumer who has lost personal data in a breach?

A
Tell others of their experienceCorrect Answer
B
Use social media to complain about their experience
C
Comment directly on the company)s website
D
File a complaint with the FTC or other regulatory body
QUESTION 10 OF 40

You get a pop-up message on your screen telling you that critical files on your system have been encrypted and that you must pay a fee to get the encryption key. What type of ransomware has attacked your system?

A
Blockware
B
CryptoCorrect Answer
C
Leakware/Doxware
D
Locker
QUESTION 11 OF 40

Your bank sends you an email with your account statement attached. You think this is odd but open it anyway to see what it is. The document is blank so you close it and think no more about it. A few days later you realize that your computer is infected with malware. What attack vector was used to compromise your system?

A
Remote Desktop Protocol (RDP)
B
Malicious Links
C
PhishingCorrect Answer
D
Software Vulnerabilities
QUESTION 12 OF 40

You take advantage of an Internet offer for free technical support and a live technician acutally does contact you, log into your computer and help you optimize your system. A few days later you notice some critical business files are missing when a big red message block appears on your screen demanding money if you ever want to see your files again. What attack vector is the malware exploiting?

A
Software Vulnerabilities
B
Phishing
C
Malicious Links
D
Remote Desktop Protocol (RDP)Correct Answer
QUESTION 13 OF 40

If you fail to patch your operating system and that fact allows a bad actor to install ransomware on your system, what was the likely attack vector?

A
Remote Desktop Protocol (RDP)
B
Software VulnerabilitiesCorrect Answer
C
Malicious Links
D
Phishing
QUESTION 14 OF 40

You read an interesting article online that contains links to related articles so you follow one of them and pretty soon you are a victim of a ransomware attack. What was the likely attack vector used by the bad actors?

A
Phishing
B
Remote Desktop Protocol (RDP)
C
Software Vulnerabilities
D
Malicious LinksCorrect Answer
QUESTION 15 OF 40

What is the most important thing to have in place that will save you from having to pay a ransom in the event you have fallen victim to a ransomware attack?

A
Fully patched operating system and applications
B
Strong passwords
C
Anti-virus software
D
A full system backupCorrect Answer
QUESTION 16 OF 40

Which ransomware spread across 150 countries in 2017 and was responsible for over $4 billion in losses worldwide?

A
Bad Rabbit
B
GoldenEye
C
Jigsaw
D
WannaCryCorrect Answer
QUESTION 17 OF 40

True or False. Projections are that ransomware will not be a significant problem in the future as operating systems become more secure and anti-malware applications gain in sophistication. RANSOMWARE GRADED ASSESSMENT

A
True
B
FalseCorrect Answer
QUESTION 18 OF 40

You get a pop-up message on your screen telling you have been locked out of your computer and that access will remain blocked until you pay a fee to have your access restored. What type of ransomware has attacked your system?

A
Blockware
B
Crypto
C
LockerCorrect Answer
D
Leakware/Doxware
QUESTION 19 OF 40

You get a pop-up message on your screen telling you that embarrassing photos taken of you at a college party many years ago have been downloaded and will be made public unless you pay a fee. What type of ransomware has attacked your system?

A
Leakware/DoxwareCorrect Answer
B
Blockware
C
Crypto
D
Locker
QUESTION 20 OF 40

You get an email from your Internet service provider addressed to "Dear Customer" asking you to log in and verify your credentials due to "suspicious activity" detected in your account. This email is most likely trying to exploit which attack vector?

A
Remote Desktop Protocol (RDP)
B
Malicious Links
C
PhishingCorrect Answer
D
Software Vulnerabilities
QUESTION 21 OF 40

A person you meet at a party offers to help you optimize your computer so you arrange for her to log in remotely. The next time you reboot your system, you get a pop-up message telling you all your critical files have been encrypted and you must pay a ransome to get the encryption key. What attack vector was used to exploit your system?

A
Phishing
B
Malicious Links
C
Software Vulnerabilities
D
Remote Desktop Protocol (RDP)Correct Answer
QUESTION 22 OF 40

You fear that the security patches sent out by the vendor of one of your products may introduce changes to what you are used to so you never allow the updates. What attack vector are you setting yourself up for?

A
Remote Desktop Protocol (RDP)
B
Software VulnerabilitiesCorrect Answer
C
Phishing
D
Malicious Links
QUESTION 23 OF 40

You log into your bank and see an offer for a 0% interest rate loan. You click on the link to check out the details and suddenly your computer is locked and there is a message demanding payment in order to unlock it. Your bank)s website was hacked! What attack vector was being used to install ransomware on your system?

A
Phishing
B
Remote Desktop Protocol (RDP)
C
Malicious LinksCorrect Answer
D
Software Vulnerabilities
QUESTION 24 OF 40

True or False. Being vigilant about email you receive, links your follow and websites you visit is an effective way to keep yourself safe from a ransomware attack.

A
TrueCorrect Answer
B
False
QUESTION 25 OF 40

Which ransomware used fake Adobe Flash download websites to distribute and install ransomware?

A
Bad RabbitCorrect Answer
B
GoldenEye
C
Jigsaw
D
WannaCry
QUESTION 26 OF 40

True or False. It is feared that in the future our cars, homes and factories may fall victim to ransomware attacks as more and more devices join the Internet of Things.

A
TrueCorrect Answer
B
False
QUESTION 27 OF 40

According to a 2019 Ponemon study, what percent of consumers say they will defect from a business if their personal information is compromised in a breach?

A
10%
B
51%
C
80%Correct Answer
D
92%
QUESTION 28 OF 40

True or False. According to a 2018 Ponemon study, organizations surveyed cited “A third-party misused or shared confidential information…” as their top cyber security concern for the coming year.

A
TRUECorrect Answer
B
False
QUESTION 29 OF 40

True or False. There are more successful PoS attacks made against large online retailers than there are against small to medium sized brick-and-mortar businesses.

A
True
B
FalseCorrect Answer
QUESTION 30 OF 40

Which is the standard regulating credit card transactions and processing?

A
PCI-DSSCorrect Answer
B
Sarbanes-Oxley (SOX)
C
GDPR
D
NIST SP-800
QUESTION 31 OF 40

Which three (3) of these are PCI-DSS requirements for any company handling, processing or transmitting credit card data? (Select 3)

A
Cardholder data may not reside on local PoS devices for more than 48 hours
B
Protect stored cardholder dataCorrect Answer
C
Install and maintain a firewall configuration to protect cardholder dataCorrect Answer
D
Do not use vendor-supplied defaults for system passwords and other security parametersCorrect Answer
QUESTION 32 OF 40

True or False. A study conducted by the Ingenico Group found that credit card transactions were sufficiently secure as long as all participants were in strict compliance with PCI-DSS standards.

A
True
B
FalseCorrect Answer
QUESTION 33 OF 40

What are the two (2) most common operating systems for PoS devices? (Select 2)

A
WindowsCorrect Answer
B
Mac i/OS
C
LinuxCorrect Answer
D
POSOS
QUESTION 34 OF 40

If your credit card is stolen from a PoS system, what is the first thing the thief is likely to do with your card data?

A
Use it as part of a larger identity theft scheme
B
Use it to buy merchandise
C
Sell it to a carder
D
Sell it to a distributorCorrect Answer
QUESTION 35 OF 40

PCI-DSS can best be described how?

A
A voluntary payment card industry data security standardCorrect Answer
B
A provision of the European GDPR that covers payment card data privacy regulations
C
A financial regulation in the United States covering the payment card industry that replaced Sarbanes-Oxley
D
A financial regulation in the United States that supplements Sarbanes-Oxley with missing provisions covering the payment card industry
QUESTION 36 OF 40

Which group suffers from the most PoS attacks?

A
Restaurants and small retail stores.Correct Answer
B
Large online retailers like Amazon.com
C
Social media companies like Facebook and Instagram.
D
Government agencies.
QUESTION 37 OF 40

Which three (3) of these control processes are included in the PCI-DSS standard? (Select 3)

A
Build and maintain a secure network and systemsCorrect Answer
B
Maintain a vulnerability management programCorrect Answer
C
Protect cardholder dataCorrect Answer
D
Require use of multi-factor authentication for new card holders
QUESTION 38 OF 40

Which three (3) additional requirements did the Ingenico Group recommend be used to enhance credit card transactions above and beyond the requirements found in PCI-DSS? (Select 3)

A
Mobile Device Management (MDM)Correct Answer
B
Employee EducationCorrect Answer
C
TokenizationCorrect Answer
D
Discontinue use of magnetic strip readers and cards
QUESTION 39 OF 40

When is credit card data most vulnerable to PoS malware?

A
While stored on the PoS device hard drive
B
While in RAMCorrect Answer
C
After the card data has been received by the credit card processor
D
While in transit between the PoS device and the credit card processing center
QUESTION 40 OF 40

Which scenario best describes how a stolen credit card number is used to enrich the thief?

A
Credit card thieves use stolen credit cards to buy merchandise that is then returned to the store in exchange for store credit that is sold at a discount for profit
B
Credit card thieves resell stolen card numbers to dark web companies that use call-center style operations to purchase goods on behalf of customers who pay for them at discounted rates using real credit cards
C
Credit card thieves sell stolen credit cards directly to carders using weekly dark web auctions. The carders then encode credit card blanks with the stolen numbers and resell the cards
D
Stolen credit card numbers are sold to brokers who resell them to carders who use them to buy prepaid credit cards that are then used to buy gift cards that will be used to buy merchandise for resaleCorrect Answer
E
Google Advanced Data Analytics
F
Google Cybersecurity Professional Certificate
G
Meta Marketing Analytics Professional Certificate
H
Google Digital Marketing & E-commerce Professional Certificate
I
Google UX Design Professional Certificate
J
Meta Social Media Marketing Professional Certificate
K
Google Project Management Professional Certificate
L
Meta Front-End Developer Professional Certificate

Ready to test your recall?

A cyber attack originating from which three (3) of the following would be considered a supply-chain attack? (Select 3)

💡Select all 3 correct answers before submitting (0 of 3 selected).
A
An environmental activist group
B
E-mail providers
C
Subcontractors
D
Web hosting companies

How confident are you in this answer?